Start free for 7 days — No credit card required Start Now

Security & HIPAA

Last updated: January 2026

Our Position

ResolveRCM is PHI-aware but not a PHI custodian. We do not store Protected Health Information on our servers.

Key Safeguards

HIPAA

ResolveRCM does not act as a Business Associate and does not store PHI on its systems. Users are responsible for HIPAA compliance related to locally stored exports.

Our architecture is designed with HIPAA's "minimum necessary" principle in mind — we only process de-identified clinical information necessary to generate appeal documentation.

Data Flow

  1. User enters de-identified clinical facts (no PHI)
  2. AI generates appeal content with placeholder tokens
  3. PHI stored in browser's local storage is merged client-side
  4. Final document is exported directly to user's device

Contact

For security inquiries, contact us at:

Email: support@resolvercm.com