Privacy Policy
Last updated: September 9, 2026
Introduction
Claim Copilot, Inc., doing business as Pinetree Health ("Pinetree Health," "Pinetree," "we," "our," or "us"), provides revenue cycle management and related administrative services to healthcare organizations. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through pinetree.health, our business operations, and the services we provide to clients.
This Policy applies to website visitors, prospective and current clients, client personnel, vendors, business partners, job applicants, and other people whose information we process for our own business purposes. It also explains our role when we process patient and healthcare information for clients.
This Policy is not a healthcare provider's HIPAA Notice of Privacy Practices and does not replace any notice provided by a physician, practice, facility, health plan, or other healthcare organization. If you are a patient with a question about your medical or billing record, contact the healthcare organization that provided your care.
Our Privacy Roles
Information used for our business
Pinetree generally determines the purposes and means of processing website, business-contact, recruiting, vendor, security, and administrative information. For this information, Pinetree acts as the business or controller where those terms apply.
Information processed for healthcare clients
When we process claims, billing, patient, payer, or clinical information to provide revenue cycle management services, we generally act only under the healthcare client's instructions and the applicable service agreement. Where the information is protected health information under HIPAA, Pinetree acts as a business associate and processes it under a signed Business Associate Agreement, or BAA.
The healthcare client remains responsible for its privacy notices, legal basis, patient authorizations, recordkeeping duties, and responses to patient rights requests. We assist the client as required by the BAA and applicable law.
Information We Collect
Information you provide
- Contact and professional information, such as name, business email, telephone number, title, employer, practice, specialty, and professional identifiers.
- Business and service information, such as service requests, statements of work, payer mix, practice details, workflows, implementation information, and client preferences.
- Billing and transaction information, such as billing contacts, invoices, payment status, tax information, and limited payment details supplied through our payment providers.
- Communications, such as messages, meeting notes, support requests, feedback, survey responses, and information submitted through forms or email.
- Recruiting information, such as resumes, employment history, education, references, interview notes, work authorization, and information voluntarily supplied during an application.
Information processed while providing services
At a client's direction, we may process patient demographics, insurance and eligibility information, claims, diagnoses, procedures, modifiers, charges, remittances, payments, denials, appeals, prior-authorization information, patient account information, communications, limited clinical documentation, and other records needed to perform the agreed revenue cycle services. This information may include PHI and other sensitive personal information.
Information collected automatically
When you visit our website or communicate electronically with us, we may collect IP address, approximate location derived from IP address, browser and device details, referring pages, pages viewed, timestamps, cookie identifiers, website interactions, and diagnostic, security, and performance information.
Information from other sources
We may receive information from healthcare clients, their patients and personnel, payers, clearinghouses, electronic health record and practice management vendors, payment processors, service providers, public sources, referrals, event organizers, recruiting platforms, and business partners. We process that information according to our role, the applicable agreement, and law.
How We Use Information
- Provide, manage, support, and improve our revenue cycle management and related administrative services.
- Prepare and submit claims, post payments, work accounts receivable, support denials and appeals, communicate with authorized parties, and perform other services stated in a client agreement.
- Establish and manage client, vendor, and business relationships, including onboarding, contracting, invoicing, payment, support, and communications.
- Operate, maintain, secure, troubleshoot, and improve our website, business systems, workflows, and service quality.
- Authenticate authorized users, manage access, detect fraud or misuse, investigate incidents, protect rights and safety, and maintain business continuity.
- Analyze operations, measure performance, forecast capacity, create reports, and develop new or improved service methods.
- Recruit and evaluate candidates and administer employment relationships.
- Comply with healthcare, privacy, tax, accounting, employment, sanctions, legal-process, recordkeeping, and other applicable obligations.
- Carry out another purpose disclosed when information is collected or to which the relevant person or client consents.
HIPAA and Healthcare Information
Before Pinetree creates, receives, maintains, or transmits PHI as a business associate, Pinetree and the applicable covered entity or business associate will enter into a BAA. The BAA establishes permitted uses and disclosures, required safeguards, incident-reporting duties, subcontractor obligations, support for individual rights, regulatory access, and return or destruction requirements.
We use and disclose PHI only as permitted by the BAA, the client's lawful instructions, and applicable law. We apply the minimum-necessary standard where required and do not use PHI for advertising, sell PHI, or use PHI to train a general-purpose artificial intelligence model without the client's express written authorization and any authorization required by law.
Patients should ordinarily direct requests to access, amend, restrict, or receive an accounting of disclosures of PHI to their healthcare provider or health plan. If we receive a request involving client-controlled PHI, we may refer it to the relevant client and assist that client as required by the BAA and law.
Artificial Intelligence and Automation
Pinetree may use artificial intelligence, rules-based automation, analytics, and other technology to assist personnel in performing revenue cycle services. Uses may include organizing records, extracting information, identifying discrepancies, prioritizing work, generating suggested content, and supporting quality review. Appropriate personnel may review, validate, supplement, or override automated output based on the task and risk.
We apply contractual, access, security, and confidentiality controls to service providers that support these activities. We do not permit an AI provider to use client PHI or confidential client information to train a provider's general-purpose models unless the client expressly authorizes that use in writing and it is lawful under the BAA and applicable law.
How We Disclose Information
Healthcare clients and authorized participants
We disclose service information to the healthcare client that controls it and, at that client's direction, to authorized patients, payers, clearinghouses, providers, banks, record systems, auditors, and other participants involved in billing, payment, healthcare operations, or compliance.
Service providers and subcontractors
We may disclose information to vendors that provide secure hosting, communications, analytics, payment processing, document handling, professional services, security, recruiting, and operational support. Vendors may process information only for authorized purposes and are subject to contractual privacy, confidentiality, security, retention, and deletion requirements. Subcontractors that process PHI must accept applicable HIPAA obligations.
Professional advisers and corporate transactions
We may disclose information to lawyers, accountants, auditors, insurers, financing sources, and other professional advisers under appropriate duties. Information may also be disclosed or transferred in connection with diligence, financing, a merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable confidentiality and legal requirements.
Legal, safety, and compliance purposes
We may disclose information when reasonably necessary to comply with law, valid legal process, payer or government-program requirements, or a lawful audit; enforce agreements; investigate fraud, abuse, overpayments, or security incidents; or protect patients, clients, Pinetree, or others. Where legally permitted and appropriate, we may notify the affected client before disclosing client-controlled information.
At your direction or with consent
We may disclose information when the relevant client or individual directs us to do so, consents, or intentionally makes information public.
No Sale or Behavioral Advertising
We do not sell personal information or PHI. We do not share personal information for cross-context behavioral advertising and do not use PHI for targeted advertising. If our practices change, we will update this Policy and provide any notice and choice required by law before the change applies.
Cookies and Website Analytics
Our public website may use cookies and similar technologies that are necessary for functionality, security, preferences, analytics, and performance. You can control many cookies through browser settings and any consent tool we make available. Blocking cookies may affect website functionality.
Browser-based Global Privacy Control signals are treated as opt-out requests where required by applicable law. Because there is no uniform standard for other Do Not Track signals, we do not currently respond to them unless legally required.
Do not submit PHI or other sensitive patient information through a public website form unless the form expressly states that it is approved for that purpose. Website analytics are not intended to receive PHI from client service workflows.
Data Retention and Secure Destruction
How retention periods are determined
We identify retention periods based on the information category, the purpose for which it was collected, the applicable client agreement or BAA, documented client instructions, our documented retention schedule, payer and audit requirements, limitation periods, security needs, and applicable law. Client-controlled information is retained for the period specified in the applicable agreement, BAA, or written instruction. Business information is retained only as long as reasonably necessary for the purposes described in this Policy and applicable legal obligations.
Deletion and destruction
When the applicable retention period ends or information is no longer needed, we delete, de-identify, return, or securely destroy it using a method appropriate to the information's sensitivity and storage medium. At the end of a healthcare client relationship, we return or destroy PHI as required by the BAA where feasible.
Limited retention exceptions
Information may remain in routine backups, legal archives, audit records, security records, or disaster-recovery systems until removed under the applicable documented schedule. Information retained because deletion is infeasible or law requires continued retention remains protected, is isolated from ordinary use where reasonably practicable, and is used only for the reason requiring retention. When that reason ends, the information is securely deleted or destroyed.
Contractual controls and confirmation
Our client and vendor agreements identify confidential information and require appropriate maintenance, access, retention, return, and destruction practices. Upon reasonable written request and where contractually appropriate, we will confirm completion of the return or destruction of client-controlled information in writing.
Data Security and Incident Response
We maintain administrative, technical, and physical safeguards designed to protect personal information and PHI against unauthorized access, use, disclosure, alteration, loss, and destruction. Depending on the information and system, safeguards may include access controls, least-privilege permissions, encryption, monitoring, logging, vulnerability management, workforce training, vendor review, incident-response procedures, and business-continuity measures.
No security program can eliminate every risk. If we confirm an incident affecting client-controlled information, we notify and cooperate with the affected client as required by the applicable agreement, BAA, and law. Any legally required notices to individuals, regulators, or others will be handled according to the parties' legal roles and agreements.
To report a suspected privacy or security issue, contact hello@pinetree.health.
Your Privacy Rights
Depending on your location and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a copy of personal information we control; object to or restrict certain processing; withdraw consent where processing is based on consent; opt out of certain sales, sharing, targeted advertising, or profiling; and appeal a decision concerning a request.
To submit a request concerning personal information Pinetree controls, contact hello@pinetree.health.
We may request information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where permitted by law, but we may verify the agent's authority and the individual's identity. We will not unlawfully discriminate against you for exercising a privacy right.
For PHI or patient billing information that we process for a healthcare client, contact the relevant healthcare provider or health plan. We may forward your request to that client and assist with its response as required by the BAA and law.
California Privacy Notice
This section applies to California residents to the extent the California Consumer Privacy Act applies to Pinetree and the information at issue. Certain medical information and PHI may be exempt from some CCPA requirements, but other business-contact and website information may remain covered.
Categories collected
- Identifiers and contact information, including names, addresses, email addresses, telephone numbers, IP addresses, and professional identifiers.
- Professional, employment, education, and business information.
- Commercial, contract, invoice, payment, and transaction information.
- Internet, device, security, and website activity information.
- Audio, visual, and communications information, such as meeting recordings when participants are notified and communications with us.
- Sensitive personal information and health-related information when processed under client instructions, a BAA, or another lawful basis.
- Inferences derived from business and operational information, such as service interests or workflow needs.
We collect these categories from individuals, healthcare clients, client personnel and systems, payers, clearinghouses, vendors, service providers, public sources, referrals, recruiting sources, and website interactions. We use and disclose them for the business purposes described in this Policy.
California rights
Subject to legal exceptions, California residents may request to know the categories and specific pieces of personal information collected, sources, purposes, and categories of recipients; request deletion or correction; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing when exercising rights. We do not sell or share personal information for cross-context behavioral advertising and do not use sensitive personal information for purposes that currently require a right to limit.
California residents or authorized agents may submit a request at hello@pinetree.health.
EEA, United Kingdom, and Switzerland
Where European data protection law applies to information we control, our legal bases may include performance of a contract or steps requested before a contract, compliance with legal obligations, consent, and legitimate interests such as operating and securing our business, communicating with business contacts, improving services, and preventing fraud. We balance legitimate interests against individual rights and expectations.
Individuals may have rights to access, correct, erase, restrict, object, receive portable data, withdraw consent, and complain to a supervisory authority. Where Pinetree processes personal data for a healthcare client, that client is generally responsible for responding, and we assist as required by contract and law.
If personal data is transferred to a country not recognized as providing adequate protection, we use an approved transfer mechanism where required, such as standard contractual clauses, together with supplementary measures appropriate to the transfer.
Children and Minor Patient Information
Our website and business services are directed to healthcare organizations and adults, not children. We do not knowingly collect personal information directly through the public website from children under 13. If you believe a child submitted information directly to us without appropriate authorization, contact us so we can review and delete it where required.
Our healthcare clients may direct us to process PHI or billing information concerning minor patients as part of revenue cycle services. That information is processed for the client under the BAA, client instructions, and applicable law and is not treated as information collected directly from a child through our public website.
International Processing
Pinetree and authorized service providers may process information in the United States and other locations where they operate. Privacy and data-protection laws may differ among jurisdictions. We use contractual, organizational, and technical measures required by applicable law and applicable client agreements for cross-border processing.
Third-Party Websites and Services
Our website and communications may link to third-party websites or services. Their privacy, security, and content practices are governed by their own policies. We are not responsible for third-party practices that we do not control. This does not limit our obligations for service providers or subcontractors processing information on our behalf.
Changes to This Policy
We may update this Policy to reflect changes in our services, practices, technology, or legal obligations. We will post the revised Policy and update the Last Updated date. If a change is material, we will provide additional notice when required by law or an applicable agreement. Changes do not reduce obligations in an existing BAA or signed client agreement unless that agreement is amended as permitted by its terms.
Contact Us
Questions, privacy requests, or security reports may be sent to hello@pinetree.health.
Claim Copilot, Inc., doing business as Pinetree Health.
