Privacy First

Privacy Policy

Last Updated: June 20, 2026

shield1. Overview & Commitment to Privacy

ARC Health ("we", "us", or "our") is dedicated to protecting the privacy and security of medical and personal data. Our platform leverages advanced Artificial Intelligence (AI) to analyze surgical operative notes and generate Current Procedural Terminology (CPT) codes. This Policy explains how we collect, process, protect, and utilize information uploaded by users (such as surgeons, clinical coders, and administrators).

Given the highly sensitive nature of medical reports, ARC Health is engineered with a Privacy-First Architecture. We comply strictly with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH).

visibility_off2. Protected Health Information (PHI) & Hybrid Redaction

We believe the most secure way to handle Protected Health Information (PHI) is to prevent it from being stored on our servers in identifiable form. To achieve this, ARC Health implements a dual-layer **Hybrid Redaction Pipeline**:

  • Layer 1 (Browser-Side Redaction): Before any clinical document or text is transmitted to our servers, our client-side software automatically identifies and scrubs the 18 core HIPAA identifiers (including patient names, dates, facility details, and medical record numbers) using highly accurate local regex patterns and text parsers. These are replaced with secure placeholders (e.g., [PATIENT_NAME_1]). The original PHI remains exclusively in your browser's volatile memory.
  • Layer 2 (Server-Side Medical NER): As an extra line of defense, our server-side secure processor runs a specialized Named Entity Recognition (NER) model to catch any complex or structured identifiers missed by the client-side pass.

Important: Because of our hybrid redaction process, all underlying patient identities are completely stripped. The text sent to our secure AI inference engine (AWS Bedrock) contains absolutely zero patient-identifiable PHI.

psychology3. AI Processing & Subprocessors

To analyze clinical narratives and compile CPT codes, ARC Health forwards redacted notes to Amazon Web Services (AWS) Bedrock, which hosts our reasoning engine (Claude 3.5 Sonnet). AWS Bedrock operates under a comprehensive, signed Business Associate Agreement (BAA) with ARC Health. Your inputs and outputs are processed within a secure private cloud environment, and the AI models **never** use your clinical data for training or improvement.

model_training4. Use of De-Identified Data for AI Training

To constantly improve the accuracy, clinical reasoning, and performance of the ARC Health CPT Analyzer, we collect and retain **fully de-identified** operative reports (Safe Harbor Method).

Once clinical notes undergo our dual-layer redaction pipeline and are completely stripped of all 18 HIPAA identifiers, the remaining text consists solely of anatomical, surgical, and technique descriptions. Under HIPAA regulations, this fully de-identified data is no longer classified as PHI. By using the platform, you grant ARC Health implicit consent to utilize this de-identified data for machine learning model fine-tuning and development. This allows us to build a "Golden Dataset" of surgical techniques mapped to standard codes, improving medical coding globally.

history5. Data Retention & User-Managed Purging

ARC Health supports **User-Managed Retention** for operational data:

  • User Controls: Your coded notes and analysis histories are kept in our encrypted database so you can access, review, and export them at any time. You can manually delete any analyzed note or historical log from your dashboard instantly.
  • Account Deletion: Upon closing your account, all associated operational data is permanently purged from our active systems within 30 days.
  • Audit Trails: For compliance and regulatory tracking, security logs (access attempts, actions taken) are maintained for a minimum of six (6) years in accordance with HIPAA requirements. These logs contain no PHI.

lock6. Information Security Standards

We maintain state-of-the-art security measures to safeguard all operational data:

  • In-Transit: All transmissions between your browser and our servers are encrypted using TLS 1.3.
  • At-Rest: Our SQLite databases and storage systems are protected using server-side AES-256 encryption.
  • Access Controls: Multifactor authentication (MFA) is strictly enforced for administrative access, and strict role-based access control (RBAC) separates users from super-administrators.

contact_support7. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our HIPAA-compliant workflows, please contact our HIPAA Security Officer:

ARC Health Compliance Office

Email: compliance@archealth.com

Address: 100 Medical Plaza, Suite 400, San Francisco, CA 94143