Privacy Policy for CareCode AI
Protected Health Information (PHI)
When CareCodeAI is provided to a HIPAA Covered Entity or Business Associate, CompleteCare may process Protected Health Information (“PHI”) solely as necessary to provide the CareCodeAI services.
The collection, use, disclosure, storage, and protection of PHI is governed by the applicable Business Associate Agreement (“BAA”) between CompleteCare and the Covered Entity. In the event of any conflict between this Privacy Policy and an executed BAA, the BAA shall control with respect to PHI.
This Privacy Policy primarily describes CompleteCare's privacy practices relating to website visitors, prospective customers, account information, platform users, and other information not governed by HIPAA.
1. Data Collection and Use
- CareCode AI accepts SOAP notes (Subjective, Objective, Assessment, Plan) as user input in order to generate CPT, ICD-10, and modifier code suggestions, including denial risk levels and prior authorization alerts.
- CareCodeAI is designed to minimize the storage of Protected Health Information. Patient identifiers are removed through a de-identification process before information is transmitted to external AI services.
- We do not sell, share, or disclose any user-submitted data to third parties for marketing or commercial purposes.
2. De-Identification of Data
- All SOAP notes pass through a proprietary LLM-powered de-identification engine that strips PHI in accordance with HIPAA Safe Harbor and Expert Determination standards before being analyzed for coding purposes.
- Only de-identified clinical text is used to generate code recommendations.
3. AI Processing and Outputs
- The AI algorithms return suggested CPT, ICD-10, and modifier codes, alongside payer-specific denial risk indicators.
- Outputs are advisory only and must be reviewed and confirmed by the provider, coder, or authorized clinical user.
4. User Access and Permissions
- User access is role-based and configured by organization administrators.
- Permissions can be set at the user, department, and location levels.
5. Data Ownership
Customer retains ownership of all Customer Data submitted through CareCodeAI. CompleteCare processes Customer Data only as necessary to provide the Services and in accordance with applicable agreements, including any applicable Business Associate Agreement.
6. No Sale of Data
CompleteCare does not sell Customer Data, Protected Health Information, or personal information.
7. AI Processing
CareCodeAI uses artificial intelligence as part of its coding assistance workflow. Prior to transmission to external AI services, CareCodeAI is designed to remove patient identifiers through its de-identification process. Customer PHI is not used to train public or third-party AI models.
8. Security Safeguards
- CareCode operates on HIPAA-compliant hosting infrastructure with appropriate administrative, technical, and physical safeguards.
- All data transmissions are encrypted using industry-standard TLS protocols.
- Access to systems is restricted and audited.
9. Indemnification
By using CareCode, users agree to indemnify, defend, and hold harmless CompleteCare, Inc. and its affiliates from any and all liabilities, claims, and expenses (including reasonable attorneys’ fees) that arise from:
- Misuse of the Application
- Inaccurate coding outputs due to incomplete or erroneous SOAP note entries
- Unauthorized access or use by end-users under the organization’s account
- Any breach of applicable laws or regulations by the user or their organization
CareCode does not replace the judgment of certified coders or clinicians.
10. No Warranties
CareCode is provided “as-is” without warranties of any kind, express or implied. While our AI aims for accuracy and payer-specific insights, ultimate billing responsibility lies with the user.
11. Updates to This Policy
We may update this Privacy Policy to reflect legal or operational changes. Users will be notified of material updates via email or platform alerts.
12. Contact
CompleteCare, Inc.Email: carecodeai@completecare.com