← Back to PayerVista
Legal

Privacy Policy

This Privacy Policy explains how [COMPANY LEGAL NAME] ("PayerVista," "we," "us," or "our") collects, uses, discloses, and protects information when you visit our websites, create an account, or use the PayerVista platform (the "Service"). PayerVista is a business-to-business analytics service for healthcare practices.

Version 2.0 · Last updated August 2, 2026

1. Protected Health Information and our role under HIPAA (important)

PayerVista ingests EDI 835 electronic remittance advice files, and optionally EDI 837 claim files, submitted by healthcare providers. These files contain Protected Health Information ("PHI"), including patient names, health plan member or medical record identifiers, dates of service, claim identifiers, and procedure and payment detail tied to identified individuals.

PayerVista therefore acts as a HIPAA Business Associate, and a Business Associate Agreement ("BAA") is required before a covered entity transmits PHI to the Service. A BAA is available — contact support@payervista.com. See our HIPAA & Business Associate Agreements statement for full detail.

A previous version of this Policy stated that PayerVista worked only with de-identified data and did not handle PHI or sign BAAs. That statement did not reflect how the Service operates and has been corrected.

2. Information we collect

  • Remittance and claim data containing PHI. Claim, payment, denial, adjustment, and variance data parsed from the 835 and 837 files you upload, including patient names and member or record identifiers, dates of service, and claim identifiers.
  • Account and business information. Your name, business email address, practice/organization name, user role, and account settings.
  • Billing information. Subscription and billing details are processed by our payment processor, Stripe. We never receive or store full payment card numbers; Stripe provides us limited information such as billing status, the last four digits, card brand, and expiration.
  • Usage and technical data. Product usage, telemetry, log data, IP address, browser and device details, and error diagnostics used to operate, secure, and improve the Service.

3. How we use information

  • To create, operate, and secure your account and workspace.
  • To parse remittance and claim data and generate analytics and reports for you.
  • To process subscription billing through Stripe.
  • To send account, verification, security, and service-related communications.
  • To monitor, troubleshoot, and improve performance, reliability, and security.
  • To comply with legal obligations and enforce our Terms.

We use and disclose PHI only as permitted by our BAA with you and as required by law. We do not sell personal information, and we do not use PHI for advertising or marketing.

Where we use aggregated data to operate and improve the Service, that data is aggregated and de-identified so that it does not identify you or any individual, consistent with our BAA.

4. Third-party subprocessors

We share information with service providers only as needed to operate the Service:

  • Cloud hosting and database — Amazon Web Services (AWS). Stores and processes PHI. Covered by an executed AWS Business Associate Addendum; production PHI is kept on HIPAA-eligible AWS services.
  • Payment processing — Stripe. Subscription billing only. Does not receive PHI.
  • Transactional email — Resend. Account, verification, security, and service notifications only. Email content is restricted by policy to account and security workflow information and must not contain patient, claim, remittance, or member-identifier data. Does not receive PHI.
  • Error monitoring — Sentry. Configured to minimise the risk of capturing PHI: session replay disabled, default personally identifiable information capture disabled, and an event scrubber applied before transmission.

These providers are bound by their own terms and data-protection obligations and process information on our behalf.

5. Data storage and security

Data is hosted on AWS infrastructure in the United States. We employ a multi-tenant architecture with row-level security (RLS) and cross-tenant isolation testing to keep each customer's data logically separated, role-based access controls within each workspace, audit logging of security-relevant actions, and encryption of data in transit and at rest. No method of transmission or storage is perfectly secure, but we maintain administrative, technical, and organizational safeguards appropriate to PHI as required by the HIPAA Security Rule and our BAA.

6. Data retention

We retain account data and uploaded remittance and claim data for as long as your account is active and as needed to provide the Service, then for a reasonable period thereafter to comply with legal, tax, and operational obligations, after which it is deleted or aggregated so that it no longer identifies any individual. Usage logs are retained for a limited period for security and troubleshooting. Retention and return or destruction of PHI on termination are governed by the BAA.

7. Deletion and your choices

You may request deletion of your account data by contacting support@payervista.com. Workspace administrators can manage team access and certain account settings within the application. We will honor deletion requests subject to legal retention requirements and the terms of the BAA.

Individual rights requests. Because we hold PHI as a Business Associate rather than as the covered entity, requests from individuals exercising HIPAA rights — access, amendment, or an accounting of disclosures — should be directed to the healthcare provider that submitted the data. We will assist that provider in responding as provided in the BAA.

8. Cookies and analytics

We use cookies and similar technologies that are necessary to authenticate sessions, remember preferences, and understand aggregate product usage. You can control cookies through your browser settings; disabling necessary cookies may affect functionality.

9. Children's privacy

The Service is for business use and is not directed to individuals under 18. We do not knowingly collect account information from children. This does not limit the fact that remittance data submitted by a provider may relate to patients of any age.

10. Changes to this Policy

We may update this Privacy Policy as the product and our processors evolve. Material changes will be reflected by an updated version and "Last updated" date on this page.

11. Contact

For privacy questions or requests, contact support@payervista.com, [COMPANY LEGAL NAME], [ADDRESS].

TermsRefund PolicyHIPAA & Security

This document is a launch-stage baseline and is subject to legal review before it is relied upon as final. It does not constitute legal advice.