The short version: We do not sell your data. We do not share PHI with advertisers. We use your denied claims data only to deliver the audit or analysis you requested — nothing else. All PHI is encrypted and deleted within 30 days of audit completion.
1. Who We Are
SurfAI operates surfai.ai, an AI-powered medical billing denial analysis and appeal letter generation platform for independent healthcare clinics. We are a Business Associate under HIPAA — meaning we handle Protected Health Information (PHI) on behalf of covered healthcare providers and are legally bound by HIPAA's privacy and security requirements.
Questions about this policy: compliance@surfai.ai
2. Information We Collect
2.1 Contact Information (No PHI)
When you fill out the contact form on surfai.ai, we collect:
- First and last name
- Work email address
- Clinic or practice name and type
- Monthly claim volume and plan interest
- Description of your billing challenges
This information contains no patient data and is used only to respond to your inquiry and deliver our services.
2.2 Denied Claims Data (May Contain PHI)
When you use our Lost Revenue Audit Engine or Claim Analyzer, you may upload denied claims data. This data may contain PHI including patient identifiers, dates of service, diagnosis codes, and procedure codes.
Recommendation: We strongly encourage you to upload de-identified claims data — with patient names, dates of birth, and Social Security numbers removed. De-identified data provides all the analytical value we need without PHI exposure.
If you upload PHI, our full HIPAA Business Associate obligations apply, and you must have an executed Business Associate Agreement (BAA) with SurfAI in place before uploading.
2.3 Website Analytics
Our website collects standard analytics data (IP address, browser type, pages visited, time on site) for website improvement purposes only. This data does not contain PHI and is not linked to any patient information.
3. How We Use Your Information
| Data Type | How We Use It |
|---|---|
| Contact form data | Respond to inquiries, deliver audit reports, business communication |
| Denied claims / PHI | Run the audit or claim analysis you requested — nothing else |
| Analytics data | Website improvement only |
| Aggregated/de-identified data | Improve our AI denial analysis accuracy |
We never: Sell your data or PHI · Use PHI to train AI models without written consent · Share data with advertisers · Use individually identifiable PHI for any purpose beyond your requested service
4. How We Share Your Information
4.1 Technology Subcontractors
We share data with the following vendors to deliver our services. Each has an executed Business Associate Agreement with SurfAI prior to any PHI processing:
| Vendor | Purpose | BAA Status |
|---|---|---|
| Anthropic PBC | AI processing for denial analysis and appeal letters | ✓ Executed |
| Google LLC | Secure file storage and data transmission | ✓ Executed |
| Make.com | Workflow automation and communications | ✓ Executed |
We do not share your data with any other third parties without your explicit written consent, except as required by law.
4.2 Legal Requirements
We may disclose information when required by law, court order, or valid government request, or when necessary to protect our legal rights or the safety of others.
5. Data Security
We implement the following technical and administrative safeguards:
- Encryption: AES-256 encryption for all data at rest; TLS 1.2+ for all data in transit
- Access controls: PHI accessible only to authorized personnel on a need-to-know basis
- Authentication: Multi-factor authentication for all systems that access PHI
- Monitoring: Regular security risk assessments and vulnerability scanning
- Workforce: Employee security training and confidentiality agreements
- Session security: Automatic timeouts and strong password policies
Despite these measures, no method of data transmission or storage is 100% secure. We cannot guarantee absolute security but commit to using commercially reasonable safeguards consistent with HIPAA requirements.
6. Data Retention & Deletion
| Data Type | Retention Period |
|---|---|
| Uploaded claims data / PHI | Deleted within 14 days of audit completion |
| Audit reports | Retained 30 days after delivery, then permanently deleted |
| Contact form data | Retained 12 months for business communication |
| Website analytics | Aggregated and anonymized after 90 days |
To request immediate deletion of your data, email compliance@surfai.ai. We will confirm deletion within 5 business days.
7. Your HIPAA Rights
If you are a healthcare provider submitting PHI to SurfAI, the patients whose PHI is processed retain the following rights under HIPAA. As your Business Associate, we will cooperate fully to help you fulfill these obligations:
- Right of access — patients may request access to their PHI
- Right to amend — patients may request corrections to their PHI
- Right to accounting — patients may request a log of disclosures of their PHI
- Right to restrict — patients may request restrictions on use and disclosure
To submit a HIPAA rights request: compliance@surfai.ai
8. Breach Notification
In the event of a breach of unsecured PHI, we will notify affected covered entities without unreasonable delay and no later than 60 calendar days after discovery, in compliance with HIPAA's Breach Notification Rule (45 C.F.R. Part 164, Subpart D).
Our notification will include a description of the breach, the types of PHI involved, steps we are taking to mitigate harm, and our contact information for follow-up.
9. Business Associate Agreements
Before uploading any PHI to SurfAI, you must have a signed Business Associate Agreement (BAA) with us. Our standard BAA is available upon request.
To request a BAA: compliance@surfai.ai
10. Changes to This Policy
We may update this Privacy Policy as our services evolve or as required by law. When we make material changes we will:
- Post the updated Policy on surfai.ai with a new Effective Date
- Notify existing clients by email at least 30 days before changes take effect
11. Contact & Complaints
For privacy questions, data deletion requests, BAA requests, or security concerns:
SurfAI Compliance
Email: compliance@surfai.ai
Website: surfai.ai
To file a complaint with the federal government:
HHS Office for Civil Rights
www.hhs.gov/ocr
Phone: 1-800-368-1019