How CodeSync Health, Inc. collects, uses, and protects your information.
Effective March 31, 2026
This Privacy Policy describes how CodeSync Health, Inc. collects, uses, and protects your information through our websites and platforms.
1.1 This Privacy Policy (the “Policy”) describes how CodeSync Health, Inc., its subsidiaries, and affiliated companies (“CodeSync,” “we,” “us,” or “our”) may collect, use, and share information obtained through www.codesync.ai and other websites, mobile applications, and software platforms that link to this Policy (collectively, the “Sites”).
1.2 This Policy applies only to information collected through the Sites and does not govern CodeSync’s offline services or any other products or solutions that are subject to separate agreements or notices.
2.1 CodeSync is an AI-native healthcare technology company engaged in providing software-as-a-service (“SaaS”) platforms and Revenue Cycle Management (“RCM”) services to healthcare providers and organizations across the United States.
2.2 Our online platform offerings available through the Sites include a SaaS Charge Capture Platform, AI-native billing intelligence, and clearinghouse and payer connectivity that support the clinical billing workflows, financial operations, and business processes of our clients and their authorized users when they access and use the Sites. Any offline or separately contracted services are governed by separate agreements and are not covered by this Policy.
2.3 For more information about our services and offerings, please visit our website at www.codesync.ai.
3.1.1 Our website collects information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“Personal Information”). Personal Information does not include publicly available information lawfully made available from government records, de-identified or aggregated consumer information that cannot reasonably be linked to a particular consumer or household, or information otherwise excluded from the scope of applicable state or federal privacy laws.
3.1.2 Depending on how you interact with the Sites, the Personal Information we collect may include the following categories:
(a) Identifiers such as name, email address, phone number, Internet Protocol (IP) address, account username, and device identifiers;
(b) Professional and organizational information such as job title, National Provider Identifier (NPI), medical license number, specialty, and organization name;
(c) Financial, billing, and claims information such as payment details, insurance policy data, claims and remittance data, and payer identifiers;
(d) Technical, usage, and account data such as device type, browser, log data, session identifiers, login credentials, access permissions, activity logs, Multi-Factor Authentication (MFA) records, and platform clickstream data;
(e) Integration and portal data such as data received via Application Programming Interface (API) connections with Electronic Medical Record (EMR) systems, practice management systems, clearinghouses, and payer networks, as well as data retrieved through automated payer portal interactions conducted in connection with eligibility verification, benefits checking, and prior authorization workflows; and
(f) Artificial Intelligence (AI)-generated and interaction data such as coding suggestions, denial predictions, claim risk assessments, audit trail data, inputs and outputs from billing intelligence tools, real-time clinical transcriptions, AI-generated Subjective, Objective, Assessment, and Plan (SOAP) notes, audio recordings from automated payer calls, and structured data extracted from insurance cards, face sheets, and intake forms.
Where CodeSync’s Services involve access to or processing of Protected Health Information (the “PHI”) on behalf of a healthcare provider or contracted partner organization, such information is governed by one or more applicable agreements and not by this Policy. Please refer to Section 8.5 for more details.
4.1 Information Provided by You.
We obtain personal information in a number of ways, including through your use of the Sites when you:
(a) Submit inquiries, demo requests, or other contact forms through the Sites;
(b) Create, access, or manage user accounts and related preferences on the Sites;
(c) Interact with online features of our SaaS and AI-native tools that are made available through the Sites (for example, web-based dashboards, portals, or interfaces);
(d) Download or access content, resources, or materials made available through the Sites;
(e) Communicate with us via web-based chat, support widgets, or email links provided on the Sites; and
(f) Register for or participate in webinars, events, or other online sessions promoted or hosted through the Sites.
4.2 Information We Automatically Collect.
We automatically collect certain information through cookies and similar tracking technologies when you visit or interact with the Sites. For more details, please refer to our Cookie Policy.
4.3 Information from Partner Organizations.
CodeSync may receive limited personal information about you from contracted partner organizations, including billing intermediaries and healthcare service providers, for purposes such as creating or managing user accounts, granting access to the Sites, or supporting your use of our online tools. This may include identifiers (such as name, email address, phone number, and account username), professional details (such as job title, National Provider Identifier (NPI), medical license, specialty, and organization name), and usage or technical data related to your interaction with our Sites and support channels; any Protected Health Information (PHI) received from such organizations is governed solely by applicable agreements (such as Business Associate Agreements) and not by this Policy.
5.1 Storage.
CodeSync retains personal information only for as long as necessary to fulfill the purposes for which it was collected, as required by applicable law. Retention periods may vary depending on the nature of the information, the applicable legal or regulatory requirement, and the terms of the relevant client agreement. Upon expiration of the applicable retention period, personal information is securely deleted or anonymized in accordance with our internal data retention procedures.
5.2 Security.
5.2.1 The security of information transmitted through the Internet can never be guaranteed. We are not responsible for any interception or interruption of any communications through the Internet or for changes to or losses of data.
5.2.2 It is your responsibility to safeguard the devices you use to access our platform (such as laptops, tablets and mobile devices), and to use appropriate security settings on those devices.
5.2.3 In order to protect us, you and your information, we may suspend your use of the Site, without notice if any breach of security is suspected.
5.3 Retention Periods.
Without limiting the generality of the foregoing, CodeSync applies the following general retention guidelines, subject to applicable law and contractual obligations:
(a) Account and user information is retained for the duration of the relationship with the applicable client organization and for a reasonable period thereafter for legal, compliance, and audit purposes;
(b) Technical and usage data is retained for as long as necessary to support platform functionality, security monitoring, and analytics, typically not exceeding 24 months, unless required for a longer period for security or compliance purposes; and
(c) Information processed in connection with Revenue Cycle Management services, including billing and claims data, is retained in accordance with applicable healthcare regulations, contractual requirements, and industry standards.
We use information that we collect about you or that you provide to us, including any personal information, for the following purposes:
6.1 Service Delivery and Platform Operations.
To provide, operate, maintain, and improve our SaaS Charge Capture platform, RCM Services, and AI-native billing intelligence tools, including processing claims, verifying eligibility, managing denials, and posting payments on behalf of our contracted partner organizations. To create, maintain, and secure your account, process transactions, and authenticate authorized users accessing our platform.
6.2 AI and Analytics.
6.2.1 To analyze platform usage and billing patterns to improve our Services and enhance the accuracy of our AI-native tools. CodeSync’s Digital Workers operate on a continuous learning loop observing user activity, receiving human feedback, and iteratively improving automated workflows. Where permitted, we may use de-identified or aggregated data for internal research and model performance evaluation.
6.2.2 Human reviewers employed by or contracted to CodeSync may, as part of our Human-in-the-Loop (HITL) oversight model, review, verify, or override AI-generated outputs to ensure accuracy and compliance. All such reviewers are bound by applicable confidentiality obligations and, where PHI is involved, by the terms of any applicable agreement with the relevant covered entity or client organization.
6.2.3 CodeSync does not train its AI models on identifiable patient data or Protected Health Information (PHI) without explicit written authorization from the relevant covered entity under any applicable agreement.
6.3 Fraud Detection and Security.
To detect, investigate, and prevent fraudulent transactions, unauthorized access, security incidents, and other potentially prohibited or unlawful activity on our platform. To monitor platform activity, maintain audit logs, and enforce our agreements, terms of service, and internal security policies.
6.4 Communications.
To respond to your inquiries, support requests, and feedback, and to communicate with you regarding your account, platform updates, service changes, and billing matters. To send you operational notices, legal disclosures, policy updates, and other communications required or permitted under applicable law or our agreements with your organization.
6.5 Legal and Regulatory Compliance.
To comply with applicable federal and state laws and regulations, including HIPAA/HITECH, U.S. Privacy Laws, and other healthcare regulatory requirements. To respond to lawful requests from government authorities, regulatory bodies, or law enforcement, and to establish, exercise, or defend legal claims in any forum. To fulfill our obligations under executed Business Associate Agreements and other contractual commitments with our client organizations and partner entities.
CodeSync does not sell your personal information. We disclose personal information only in the following circumstances:
7.1 With Partner Organizations.
We may share your information with contracted partner organizations, billing intermediaries, healthcare service providers, clearinghouses, payers, and third-party service providers solely to the extent necessary to deliver our Services. This includes providers of payment processing, claim submission, data analytics, platform hosting, customer support, security monitoring, and audit services. All third parties receiving personal information are bound by confidentiality obligations and, where applicable, by other agreements consistent with HIPAA requirements.
7.2 With Healthcare Providers and Payers.
In connection with the submission and processing of claims, we may share billing and clinical information with government and commercial insurance payers, clearinghouses, and credentialing organizations solely as necessary to perform RCM Services on behalf of our contracted partner organizations.
7.2.1 Service providers engaged by CodeSync may process personal information solely for the purposes described in this Policy and in accordance with contractual obligations that require appropriate confidentiality, security, and data protection measures.
7.2.2 Such service providers retain personal information only for as long as necessary to perform their services or as required by applicable law.
7.2.3 For the avoidance of doubt, service providers are not permitted to use personal information for their own independent purposes.
7.3 By Law or To Protect Rights.
We may disclose your information where required or permitted by applicable law, regulation, legal process, or governmental request, or where we have a good-faith belief that disclosure is reasonably necessary to:
(a) Comply with applicable laws, regulations, legal obligations, or governmental requests;
(b) Enforce our agreements, terms, policies, and defend or pursue claims or litigation in any forum; or
(c) Protect the rights, property, safety, or interests of CodeSync, its clients, or the public, and prevent or act against fraud, misconduct, or unlawful activity.
7.4 Business Transfers.
In the event of a merger, acquisition, reorganization, sale of assets, or change of control, your information may be transferred to the successor entity, subject to the same protections described in this Policy.
7.5 With Your Consent.
We may share your information for any other purpose with your prior written consent or at your direction.
7.6 Third-Party API Consumers.
Where client organizations or authorized third-party developers access CodeSync’s platform through our public API to build custom workflows or integrations, such access is governed by the applicable API terms of use, integration agreements, and, where PHI is involved, any applicable agreements with the relevant covered entity or client organization. CodeSync does not grant API access to third parties for purposes inconsistent with this Policy or the applicable client agreement.
7.7 Cross-Border Data Transfers.
CodeSync may process and store personal information in the United States and in other jurisdictions where its service providers operate. Where personal information is transferred outside of your jurisdiction of residence, CodeSync implements appropriate safeguards consistent with applicable law, which may include contractual protections, data processing agreements, and other legally recognized transfer mechanisms designed to ensure an adequate level of data protection.
7.7.1 For the avoidance of doubt, this Section applies solely to personal information and does not apply to protected health information (PHI), which is handled in accordance with applicable healthcare laws, regulations, and contractual obligations, including business associate agreements where applicable.
7.7.2 By using the Sites, you acknowledge that your personal information may be transferred to and processed in jurisdictions that may have data protection laws different from those of your jurisdiction.
8.1 Scope of PHI Processing.
CodeSync may process protected health information (“PHI”) solely in its capacity as a service provider to healthcare providers, billing organizations, and other contracted partner organizations, and only in accordance with applicable healthcare laws and regulations, including the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (“HIPAA/HITECH”), and any applicable agreements.
8.2 Source of PHI.
CodeSync does not collect PHI directly from individuals through its publicly accessible websites or applications. Any PHI processed by CodeSync is received from or on behalf of covered entities or their authorized representatives, including in connection with billing, claims processing, and related Revenue Cycle Management workflows.
8.3 Permitted Use and Disclosure.
CodeSync processes PHI exclusively on behalf of its contracted clients and partner organizations, and solely for purposes permitted under applicable agreements and law. In accordance with the Minimum Necessary Standard under 45 C.F.R. Section 164.502(b), CodeSync limits access to PHI to what is necessary to perform its services.
8.4 Operational Use of PHI.
Certain CodeSync Services, including charge capture, clinical documentation support, data extraction from patient intake materials, and automated interactions with payer systems or portals, may involve the processing of PHI. Such activities are performed solely on behalf of the relevant covered entity or partner organization and in accordance with applicable agreements and regulatory requirements.
8.5 Relationship to This Privacy Policy.
This Privacy Policy governs only personal information collected through CodeSync’s general website and business operations. It does not govern CodeSync’s use or disclosure of PHI processed on behalf of healthcare provider clients or partner organizations. Such PHI is governed exclusively by:
(a) Applicable agreements between CodeSync and the relevant covered entity or partner organization;
(b) The Notice of Privacy Practices issued by the applicable healthcare provider or organization under 45 C.F.R. Section 164.520; and
(c) Any applicable integration, data use, or access agreements governing third-party systems.
Depending on your state of residence, you may have specific rights regarding your personal information under applicable data privacy laws. The following rights apply to residents of the states listed below.
9.1 California.
If you reside in California, you are afforded certain rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code Section 1798.100 et seq.), including the right to access, correct, and delete personal information, and the right to opt out of certain data sharing practices.
9.2 Texas.
If you reside in Texas, you are afforded certain rights under the Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Section 541.051 et seq., including the right to access, correct, delete, and obtain a portable copy of your personal information, as well as the right to opt out of the sale of personal data, targeted advertising, and certain profiling activities, and the right to non-discrimination for exercising such rights.
9.3 Delaware.
If you reside in Delaware, you are afforded certain rights under the Delaware Personal Data Privacy Act (DPDPA), Del. Code tit. 6, Section 12D-101 et seq., effective January 1, 2025, including the right to access, correct, delete, and obtain a portable copy of your personal information, the right to obtain information regarding third parties to whom your personal information has been disclosed, the right to opt out of the sale of personal data, targeted advertising, and certain profiling activities, and the right to non-discrimination for exercising such rights.
9.4 Virginia, Colorado, Connecticut, or Florida.
If you reside in Virginia, Colorado, Connecticut, or Florida, you are afforded certain rights under the applicable state privacy laws of your jurisdiction, including the right to access, correct, delete, and obtain a portable copy of your personal information, the right to opt out of the sale of personal data, targeted advertising, and certain profiling activities, and the right to non-discrimination for exercising such rights.
9.5 Other Jurisdictions.
Depending on your state or country of residence, you may have specific rights regarding your personal information under applicable data privacy laws, including but not limited to other U.S. state or international privacy regulations.
9.6 Exercising Your Rights.
We are committed to honouring these rights in accordance with the laws applicable to you in your jurisdiction. We will respond to all verified requests within the timeframe required by applicable law. To exercise any privacy rights applicable to you, you may:
i. Email us a request at privacy@codesync.ai
CodeSync reserves the right to amend this Policy at any time at its sole discretion, with material changes communicated by email or through a prominent notice on www.codesync.ai prior to taking effect and non-material changes effective immediately upon posting. The date of the most recent revision is indicated at the top section of this Policy under “Effective Date” and it is your responsibility to review this Policy periodically. Your continued access to or use of our platform or website following the effective date of any amendment shall constitute your acknowledgment and acceptance of the revised Policy.
We will not intentionally collect any personal information (as that term is defined in the Children’s Online Privacy Protection Act) from children under the age of 13 through our Sites without receiving parental consent.
If you think that we have collected such personal information from a child under the age of 13 through the Sites, please contact us immediately.
If you have any questions or comments about this Policy or if you have a disability and would like to access this Policy in an alternative format, please contact us by writing to:
Questions about this policy?
privacy@codesync.aiCodeSync Health, Inc. · 2625 New Concorde Ct, Herndon, VA 20171