Legal · Health Information

HIPAA Notice of
Privacy Practices

Effective date: July 19, 2026Last updated: July 19, 2026
THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

This health information privacy notice explains how AuthFight handles your information. It follows HIPAA principles, but it is not intended to suggest that HIPAA applies to every AuthFight user or that AuthFight is legally required to issue a HIPAA Notice of Privacy Practices in every relationship. See Section 01 for details.
Plain-English Summary: When you use AuthFight, you share health information with us — like your diagnosis and denial details. This page explains exactly what we do with that information, who we can share it with, and the legal rights you have over it at all times.
01

Who We Are

AuthFight, Inc. ("AuthFight") handles your health information in one of two legal postures, depending on how you reach us. When we provide services on behalf of a HIPAA Covered Entity — such as a partner pharmacy that refers you to us — we act as a Business Associate under a signed Business Associate Agreement (BAA) with that entity, and HIPAA's Privacy Rule (45 CFR Part 164, Subpart E) and Security Rule (45 CFR Part 164, Subpart C) apply directly to our handling of your information.

When you sign up with AuthFight directly, HIPAA generally does not govern that relationship — HIPAA applies to Covered Entities and their Business Associates, not to services you engage yourself. In that case, your information is protected by this notice, our Privacy Policy, the FTC Act's prohibition on unfair and deceptive practices, the FTC Health Breach Notification Rule (16 CFR Part 318), and applicable state privacy laws. As a matter of policy, we apply the same HIPAA-aligned administrative, technical, and physical safeguards to your information in both postures.

Where technology service providers store, transmit, or otherwise process identifiable health information to help AuthFight operate the platform, we require appropriate contractual safeguards, including Business Associate Agreements where HIPAA requires them and equivalent confidentiality and data-protection terms where it does not. These technology providers are separate from your treating physician, partner pharmacy, and health insurer. Disclosures to your physician and insurer are made at your direction as part of your appeal.

02

What Is Protected Health Information

Protected Health Information (PHI) is individually identifiable health information that AuthFight creates, receives, maintains, or transmits on behalf of a HIPAA Covered Entity, such as a participating pharmacy, while acting as its Business Associate. Information you provide directly to AuthFight may contain the same sensitive health details without being PHI as legally defined by HIPAA. We protect both categories under the safeguards described in this notice.

PHI includes information in any form: written, electronic (ePHI), or verbal. The following identifiers, when combined with health information, make data PHI under HIPAA:

Name
Address
Dates (DOB, admission)
Phone numbers
Email address
Social Security Number
Medical record numbers
Health plan numbers
Account numbers
Certificate / license numbers
Device identifiers
Web URLs
IP addresses
Biometric identifiers
Full-face photos
Geographic data
Fax numbers
Any unique identifier

In the context of AuthFight, the PHI we typically hold includes your name, diagnosis, prescribed medication or procedure, prescribing physician's name, insurer name and member ID, and the contents of your denial letter and appeal documents.

03

How We Use Your PHI

We use your PHI only for purposes directly related to building and submitting your insurance appeal. Specifically:

Appeal preparation

We use your diagnosis, denial code, denial letter contents, and medical history you provide to decode your denial, calculate your Fight Score, and generate a personalized appeal letter that accurately reflects your clinical situation.

Deadline tracking and reminders

We use your denial date, insurer name, and plan type to calculate your legal appeal deadlines and send you reminders before those windows close.

Physician coordination

We use your PHI to share your appeal draft with your treating physician, who reviews the letter for clinical accuracy and medical appropriateness and signs it before it is submitted to your insurer, and we follow up with their office on your behalf until a response is received.

Platform operations

We use de-identified, aggregated data — from which all PHI identifiers have been removed — to understand appeal outcomes, improve our Fight Score accuracy, and develop new features. De-identified data is not PHI and is not subject to HIPAA restrictions.

We do not use your PHI for marketing. We will never use or sell your health information to advertise products or services to you or to third parties, including pharmaceutical companies, data brokers, or insurers outside your active appeal.
04

How We Disclose Your PHI

We disclose your PHI only in the following circumstances. We practice data minimization and limit information to what is reasonably appropriate for each purpose, subject to circumstances in which HIPAA's minimum-necessary standard does not apply, including certain authorized disclosures and disclosures for treatment.

Recipient
Purpose & What Is Shared
Your treating physician
The provider who prescribed the denied treatment receives your appeal draft and related denial details to review for clinical accuracy and sign before submission. Your physician is independently bound by HIPAA as a Covered Entity.
Your health insurer
Your signed appeal letter, supporting clinical documentation, and insurance identifiers (member ID, group number, denial reference) are submitted to your insurer on your behalf, at your direction, to process your appeal.
A referring pharmacy
When a participating pharmacy refers your case to AuthFight, we may share limited case-status information with that pharmacy as necessary to coordinate the referral and services it sponsors. We do not share more health information than is needed for that purpose.
External reviewers
If you elect to pursue external independent review after an internal appeal denial, we share your appeal record with the independent review organization (IRO) assigned by your state or the federal government.
Technology service providers
Technology service providers that help us securely host the platform, store information, or transmit documents may process identifiable health information while performing those services for AuthFight. We require appropriate confidentiality and data-protection safeguards, including Business Associate Agreements where HIPAA requires them.
Legal requirements
We may disclose PHI when required by law, court order, or subpoena, or to prevent or lessen a serious and imminent threat to health or safety, as permitted under 45 CFR §164.512.
HHS / Regulators
We may disclose PHI to the U.S. Department of Health and Human Services (HHS) for compliance investigations or enforcement proceedings as required under 45 CFR §164.502(a)(2)(ii).

We do not disclose your PHI to employers, life insurers, financial institutions, data brokers, pharmaceutical companies, or any marketing entity.

05

When We Need Your Authorization

The uses and disclosures described above are made with your consent and at your direction — they are what you hire us to do when you start an appeal. Where HIPAA applies to our work, they fall within its permitted purposes. For any use or disclosure not described in this notice, we will ask for your written authorization before proceeding, regardless of which legal posture applies.

Uses that always require your written authorization include:

  • Most uses of PHI for marketing purposes
  • Sale of PHI to any third party
  • Disclosures of psychotherapy notes
  • Any use not otherwise permitted by the HIPAA Privacy Rule

Revoking your authorization

You may revoke a written authorization at any time by notifying us in writing at support@authfight.com. Revocation takes effect upon our receipt of your written notice. It does not apply to actions we have already taken based on your prior authorization. Please note that revoking authorization for us to process your PHI will prevent us from continuing to work on your appeal.

06

Your HIPAA Rights

When AuthFight holds PHI as a Business Associate, the applicable Covered Entity is generally responsible for responding to HIPAA requests for access, amendment, restrictions, and an accounting of disclosures. AuthFight supports the Covered Entity as required by our BAA and may respond directly when the BAA authorizes us to do so. We also offer comparable privacy choices to direct AuthFight users as a matter of policy. You may begin a request by emailing support@authfight.com with the subject line "Health Information Request." We will respond or route the request to the appropriate Covered Entity within the timeframe required by applicable law and our contractual obligations.

Right to Access

You may request a copy of your PHI that we hold in a designated record set. We will provide access within 30 days. We may provide records electronically upon request at no charge.

Right to Amend

If you believe PHI in our records is inaccurate or incomplete, you may request an amendment. We may deny the request in certain limited circumstances and will explain why in writing.

Right to an Accounting

You may request a list of disclosures of your PHI we have made in the past six years, other than disclosures made for treatment, payment, or healthcare operations.

Right to Request Restrictions

You may request that we limit certain uses or disclosures of your PHI. We are not required to agree to all restriction requests, but will honor those we accept in writing.

Right to Confidential Communications

You may request that we communicate with you about your PHI through a specific method or at a specific address — for example, only by email rather than phone. We will accommodate reasonable requests.

Right to a Paper Copy

You may request a printed copy of this Notice at any time, even if you previously agreed to receive it electronically. Email us and we will mail one to you at no charge.

Right to Revoke Authorization

You may withdraw your authorization for us to use or share your PHI at any time in writing. This will stop all future processing of your health information and your active appeal.

Right to Breach Notification

If a breach of your unsecured health information occurs, AuthFight will make the reports and notifications for which it is responsible under its BAAs, HIPAA's Breach Notification Rule where applicable, the FTC Health Breach Notification Rule where applicable, and state law. When we act as a Business Associate, this includes notifying the applicable Covered Entity so it can fulfill its notification duties.

07

Our Legal Duties

When we act as a Business Associate, HIPAA and our BAA impose duties concerning how we safeguard and handle PHI. We apply comparable protections to every user as a matter of policy. Our responsibilities include:

  • Maintain the privacy and security of your Protected Health Information.
  • Report breaches of unsecured PHI to the applicable Covered Entity and provide any other notifications for which AuthFight is responsible under applicable law.
  • Follow the privacy commitments described in this notice.
  • Not use or disclose your PHI except as described in this Notice or as otherwise permitted by applicable law.
  • Train all members of our workforce on our HIPAA privacy and security policies.
  • Designate a Privacy Officer responsible for developing and implementing our HIPAA compliance program.
We follow the privacy commitments in this notice and the requirements that apply to our role. We may revise this notice as our practices or obligations change and will post the revised version with its effective date.
08

Minimum Necessary Standard

Where HIPAA's minimum necessary standard applies, AuthFight makes reasonable efforts to limit PHI to what is needed for the intended purpose. The HIPAA standard does not apply to every disclosure, including certain disclosures for treatment or those made under a valid individual authorization. Even when the HIPAA standard does not apply, we practice data minimization as a company policy.

In practice, this means:

  • We only request the clinical records and documentation directly relevant to your specific denial and appeal.
  • We only share with your treating physician the appeal materials relevant to the denied treatment they prescribed.
  • We only transmit to your insurer the documents required for your appeal submission.
  • Internal access to your PHI is restricted to AuthFight personnel whose job function requires it, and all access is logged.
09

How to File a Complaint

If you believe AuthFight has not complied with this notice, you may file a complaint with us. If your concern involves PHI handled by AuthFight as a Business Associate, you may also complain to the applicable Covered Entity or the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR).

File a complaint with AuthFight

Emailsupport@authfight.com
Subject line"HIPAA Complaint"
Response timeWe will acknowledge your complaint within 5 business days and investigate within 30 days.

File a complaint with HHS Office for Civil Rights

Phone1-800-368-1019 (toll-free) · 1-800-537-7697 (TDD)
MailU.S. Department of Health and Human Services
200 Independence Avenue, S.W.
Washington, D.C. 20201
DeadlineComplaints must be filed within 180 days of when you knew or should have known of the violation.
No retaliation. AuthFight will not retaliate against you in any way for filing a complaint — with us or with HHS OCR. This is a protected right under 45 CFR §164.530(g).
10

Changes to This Notice

We may update this notice as our services, privacy practices, or legal obligations change. A revised notice will state its effective date and describe the practices that apply to health information we maintain, including information collected before the revision when permitted by applicable law and our contractual obligations.

When we make a material change to this Notice, we will:

  • Post the updated Notice on our website at authfight.com/hipaa with a new effective date.
  • Send email notification to all registered users at the address on their account.
  • Make a paper copy available upon request at no charge.

The most current version of this Notice is always available at authfight.com/hipaa. Previous versions are available upon request by emailing support@authfight.com.

11

Contact Our Privacy Officer

For questions about this Notice, to exercise your HIPAA rights, or to report a privacy concern, contact our designated Privacy Officer:

AuthFight Privacy Officer

Emailsupport@authfight.com
Subject line"HIPAA Privacy Officer"
Response timeWithin 30 days, or sooner when required by applicable law or contract

Legal disclaimer:This notice reflects AuthFight's current data practices. It does not constitute legal advice. This notice should be reviewed by a qualified healthcare privacy attorney before being published in a final production environment. Legal obligations vary based on specific business relationships and the nature of the health information handled.