Subprocessors

Last updated: 2026-06-14 · Customer BAA: v1.0 (off-the-shelf template, 2026-06)

ClaimCare Pro uses the following third-party processors. Vendors marked Signed have a Business Associate Agreement on file under 45 CFR §164.504(e). Vendors marked Not in scope do not access Protected Health Information.

Active subprocessors

VendorService usedPHI scopeBAA statusSigned evidence
Amazon Web ServicesDynamoDB, S3, Lambda, Cognito, CloudWatch, SNS, KMS, AppSyncAll PHI at rest and in transit — primary data storeSignedAWS Artifact (auto-accepted via account console)
AnthropicClaude API for superbill extraction, denial triage, coding-suggestSuperbill PDFs and claim text sent to Claude for inferenceSignedAnthropic Trust Center BAA
Claim.MD837P/EDI claim submission and 835 ERA retrievalFull claim payload (subscriber + service lines) and remittanceSignedPer Claim.MD account dashboard
SquarePatient card-not-present payment processingPatient name, billing address, amount, transaction ID — no diagnosis, no treatmentSignedSquare seller dashboard
Vercel / Amplify HostingStatic asset CDN; SSR runs in customer-region AWS LambdaNo PHI — static marketing assets onlyNot in scope
SSR Lambda runs inside our AWS account, covered by AWS BAA.
GitHubSource code hostingNo PHI — code only; CI runs against synthetic seed dataNot in scope

Customer Business Associate Agreement

ClaimCare Pro signs a BAA with every customer covered entity before any PHI flows through the service. The current customer- facing BAA template is available below.

Download ClaimCare Pro BAA (v1.0 (off-the-shelf template, 2026-06))

For pre-signed or negotiated agreements, contact privacy@accuratebillingandcoding.com.

Notification of new subprocessors

When ClaimCare Pro adds a new subprocessor that will process PHI, we update this page and notify customers by email at least 30 days in advance. Customers may object to the new subprocessor per the terms of their signed BAA.