Privacy Policy
Privacy Policy
This policy explains what Claims Native collects, how we use it, and the choices you have. It covers claimsnative.com, the Claims Native app, and related emails.
Last updated September 16, 2026. Version 2026-09-16.
Who we are
Claims Native is a product of Atom & Bits, LLC, based in Chattanooga, Tennessee. We help independent practices handle insurance work: claim preparation, payer follow-up, remittance matching, and related setup.
Questions about this policy: [email protected].
What this policy covers
It applies when you visit the website, create an account, explore the sample workspace, accept a service agreement, or use Claims Native for live insurance work.
Your practice service agreement, if you accept one, can add terms for paid work. A business associate agreement is required before we create, receive, maintain, or transmit protected health information (PHI) for your practice. Those agreements control if they conflict with this policy on the same subject.
Information we collect
We collect only what we need to operate the product, communicate with you, and perform the work you authorize.
- Account and contact details: name, email, password (stored by our identity provider), verification and recovery codes, and messages you send us.
- Practice and service details: legal names, starting point, accepted service scope, fees, signature records, and the contacts you name.
- Workspace and product use: which screens you open in the sample or live workspace, and the nine product events we record when analytics is on.
- PHI and billing records, only after you authorize live work: visit, claim, coverage, remittance, and payment facts needed for the agreed lanes, plus source files and outside responses we must keep as evidence.
- Technical data: browser type, approximate time, and privacy signals such as Do Not Track and Global Privacy Control. We do not store payment card numbers.
How we use information
We use this information to:
- Create and secure your account, and send verification, recovery, and service email.
- Run the sample workspace on fictional patients and payments.
- Issue, accept, and retain service agreements and receipts.
- Perform the insurance work in an accepted agreement: eligibility, coding checks, claim filing, acknowledgments, status, denials, remittance posting, deposit matching, and patient balances.
- Connect to the practice systems, clearinghouse, and payers you authorize.
- Measure product use, find defects, and keep the service available.
- Meet legal, security, and record-keeping duties.
How we share information
We do not sell personal information or PHI. We do not share it for cross-context behavioral advertising.
We share information only as needed to run the product or as the law requires:
- Vendors who host the site and app, authenticate accounts, store data, send email, or measure product use. They may process data only to provide their service to us.
- Clearinghouses, payers, enrollment services, and your practice systems when you authorize a live route.
- People at your organization who have access to the practice workspace.
- Professional advisers, or authorities, when we must disclose information to meet a legal duty, enforce our terms, or protect a person or the service.
HIPAA and business associate status
The sample workspace uses fictional patients and payments. That data is not PHI.
When we handle PHI for your practice, we act as a business associate. We use and disclose that PHI only to provide the agreed services, as your practice instructs, or as HIPAA and the signed BAA allow. We apply the minimum necessary standard to those uses.
Your practice remains the covered entity (or the party that controls the designated record set). Clinical judgment, care records in your EHR, and decisions about what to bill stay with you unless an accepted agreement says otherwise.
Analytics and privacy signals
When analytics is enabled, we send a short list of product events to PostHog: signup viewed or submitted, email verified, signed in, sample setup prepared or started, and service-agreement viewed, accepted, or receipt viewed.
Each event includes a random journey ID, the event time, the release revision, a source name, and two privacy flags. It does not include email, names, passwords, codes, IP addresses, page URLs, form values, claim records, or agreement contents. Person profiles and GeoIP enrichment are off. We do not install a browser SDK, autocapture, or session replay.
If your browser sends Do Not Track or Global Privacy Control, we do not capture these events.
Cookies and similar storage
We use a signed session cookie so you stay signed in, and we store a journey ID in that session so analytics can follow one signup path. The cookie is necessary to use the app. We do not use advertising cookies.
Retention
Account, agreement, and receipt records stay for the life of the relationship and as long as we must keep them for legal, security, or audit reasons.
PHI and billing evidence stay for the retention period in your BAA and service agreement, then we delete or return them as those agreements require. Sample-workspace data stays until you reset it, close the account, or we remove an expired sample.
Analytics events, when captured, are kept only as long as needed to measure the product.
Security
We use access controls, encryption in transit, least-privilege vendor access, and immutable records for offers, receipts, and source evidence. No method of transmission or storage is completely secure. Tell us at [email protected] if you think an account or workspace was used without authorization.
Your choices and rights
You can refuse analytics with Do Not Track or Global Privacy Control. You can close your account, reset a sample workspace, and ask us for access, correction, or deletion of account information we hold.
If we process PHI as your business associate, we will help your practice respond to individual rights requests that apply to that PHI.
Residents of some U.S. states can ask us what personal information we collected, request deletion, and appeal a denial. We will not discriminate against you for exercising those rights. Email [email protected]. We may need to verify the request.
Children
Claims Native is for adult practice operators and their authorized staff. We do not knowingly collect personal information from children under 18.
Changes
We may update this policy. The new version is posted on this page with a new date and version. Material changes that affect an accepted service or BAA follow those agreements.
Contact
Atom & Bits, LLC
Chattanooga, Tennessee
Also read the Terms of Use.