Legal

Privacy Policy

Effective Date: July 26, 2026  ·  Last Updated: July 26, 2026

The short version: We do not sell your data. We do not share PHI with advertisers. We use your denied claims data only to deliver the audit or analysis you requested — nothing else. All PHI is encrypted and deleted within 30 days of audit completion.

1. Who We Are

SurfAI operates surfai.ai, an AI-powered medical billing denial analysis and appeal letter generation platform for independent healthcare clinics. We are a Business Associate under HIPAA — meaning we handle Protected Health Information (PHI) on behalf of covered healthcare providers and are legally bound by HIPAA's privacy and security requirements.

Questions about this policy: compliance@surfai.ai

2. Information We Collect

2.1 Contact Information (No PHI)

When you fill out the contact form on surfai.ai, we collect:

This information contains no patient data and is used only to respond to your inquiry and deliver our services.

2.2 Denied Claims Data (May Contain PHI)

When you use our Lost Revenue Audit Engine or Claim Analyzer, you may upload denied claims data. This data may contain PHI including patient identifiers, dates of service, diagnosis codes, and procedure codes.

Recommendation: We strongly encourage you to upload de-identified claims data — with patient names, dates of birth, and Social Security numbers removed. De-identified data provides all the analytical value we need without PHI exposure.

If you upload PHI, our full HIPAA Business Associate obligations apply, and you must have an executed Business Associate Agreement (BAA) with SurfAI in place before uploading.

2.3 Website Analytics

Our website collects standard analytics data (IP address, browser type, pages visited, time on site) for website improvement purposes only. This data does not contain PHI and is not linked to any patient information.

3. How We Use Your Information

Data TypeHow We Use It
Contact form dataRespond to inquiries, deliver audit reports, business communication
Denied claims / PHIRun the audit or claim analysis you requested — nothing else
Analytics dataWebsite improvement only
Aggregated/de-identified dataImprove our AI denial analysis accuracy

We never: Sell your data or PHI · Use PHI to train AI models without written consent · Share data with advertisers · Use individually identifiable PHI for any purpose beyond your requested service

4. How We Share Your Information

4.1 Technology Subcontractors

We share data with the following vendors to deliver our services. Each has an executed Business Associate Agreement with SurfAI prior to any PHI processing:

VendorPurposeBAA Status
Anthropic PBCAI processing for denial analysis and appeal letters✓ Executed
Google LLCSecure file storage and data transmission✓ Executed
Make.comWorkflow automation and communications✓ Executed

We do not share your data with any other third parties without your explicit written consent, except as required by law.

4.2 Legal Requirements

We may disclose information when required by law, court order, or valid government request, or when necessary to protect our legal rights or the safety of others.

5. Data Security

We implement the following technical and administrative safeguards:

Despite these measures, no method of data transmission or storage is 100% secure. We cannot guarantee absolute security but commit to using commercially reasonable safeguards consistent with HIPAA requirements.

6. Data Retention & Deletion

Data TypeRetention Period
Uploaded claims data / PHIDeleted within 14 days of audit completion
Audit reportsRetained 30 days after delivery, then permanently deleted
Contact form dataRetained 12 months for business communication
Website analyticsAggregated and anonymized after 90 days

To request immediate deletion of your data, email compliance@surfai.ai. We will confirm deletion within 5 business days.

7. Your HIPAA Rights

If you are a healthcare provider submitting PHI to SurfAI, the patients whose PHI is processed retain the following rights under HIPAA. As your Business Associate, we will cooperate fully to help you fulfill these obligations:

To submit a HIPAA rights request: compliance@surfai.ai

8. Breach Notification

In the event of a breach of unsecured PHI, we will notify affected covered entities without unreasonable delay and no later than 60 calendar days after discovery, in compliance with HIPAA's Breach Notification Rule (45 C.F.R. Part 164, Subpart D).

Our notification will include a description of the breach, the types of PHI involved, steps we are taking to mitigate harm, and our contact information for follow-up.

9. Business Associate Agreements

Before uploading any PHI to SurfAI, you must have a signed Business Associate Agreement (BAA) with us. Our standard BAA is available upon request.

To request a BAA: compliance@surfai.ai

10. Changes to This Policy

We may update this Privacy Policy as our services evolve or as required by law. When we make material changes we will:

11. Contact & Complaints

For privacy questions, data deletion requests, BAA requests, or security concerns:

SurfAI Compliance
Email: compliance@surfai.ai
Website: surfai.ai

To file a complaint with the federal government:

HHS Office for Civil Rights
www.hhs.gov/ocr
Phone: 1-800-368-1019