Claims Native

Sandbox workspace: fictional patients. Claims go to the clearinghouse test lane until go-live.

Privacy Policy

Privacy Policy

This policy explains what Claims Native collects, how we use it, and the choices you have. It covers claimsnative.com, the Claims Native app, and related emails.

Who we are

Claims Native is a product of Atom & Bits, LLC, based in Chattanooga, Tennessee. We help independent practices handle insurance work: claim preparation, payer follow-up, remittance matching, and related setup.

Questions about this policy: [email protected].

What this policy covers

It applies when you visit the website, create an account, explore the sample workspace, accept a service agreement, or use Claims Native for live insurance work.

Your practice service agreement, if you accept one, can add terms for paid work. A business associate agreement is required before we create, receive, maintain, or transmit protected health information (PHI) for your practice. Those agreements control if they conflict with this policy on the same subject.

Information we collect

We collect only what we need to operate the product, communicate with you, and perform the work you authorize.

How we use information

We use this information to:

How we share information

We do not sell personal information or PHI. We do not share it for cross-context behavioral advertising.

We share information only as needed to run the product or as the law requires:

HIPAA and business associate status

The sample workspace uses fictional patients and payments. That data is not PHI.

When we handle PHI for your practice, we act as a business associate. We use and disclose that PHI only to provide the agreed services, as your practice instructs, or as HIPAA and the signed BAA allow. We apply the minimum necessary standard to those uses.

Your practice remains the covered entity (or the party that controls the designated record set). Clinical judgment, care records in your EHR, and decisions about what to bill stay with you unless an accepted agreement says otherwise.

Analytics and privacy signals

When analytics is enabled, we send a short list of product events to PostHog: signup viewed or submitted, email verified, signed in, sample setup prepared or started, and service-agreement viewed, accepted, or receipt viewed.

Each event includes a random journey ID, the event time, the release revision, a source name, and two privacy flags. It does not include email, names, passwords, codes, IP addresses, page URLs, form values, claim records, or agreement contents. Person profiles and GeoIP enrichment are off. We do not install a browser SDK, autocapture, or session replay.

If your browser sends Do Not Track or Global Privacy Control, we do not capture these events.

Cookies and similar storage

We use a signed session cookie so you stay signed in, and we store a journey ID in that session so analytics can follow one signup path. The cookie is necessary to use the app. We do not use advertising cookies.

Retention

Account, agreement, and receipt records stay for the life of the relationship and as long as we must keep them for legal, security, or audit reasons.

PHI and billing evidence stay for the retention period in your BAA and service agreement, then we delete or return them as those agreements require. Sample-workspace data stays until you reset it, close the account, or we remove an expired sample.

Analytics events, when captured, are kept only as long as needed to measure the product.

Security

We use access controls, encryption in transit, least-privilege vendor access, and immutable records for offers, receipts, and source evidence. No method of transmission or storage is completely secure. Tell us at [email protected] if you think an account or workspace was used without authorization.

Your choices and rights

You can refuse analytics with Do Not Track or Global Privacy Control. You can close your account, reset a sample workspace, and ask us for access, correction, or deletion of account information we hold.

If we process PHI as your business associate, we will help your practice respond to individual rights requests that apply to that PHI.

Residents of some U.S. states can ask us what personal information we collected, request deletion, and appeal a denial. We will not discriminate against you for exercising those rights. Email [email protected]. We may need to verify the request.

Children

Claims Native is for adult practice operators and their authorized staff. We do not knowingly collect personal information from children under 18.

Changes

We may update this policy. The new version is posted on this page with a new date and version. Material changes that affect an accepted service or BAA follow those agreements.

Contact

Atom & Bits, LLC

Chattanooga, Tennessee

[email protected]