BillDetect is a medical billing error-detection platform. BillDetect is designed for use by patient advocates, certified professional coders (CPCs), medical billing specialists, and other healthcare billing professionals ("Advocates," "you," or "your") who use our platform to analyze medical bills on behalf of their own clients ("Clients"). We help Advocates identify errors on a Client's medical bill by analysing billing codes against applicable federal and state regulations and generating dispute documentation for the Advocate's review and use.
This Privacy Policy explains how we collect, use, disclose, store, and protect information — including Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") — when you use our website and services.
Contact: hello@billdetect.com | billdetect.com
This Policy applies to:
This Policy does not apply to the practices of third-party websites linked from our site, nor to an Advocate's independent handling of Client information outside the Service.
BillDetect operates as a Business Associate — or, where an Advocate itself operates as a Business Associate to its Client, a Subcontractor Business Associate — as defined under HIPAA (45 CFR § 160.103). We process Protected Health Information submitted by Advocates for the limited purpose of billing error detection: identifying billing errors, generating dispute documentation, and providing regulatory citations.
Advocates are solely responsible for establishing and maintaining the appropriate legal basis — including any required Client authorisation, engagement agreement, or Business Associate Agreement — to submit a Client's PHI to BillDetect.
We do not provide medical advice, clinical services, or legal representation. We are not a covered entity, healthcare provider, health plan, or healthcare clearinghouse.
When an Advocate submits a Client's medical bill for analysis, we collect the following categories of PHI:
We collect only the minimum PHI necessary to perform our services (the "minimum necessary" standard under 45 CFR § 164.514(d)).
We collect the Advocate's name, email address, and professional details (such as organisation name or credential type, where provided) to establish an account, deliver analysis results, and communicate about submitted cases.
Payment processing is handled entirely by Stripe, Inc. BillDetect does not collect, store, or process your credit card or payment account information. Stripe's privacy policy governs the handling of your payment data.
We automatically collect standard technical information when you visit our website, including IP address, browser type, pages visited, and referring URLs. This information is used for security monitoring and service improvement and is not linked to Client PHI.
We use PHI solely for the following purposes, consistent with the Advocate's representations under our Terms and applicable law:
Our analysis checks each submitted bill against the following ten regulatory frameworks:
We do not use PHI for marketing, advertising, or sale to third parties. We do not use PHI to train artificial intelligence models.
We share PHI with the following categories of vendors who are bound by Business Associate Agreements and HIPAA-equivalent obligations: cloud infrastructure providers; artificial intelligence processing services; PDF generation services; secure email delivery services; and case management and data storage services. We do not permit any vendor to use PHI for any purpose other than providing services to BillDetect.
We may disclose PHI without consent when required by law, including: in response to a valid court order or subpoena; to report to government agencies as required by law; to avert a serious and imminent threat to health or safety; or as required by the HIPAA Privacy Rule.
We will share PHI with any third party the Advocate explicitly authorises in writing, provided the Advocate holds the requisite authority to do so on behalf of the Client. Authorisation may be revoked at any time by contacting hello@billdetect.com.
BillDetect does not sell, rent, or trade Protected Health Information. We do not share PHI with advertisers, data brokers, or any commercial party for marketing purposes.
No security system is impenetrable. In the event of a breach affecting PHI, we will notify affected Advocates and, where required, Clients, as required by HIPAA and applicable state law.
PHI submitted through BillDetect is retained for a minimum of six (6) years from the date of service on the applicable bill, consistent with HIPAA's minimum retention requirements (45 CFR § 164.530(j)). After the retention period expires, PHI is securely destroyed using cryptographic erasure of encrypted cloud storage, secure deletion of database records, and documented destruction records maintained for audit purposes.
An Advocate may request deletion of a Client's PHI before the retention period expires, provided the Advocate confirms it has the authority to make such a request on the Client's behalf. We will honour such requests unless retention is required by law, regulation, or pending legal proceedings.
The rights described below belong to the Client as the data subject, and may be exercised by the Client directly or, where the Advocate holds appropriate authority, by the Advocate on the Client's behalf.
You have the right to inspect and receive a copy of the PHI we hold. We will provide this within 30 days of a written request. Contact hello@billdetect.com.
You have the right to request correction of PHI you believe is inaccurate or incomplete. We will respond within 60 days.
You have the right to request a list of disclosures of PHI we have made within the previous six years, other than for treatment, payment, operations, or disclosures you authorised.
You have the right to request that we restrict the use or disclosure of PHI. We are not required to agree to all restrictions, but if we agree, we are bound by that agreement.
You may withdraw consent to our processing of PHI at any time by contacting hello@billdetect.com. Withdrawal does not affect processing that occurred before the withdrawal.
If you believe privacy rights have been violated, you may file a complaint with BillDetect directly at hello@billdetect.com, or with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/privacy. We will not retaliate against you for filing a complaint.
California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete, the right to correct, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise these rights, contact hello@billdetect.com.
Residents of Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy laws may have additional rights regarding their personal information. Contact us at hello@billdetect.com to exercise any applicable rights.
Our Service is intended for use by Advocates who are 18 years of age or older. Clients whose bills are submitted through the Service may include minors, where the Advocate has obtained appropriate authorisation from the minor's parent or legal guardian. Where a minor's PHI is included in a submitted bill, it is processed with the same safeguards as adult PHI and in accordance with HIPAA requirements for minor health information. Advocates are responsible for confirming they hold appropriate authority to submit a minor Client's information.
Our website uses minimal cookies necessary for site functionality. We do not use tracking pixels, cross-site tracking, or advertising cookies. We do not share website usage data with advertising networks.
BillDetect uses artificial intelligence (AI) services to analyse submitted medical bills. Specifically, bill content is transmitted to an AI processing service (currently Amazon Web Services Bedrock using Anthropic's Claude model) for automated extraction of billing codes and identification of potential billing errors across the ten regulatory frameworks described in Section 5.1. This processing is governed by a Business Associate Agreement between BillDetect and the AI service provider. The AI service provider is contractually prohibited from using PHI to train, fine-tune, or improve its AI models.
AI analysis is used as a tool to assist the Advocate's own professional review. BillDetect does not represent that AI findings are infallible.
BillDetect is a billing error-detection platform and not a law firm, certified public accountant, or licensed healthcare professional. Nothing in our reports or dispute letters constitutes legal advice, medical advice, or financial advice, to either the Advocate or the Advocate's Client. Our liability for any claim arising from our services is limited to the amount paid for those services, as further described in our Terms and Conditions.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this Policy, post the updated Policy on our website, and send an email notice to Advocates who have submitted bills within the previous 12 months. Your continued use of our services after the effective date of an updated Policy constitutes your acceptance of the updated terms.
For questions, concerns, or to exercise privacy rights:
BillDetect — Privacy Officer
hello@billdetect.com · billdetect.com
We will respond to all privacy-related enquiries within 30 days.