Is Claim Raven HIPAA-compliant?

Claim Raven does not represent the Service as HIPAA-compliant or as a HIPAA-certified service. HIPAA generally applies to covered entities, such as health plans, health care clearinghouses, and certain health care providers, and to business associates that handle protected health information on their behalf. Claim Raven is a veteran-facing technology service, not a health plan or health care provider; for information you submit directly to Claim Raven, its Privacy Policy and other applicable privacy and consumer-health laws govern. A particular organizational arrangement may require separate legal and contractual review, so do not submit protected health information on behalf of a covered entity unless Claim Raven has confirmed the arrangement in writing.

Overview

HIPAA status depends on the role and relationship The fact that a medical or VA record contains health information does not, by itself, determine whether HIPAA applies to a particular holder or use. The analysis depends on who creates, receives, maintains, or transmits the information and whether that work is performed on behalf of a HIPAA covered entity or business associate.

What HIPAA status depends on

Covered entities: HIPAA applies to health plans, health care clearinghouses, and health care providers that conduct covered electronic transactions. Business associates: Certain contractors must follow parts of HIPAA when they create, receive, maintain, or transmit protected health information on behalf of a covered entity or another business associate. A written business-associate arrangement is part of that relationship. Consumer-directed use: HHS scenarios explain that an independently selected app does not become a business associate solely because a person enters health information, uploads a record obtained from a provider, or directs information between the app and a provider for the person's own purposes. Different relationships can produce different answers: The same developer can have one product or contract that is subject to HIPAA and a separate direct-to-consumer service that is not. The facts, client, contract, data flow, and purpose matter. Do not assume a Business Associate Agreement exists If you plan to use Claim Raven on behalf of a health plan, covered health care provider, clearinghouse, or business associate, do not upload protected health information until Claim Raven has confirmed the required agreement and configuration in writing. A support question, security feature, encryption control, or ordinary account does not create a BAA.

What Claim Raven currently represents

Claim Raven's current Privacy Policy describes it as veteran-facing technology, not a health plan or health care provider, for people who choose to organize and understand their own VA disability information. Claim Raven does not advertise the Service as HIPAA-compliant or HIPAA-certified. HTTPS, encryption, access controls, audit logs, consent controls, and other safeguards are important, but they do not by themselves establish HIPAA compliance. The Privacy Policy governs direct submissions to Claim Raven and describes consumer health data, purposes, provider categories, consent, retention, privacy rights, and breach notices. Other federal and state privacy or consumer-health laws may also apply. Some features send limited content to contracted infrastructure or AI providers to perform a request. Masking is best-effort on supported text paths, and raw images or scanned PDF pages may reach a provider before text-level masking is possible.

Not covered by HIPAA does not mean unprotected

Privacy promises still matter. The FTC Act can apply to misleading or unfair health-data practices, including claims about collection, use, retention, sharing, and security. The FTC Health Breach Notification Rule can apply to qualifying vendors of personal health records, related entities, and service providers that are not covered by HIPAA. Whether that rule applies to a particular Claim Raven product or incident requires a fact-specific legal review. State privacy, consumer-health, data-security, and breach-notification laws may provide additional rights or duties depending on location and the facts. Claim Raven's Privacy Policy and Terms remain binding product disclosures. They do not become optional merely because HIPAA does not govern a particular consumer-directed use.

Before you provide sensitive information

For personal, consumer-directed use Review the current Privacy Policy, Security page, AI consent control, and feature notice. Provide only the information needed for the task, and remove unnecessary identifiers when doing so will not prevent the feature from working. For an organization or client Have the organization's privacy, security, and legal owners determine the required relationship. Contact help@claimraven.com before uploading PHI and wait for written confirmation of any required contract and configuration. For a privacy-rights request Email help@claimraven.com with the subject Consumer Health Data Request. Describe the right or question without attaching medical records, identity documents, passwords, multifactor codes, or other unnecessary sensitive information. For product security details Read the Security page and the focused Help Center articles about storage, AI providers, deletion, and data protection. Security controls reduce risk; they are not a legal certification.

Current HIPAA and consumer-health privacy sources

Current HIPAA and consumer-health privacy sources Claim Raven Privacy Policy https://claimraven.com/privacy-policy HHS OCR: Covered Entities and Business Associates https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html HHS OCR: Resources for Mobile Health Apps Developers https://www.hhs.gov/hipaa/for-professionals/special-topics/health-apps/index.html FTC: HIPAA, the FTC Act, and the Health Breach Notification Rule https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach

Related privacy and security guidance

Related privacy and security guidance Read the Consumer Health Data Notice /privacy-policy#consumer-health-data Review current operational providers /privacy-policy#third-party-sharing Review security controls and their boundaries /security Learn how AI providers handle requested content /help-center/privacy-and-security/faq-ai-vendor-data Learn where Claim Raven stores data /help-center/privacy-and-security/faq-where-is-data-stored Learn how account deletion works /help-center/privacy-and-security/faq-delete-account Learn about Claim Raven's no-sale policy /help-center/privacy-and-security/faq-do-you-sell-data

More information

Read the current consumer-health notice Open the Privacy Policy for Claim Raven's current consumer-health data categories, purposes, providers, rights, retention, and breach-notice commitments. Open the Privacy Policy /privacy-policy#consumer-health-data