BAA terms for production PHI use.
ClearClaim Verify is built for healthcare eligibility workflows. This page gives customers and reviewers the baseline BAA posture before production protected health information is used in the signed-in product.
Purpose and relationship
• Almas Orbit LLC d/b/a ClearClaim Verify is the Business Associate identified in this agreement when a covered entity or business associate customer uses ClearClaim Verify with protected health information.
• This Business Associate Agreement page describes the baseline terms ClearClaim Verify expects to use when a covered entity or business associate customer uses the signed-in product with protected health information.
• ClearClaim Verify provides eligibility workflow software for reviewing payer-returned information, Check Details, handoff summaries, report PDFs, History, team access, billing, and support workflows.
• The customer remains responsible for clinical judgment, payer-contract interpretation, medical necessity decisions, patient-facing quotes, collection decisions, and local compliance workflows.
Permitted PHI use
• ClearClaim Verify may create, receive, maintain, or transmit PHI only as needed to provide and support the signed-in eligibility workflow, secure the service, troubleshoot customer-reported issues, maintain audit-friendly records, and meet legal obligations.
• ClearClaim Verify does not sell patient information and does not use PHI for advertising or public-site analytics.
• Public website forms, demo scheduling notes, and ordinary support email should remain PHI-free unless ClearClaim routes the customer to a controlled support process appropriate for PHI.
Safeguards and access controls
• ClearClaim Verify will use administrative, technical, and physical safeguards designed to protect electronic PHI handled by the service.
• Access controls, role-aware workflows, session controls, encrypted PHI storage, audit-oriented records, and PHI-conscious support guidance are part of the product and operating posture.
• Customers are responsible for inviting only authorized users, choosing appropriate roles, removing access when staff no longer need it, and preventing PHI from being sent through public channels.
Reporting and cooperation
• ClearClaim Verify will investigate suspected unauthorized use, disclosure, or security incidents involving PHI and will provide customer notice according to the signed agreement and applicable law.
• Customers should report security, privacy, or access concerns to support without including patient identifiers in the initial email.
• ClearClaim Verify will reasonably cooperate with customer requests needed to support HIPAA-related investigation, accounting, amendment, access, or restriction workflows where applicable to the service.
Subprocessors
• ClearClaim Verify may use service providers for hosting, database, email delivery, payment processing, monitoring, support, and eligibility workflow infrastructure.
• Where a service provider handles PHI on ClearClaim Verify’s behalf, ClearClaim should maintain appropriate written terms with that provider before production PHI use.
• Customer-facing support and demo channels should not be used to send PHI unless a controlled support channel has been explicitly provided.
Return, deletion, and termination
• At termination, ClearClaim Verify will return or delete PHI according to the signed agreement, product retention needs, legal obligations, backup retention, and audit-record requirements.
• If return or deletion is not feasible for a limited retained copy, ClearClaim Verify will continue applying appropriate protections and limit further use or disclosure.
• Billing records, security logs, audit records, and operational metadata may be retained where needed to operate, secure, defend, or document the service.