Privacy Policy & HIPAA Notice of Privacy Practices for EOBme

Effective Date: July 5, 2026

ART-ie LLC ("we," "us," or "our"), founded by LJ Duhart, operates the EOBme mobile application (the "Service"). This combined page informs you of our policies regarding the collection, use, processing, and disclosure of personal data and electronic Protected Health Information (ePHI) when you use our Service, your legal rights under the Health Insurance Portability and Accountability Act (HIPAA), and the choices you have associated with that data.

1. Information Collection and Use

We collect several different types of information for various purposes to provide and improve our Service to you.

Camera Permission and Document Scanning

The app requires access to your device's camera or photo library to allow you to scan and upload your Explanation of Benefits (EOB) documents. We use this capability solely to process, analyze, and securely store your insurance billing documents.

Personal, Financial, and Protected Health Information (PHI)

While using our Service, the app extracts sensitive data from your uploaded EOBs, such as patient names, member identifiers, provider names, deductible amounts, copays, coinsurance, billing/diagnosis codes, and service dates. This data constitutes Protected Health Information (PHI) under federal law and is utilized to provide you with an automated breakdown of your patient responsibility, track your out-of-pocket maximums, and generate appeal letters.

Biometric Data

The app may use biometric authentication (e.g., fingerprint or face recognition) provided by your device's operating system to secure access to the application locally. We do not collect, transmit, or have access to your actual biometric data; our system only receives a secure cryptographic confirmation of successful authentication from your device's native operating system.

2. Data Processing, Cloud Storage, and Business Associates

To provide advanced document analysis, secure infrastructure, and cross-device syncing, we utilize highly secure third-party services. Under HIPAA compliance guidelines, these providers operate as our Business Associates and are bound by legally executed Business Associate Agreements (BAAs) that mandate absolute data isolation, robust encryption safeguards, and zero-data-retention parameters for AI model training:

3. Data Sharing, Disclosure, and Prohibitions

We do not sell your personal, financial, or medical information to any third parties under any circumstances.

Your Protected Health Information will never be utilized or disclosed for marketing, advertising, or commercial monetization tracking without your explicit prior written consent. Your data is only shared with the trusted infrastructure partners mentioned above (Veryfi and Google Firebase) strictly for the automated purpose of operating the Service, processing your documents, and storing your data securely. We may disclose your PHI without your authorization only when explicitly required to do so by federal or state law, or in response to a legally enforceable court order or subpoena.

4. Technical and Security Safeguards

The security of your health data is paramount to us. In compliance with the HIPAA Security Rule, we maintain strict administrative, physical, and technical safeguards. We utilize secure, encrypted connections (HTTPS/TLS) when transmitting your data to our infrastructure partners and enforce rigid role-based token policies to ensure your data remains accessible only to your authenticated user profile. While we strive to use enterprise-grade means to protect your Personal Data, please remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure.

5. Your Legal Rights Under HIPAA

As the absolute owner of your healthcare data, you hold specific data privacy rights under federal regulations:

6. How to File a Privacy Complaint

If you believe your privacy rights have been violated, or if you have concerns regarding the data handling practices of the app, you hold an absolute legal right to file a formal complaint without fear of retaliation:

  1. You may contact our designated internal HIPAA Privacy & Security Officer directly at the compliance email listed below.
  2. You may file an official complaint with the Secretary of the U.S. Department of Health and Human Services (HHS) Office for Civil Rights through their online compliance web portal.

7. Changes to This Privacy Policy

We may update our Privacy Policy and Notice of Privacy Practices from time to time to maintain alignment with evolving federal rules or backend API changes. We will notify you of any changes by posting the new Privacy Policy text on this page, updating the "Effective Date" at the top of this policy, and deploying a clear in-app notice if core data permissions are altered.

8. Contact Our Privacy Office

If you have any questions about this combined Privacy Policy and HIPAA Notice, wish to exercise your legal data rights, or need to contact our compliance department, please reach out to our designated HIPAA officer: