Healthcare Privacy Standards

HIPAA Privacy Policy

How StatCura safeguards clinic credentials, electronic medical claims, and Protected Health Information (PHI) under strict HIPAA, HITECH, and international data protection standards.

Zero Sale of Patient Data
AES-256 Encrypted Datastores
US & UK Cross-Border Standards

No Advertising Brokers

We never share or commercialize patient records with external ad networks or third parties. Your data is used exclusively for medical billing.

End-to-End Encryption

All data in transit is encrypted using TLS 1.3, and all data stored at rest uses military-grade AES-256 encryption keys.

Full Audit Transparency

Immutable system logs record every claim scrubbing action, submission, and remittance posting under HIPAA Security Rule mandates.

Privacy Policy Terms

Last updated: January 2026. Effective for all medical practices using statcura.com.

1.0

Scope and Dual Regulatory Framework (US HIPAA & UK GDPR)

StatCura Medical Inc. (operating via statcura.com, referred to as 'StatCura', 'we', 'our', or 'us') maintains the highest standards of data security, healthcare confidentiality, and international compliance for independent medical practices, licensed physicians, clinic staff, and the patients they serve.

This Privacy Policy governs our cloud-based revenue cycle management (RCM) platform, automated claim scrubbers, clearinghouse interfaces, and clinic administrative portals.

Dual Regulatory Governance: StatCura operates in full compliance with United States federal healthcare privacy laws (the Health Insurance Portability and Accountability Act of 1996 'HIPAA', Public Law 104-191, as amended by the HITECH Act) and United Kingdom data privacy laws (the UK General Data Protection Regulation 'UK GDPR' and the UK Data Protection Act 2018).

2.0

Protected Health Information (PHI) Protection Standards

All patient identifiable health information created, received, maintained, or transmitted through StatCura is classified as Protected Health Information (PHI) under 45 CFR § 160.103 and electronic Protected Health Information (ePHI) under the HIPAA Security Rule.

Zero Commercialization Covenant: StatCura strictly covenants that it will never sell, lease, rent, license, or commercialize patient health data to data brokers, pharmaceutical marketers, advertising networks, or commercial AI aggregators.

Strictly Limited Processing: PHI is accessed and processed solely to perform contracted healthcare revenue cycle automation: National Correct Coding Initiative (NCCI) validation, electronic claim generation (ANSI ASC X12 EDI 837P), payer eligibility verification (EDI 270/271), autonomous clinical appeal preparation, and Electronic Remittance Advice (ERA 835) ledger auto-posting.

3.0

UK GDPR & UK Data Protection Act 2018 Compliance

Data Controller vs Data Processor Designation: For all patient health records, clinical encounter notes, and diagnostic data processed on behalf of the Practice, the Practice acts as the Data Controller (Article 4(7) UK GDPR), and StatCura acts strictly as the Data Processor (Article 4(8) UK GDPR). StatCura processes patient data exclusively upon documented instructions from the Practice.

StatCura as Data Controller for Practice Accounts: StatCura acts as a Data Controller solely with respect to business account administration data, physician NPI records, clinic billing contact details, and platform access credentials necessary to maintain customer relationship management and fulfill legal accounting duties.

Lawful Bases for Processing: Processing of practice administrative data is conducted under UK GDPR Article 6(1)(b) (contractual necessity) and Article 6(1)(c) (legal obligation). Processing of special category health data is conducted pursuant to UK GDPR Article 9(2)(h) (processing necessary for the management of health or social care systems and services).

UK International Data Transfer Compliance: Cross-border transfers between our United States clearinghouse endpoints and United Kingdom operations are governed by UK International Data Transfer Agreements (IDTA), Standard Contractual Clauses (SCCs), and rigorous technical safeguards in compliance with Chapter V of the UK GDPR.

4.0

Categories of Information Collected

Healthcare Practice Credentials: Practice legal entity name, National Provider Identifier (Individual Type 1 and Organization Type 2 NPIs), Federal Employer Identification Number (EIN/TIN), state medical license credentials, physical clinic addresses, and verified physician contact coordinates.

Clinical Encounter and Claim Records: Patient demographic identifiers, health plan policy and group numbers, date of service, ICD-10-CM diagnosis codes, CPT/HCPCS procedure codes, modifier designations, provider charge schedules, and clinical encounter progress notes required to substantiate medical necessity for insurance appeals.

Financial and Stripe ACH Credentials: Clinic business bank account numbers and routing transit numbers tokenized securely through Stripe Financial Connections to facilitate NACHA compliant ACH direct debits for earned 5% performance commission fees in United States Dollars ($ USD). Raw bank account numbers are never stored in plaintext on StatCura servers.

Immutable Technical Audit Data: System access timestamps, source IP addresses, browser user agents, cryptographic session tokens, and query parameters logged continuously to fulfill mandatory HIPAA Security Rule § 164.312(b) audit trail requirements.

5.0

Permitted Processing Operations and Limitations

Automated Claims Scrubbing: Validating billing entries against CMS National Correct Coding Initiative (NCCI) edits, Medically Unlikely Edits (MUE), and commercial payer payment policies prior to electronic submission.

Autonomous Medical Appeals: Compiling peer-reviewed clinical citations and provider chart notes to draft legally grounded reconsideration appeals for denied insurance claims within statutory timely filing limits.

Remittance Posting & Ledger Balancing: Parsing incoming ERA 835 electronic remittance files to reconcile payer adjudications against outstanding accounts receivable at line-item granularity.

Security and Fraud Prevention: Verifying multi-factor authentication (MFA) credentials, monitoring automated firewall defenses, and detecting unauthorized access vectors across all system endpoints.

6.0

Authorized Third-Party Disclosures & Intermediaries

Health Plans and Accredited Clearinghouses: We transmit claims and real-time eligibility requests to authorized commercial health maintenance organizations, preferred provider organizations, Medicare Administrative Contractors (MACs), and clearinghouse networks (such as Stedi) over dedicated TLS 1.3 encrypted conduits.

Stripe Financial Infrastructure: Financial settlements are processed through Stripe Inc., a certified Level 1 PCI-DSS service provider. Payment account tokens are managed within Stripe's hardened environment.

Zero Advertising Trackers: StatCura does not deploy third-party advertising pixels, commercial analytics beacons, or behavioral tracking scripts within any authenticated clinic portal, staff interface, or claim submission workflow.

Legal Compulsion and Regulatory Oversight: StatCura will disclose information only when strictly mandated by a valid judicial court order, federal subpoena, or lawful inquiry by the US Department of Health and Human Services (HHS) Office for Civil Rights or the UK Information Commissioner's Office (ICO).

7.0

Data Retention and Cryptographic Disposal

Statutory Healthcare Retention: In accordance with Centers for Medicare & Medicaid Services (CMS) regulations, False Claims Act investigative windows, and state medical record statutes, claim histories and remittance logs are retained for seven (7) years following the date of final claim adjudication.

NIST SP 800-88 Cryptographic Purging: Upon the expiration of statutory retention windows or upon validated contract termination, data records are permanently purged using cryptographic sanitization protocols complying with NIST Special Publication 800-88 standards.

8.0

Cross-Border Infrastructure & Transatlantic Safeguards

StatCura maintains an integrated transatlantic operational and engineering footprint operating across the United States and the United Kingdom.

Under 45 CFR § 164.502(e) of the HIPAA Rules, international technology providers are fully authorized to process US healthcare data when bound by an enforceable HIPAA Business Associate Agreement with equivalent security specifications.

All cloud repositories housing PHI are hosted in certified SOC 2 Type II and ISO 27001 data centers located within approved jurisdictions with AES-256 hardware encryption. International engineering personnel are bound by rigorous background checks, zero-trust network access controls, and strict confidentiality agreements.

9.0

Technical, Administrative, and Physical Safeguards

Cryptographic Encryption Standards: All data in transit is encrypted using TLS 1.3 with Perfect Forward Secrecy. All data at rest is encrypted using AES-256 with automated cryptographic key rotation via dedicated hardware security modules (HSMs).

Zero-Trust Access Governance: Platform access mandates multi-factor authentication (MFA), role-based access control (RBAC), and automated idle session terminations after 15 minutes of inactivity.

Automated Perimeter Defense: Continuous intrusion detection systems, web application firewall (WAF) rate limiting, and automated static code analysis security pipelines prevent unauthorized intrusion attempts.

10.0

Individual Rights (HIPAA & UK GDPR Data Subject Rights)

Practice Administrative Rights: Authorized clinic administrators may access, export, or update practice profile details, bank payout instructions, and staff permissions at any time via the Practice Portal.

HIPAA Access & Accounting: StatCura supports Covered Entities in fulfilling patient requests for access (45 CFR § 164.524), amendment (§ 164.526), and accounting of disclosures (§ 164.528) within ten (10) business days of written notice.

UK GDPR Data Subject Access Rights: To the extent UK GDPR applies, data subjects possess the right to request access, rectification, erasure, restriction of processing, and data portability regarding their personal data, subject to mandatory healthcare compliance record retention requirements.

Exercising Rights: Inquiries regarding data subject access rights should be directed to [email protected].

11.0

Breach Notification and Incident Response

HIPAA HITECH Timelines: In the event of a confirmed breach of unsecured PHI, StatCura will notify affected Covered Entities in writing without unreasonable delay and in no event later than sixty (60) calendar days from discovery, pursuant to 45 CFR § 164.410.

UK GDPR Incident Reporting: For incidents involving personal data governed by UK GDPR, StatCura assists the Data Controller in meeting its obligation to notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach.

12.0

Privacy Officers & Supervisory Authority Contacts

StatCura Data Protection & Privacy Office: [email protected] | [email protected] | StatCura Medical Inc., statcura.com

United States Regulatory Authority: Office for Civil Rights (OCR), US Department of Health and Human Services (HHS), 200 Independence Avenue, S.W., Washington, D.C. 20201 (hhs.gov/ocr).

United Kingdom Supervisory Authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom (ico.org.uk).

Relationship to the Business Associate Agreement

In the event of any conflict between this Privacy Policy and the StatCura HIPAA Business Associate Agreement (BAA) with respect to Protected Health Information, the terms of the BAA shall govern and control.

Have questions about our privacy practices?
Contact our designated Privacy Officer at statcura.com.