RediMinds, Inc.

Privacy Policy

Last Updated: June 26, 2026Effective Date: June 26, 2026

RediMinds is an AI company purpose-built for healthcare workflows. We build AI agents and workflow automation for healthcare payers, providers, and administrative entities with a focus on high-stakes, compliance-sensitive processes. Privacy, security, and auditability are not afterthoughts at RediMinds — they are foundational to how our systems are designed and operated.

1Who We Are and How to Contact Us

RediMinds, Inc. ("RediMinds," "we," "our," or "us") operates www.rediminds.com and associated platforms. We provide AI agent and workflow automation technology to healthcare payers, providers, Independent Review Organizations (IROs), Independent Dispute Resolution Entities (IDREs), credentialing bodies, and related administrative organizations.

RediMinds holds URAC's AI in Healthcare accreditation and HITRUST e1 certification, maintains SOC 2 Type II attestation, and is pursuing Federal Risk and Authorization Management Program (FedRAMP) authorization. We operate under HIPAA as a Business Associate to our healthcare clients.

For privacy questions or to exercise your rights, use our Privacy Request Form or email privacy@rediminds.com.

2Scope of This Policy

This Privacy Policy applies to:

  • Visitors to www.rediminds.com and related web properties
  • Clients and authorized users of RediMinds’ AI platforms and workflow tools
  • Individuals whose data — including Protected Health Information (PHI), clinical records, credentialing records, legal dispute data, or disability evidence — is processed through our platform on behalf of our clients
  • Employees, contractors, and applicants of RediMinds to the extent described herein

This policy does not apply to third-party websites or services linked from our Site. Where a client's own privacy notice governs how that client collects and uses data before submitting it to RediMinds, the client's notice controls that collection.

This Privacy Policy should be read alongside our Terms of Service.

3Our Role: Data Processor vs. Data Controller

RediMinds operates in two distinct capacities with respect to personal information, and we believe transparency about this distinction is essential.

3.1 Data Processor (for Client Data)

When RediMinds processes data on behalf of a healthcare client — including PHI, credentialing records, clinical review files, payment dispute records, disability evidence, or any other personal data submitted by or through a client — RediMinds acts as a data processor. In this capacity:

  • The client is the data controller and determines the purpose and means of processing
  • RediMinds processes data only as instructed by the client and as permitted by applicable law and executed agreements (including Business Associate Agreements)
  • Individuals seeking to exercise rights over data processed by RediMinds on a client’s behalf should direct their requests to the client organization, which will engage RediMinds as needed

3.2 Data Controller (for Direct Data)

When RediMinds collects data directly from website visitors, prospective clients, platform users, or employees — such as contact information, account data, and usage analytics — RediMinds acts as the data controller and this Privacy Policy governs that processing.

4Data We Collect Directly

4.1 Contact and Account Information

When you engage with our website, request information, or create a platform account, we may collect:

  • Name, job title, organization name, professional email address, and phone number
  • Account credentials (username and encrypted password)
  • Billing and payment information (processed via PCI-compliant third-party payment processors — we do not store raw payment card data)
  • Professional credentials and NPI numbers for authorized clinical reviewer and arbitrator accounts

4.2 Usage and Technical Data

We automatically collect the following when you access our platforms:

  • Log data: IP addresses, browser type and version, operating system, ISP, date/time stamps, referring pages, and session duration
  • Device data: device identifiers, screen resolution, and hardware type
  • Platform usage: features accessed, workflows initiated, case navigation patterns, and in-platform interaction data (used in aggregate to improve usability and system performance)
  • Audit logs: all user actions within our platform are logged for security, compliance, and audit purposes (see Section 8)

4.3 Communications

We collect content you send us via email, support tickets, feedback forms, or our privacy request portal, including the nature of your inquiry and any information you voluntarily provide.

5Data We Process on Behalf of Clients (Client Data)

The core of RediMinds' work involves processing highly sensitive healthcare and administrative data submitted by or through our clients. This Client Data is governed by executed agreements with each client, including Business Associate Agreements where HIPAA applies. Categories of Client Data we may process include:

5.1 Protected Health Information (PHI)

Consistent with HIPAA and applicable BAAs, we may process:

  • Patient demographics: names, dates of birth, addresses, contact information
  • Medical records, diagnoses, treatment histories, clinical notes, and imaging reports
  • Health plan and insurance information, including member IDs and benefit details
  • Medication histories, lab results, and procedure records
  • Any other individually identifiable health information

5.2 Administrative and Legal Records

  • Medical billing records, claim dispute files, and payment determination documentation (IDR/No Surprises Act workflows)
  • Case files submitted for external clinical review (IRO workflows)
  • Workers’ compensation claim records and occupational injury documentation
  • Prior authorization requests, supporting clinical documentation, and payer determination records
  • Social Security Administration (SSA) disability evidence packages and medical opinion documents

5.3 Credentialing and Provider Data

  • Healthcare provider and clinician information: NPI numbers, DEA numbers, medical licenses, board certifications, specialty classifications
  • Primary source verification records and credentialing committee decisions
  • Reviewer eligibility and reviewer performance data
  • Clinician matching data used for case assignment

5.4 De-Identified and Aggregate Data

RediMinds may create de-identified datasets from Client Data in accordance with HIPAA's de-identification standards (45 CFR §164.514). De-identified data is not PHI and may be used to improve our AI/ML models, conduct research, and develop platform capabilities. We never re-identify de-identified data without express written authorization.

6Workflow-Specific Data Processing

RediMinds processes data across several distinct healthcare administrative workflows. Each workflow involves specific data types, regulatory requirements, and access controls. We describe each below to give you full transparency about how your data is handled in the context of the applicable service.

6.1 Independent Dispute Resolution (IDR) — No Surprises Act

RediMinds supports Independent Dispute Resolution Entity (IDRE) workflows under the Federal No Surprises Act (42 U.S.C. §300gg-111). Data processed includes:

  • Provider and facility billing records, claim amounts, and qualifying payment amount submissions
  • Payer explanation of benefits (EOB) and payment determination records
  • Arbitration case files, offer submissions, and arbitrator decisions
  • Party identification information for providers, facilities, and health plans

Access to IDR case data is strictly role-limited to assigned arbitrators, case managers, and authorized RediMinds operations staff. All IDR case data is retained in accordance with federal No Surprises Act recordkeeping requirements.

6.2 Independent Review Organization (IRO) — External Clinical Review

RediMinds supports external clinical review workflows for medical necessity, experimental/investigational treatment, and coverage determinations. Data processed includes:

  • Complete clinical case files: medical records, physician notes, lab results, imaging, and treatment histories
  • Peer-reviewed clinical guidelines and jurisdiction-specific coverage criteria matched to the case
  • Reviewer assignments, review determinations, and clinical rationale documentation
  • Cited patient story synthesis documents generated by our AI systems for reviewer use

IRO case files are accessible only to assigned independent clinical reviewers and authorized case management staff. AI-generated case summaries are clearly labeled and subject to mandatory human clinical review before any determination is issued.

6.3 Workers' Compensation — Utilization Review

For workers' compensation utilization review, RediMinds processes:

  • Work-related injury claim records, treatment requests, and medical necessity documentation
  • State-specific workers’ compensation guidelines and Official Disability Guidelines (ODG)
  • Reviewer determinations and required state-mandated documentation

Processing is conducted in compliance with applicable state workers' compensation utilization review regulations, which vary by jurisdiction. RediMinds maintains jurisdiction-specific workflow configurations to ensure compliance with each state's regulatory requirements.

6.4 Prior Authorization — Medical Necessity Review

For prior authorization support, RediMinds processes:

  • Authorization requests, supporting clinical documentation, and clinical criteria
  • Evidence-based clinical guidelines matched to the requested service, procedure, or treatment
  • Determination workflows and documentation for human reviewer decision-making

All prior authorization determinations involving clinical judgment are subject to human clinical reviewer oversight. RediMinds AI tools provide decision support, not autonomous determinations.

6.5 Clinician Credentialing and Provider Verification

RediMinds' credentialing AI processes:

  • Provider identity and demographic information (name, DOB, addresses, contact details)
  • Professional licenses, board certifications, DEA registration, and specialty classifications
  • Primary source verification (PSV) results from licensing boards, the NPDB, and other authoritative sources
  • Credentialing committee decisions, re-credentialing records, and reviewer eligibility status
  • Clinician performance monitoring data used for reviewer matching and quality oversight

Credentialing data is handled under applicable NCQA, URAC, and CMS credentialing standards. Access is limited to credentialing staff and authorized administrators. RediMinds does not disclose individual credentialing determinations except as authorized by the client organization and applicable law.

6.6 SSA Disability — Medical Evidence Organization

For Social Security Administration disability support workflows, RediMinds processes:

  • Medical evidence packages submitted in support of disability determinations
  • Physician and specialist opinions, treatment records, and functional assessment documents
  • AI-generated narrative syntheses of medical evidence, used by authorized reviewers

SSA disability data is handled with the highest level of data sensitivity controls. AI-generated syntheses are clearly identified and are used to assist — not replace — human adjudicator review.

7How We Use Information

We use collected information for the following purposes, consistent with applicable law and executed agreements:

  • Delivering contracted services: processing cases, generating AI-assisted outputs, supporting clinical and administrative review workflows
  • Platform operations: user authentication, access control, account management, and system reliability
  • AI/ML model improvement: using de-identified or aggregated data to train, validate, and improve our models (never using identifiable PHI without BAA authorization)
  • Compliance and audit: maintaining audit-ready documentation, access logs, and workflow records as required by HIPAA, URAC, federal and state regulations
  • Security and fraud prevention: monitoring for unauthorized access, anomalous behavior, and data integrity issues
  • Legal obligations: responding to lawful requests, regulatory inquiries, and exercising or defending legal claims
  • Platform analytics: understanding aggregate usage patterns to improve usability and performance
  • Client communications: service updates, security notifications, and support

8Artificial Intelligence and Machine Learning Governance

AI governance is not a compliance checkbox at RediMinds — it is embedded in how our systems are designed, deployed, and monitored. The following principles and controls govern all AI/ML processing on our platform.

8.1 URAC AI in Healthcare Accreditation

RediMinds has earned URAC's AI in Healthcare accreditation. Our AI systems are validated against URAC's standards for transparency, auditability, clinical oversight, and responsible AI use in healthcare workflows.

8.2 Human-Supervised Determinations

RediMinds AI systems are designed as decision-support tools, not autonomous decision-makers. For all clinical and administrative determinations — including medical necessity reviews, prior authorization decisions, IDR arbitration, and disability determinations — a qualified human reviewer must review and authorize any determination before it is finalized and issued. AI outputs that influence individual determinations are never issued without human oversight.

8.3 Auditability and Explainability

Our AI systems maintain:

  • Complete audit trails of all AI-generated outputs, including the inputs used, model version, and timestamp
  • Citations and source references embedded in AI outputs (cited patient story synthesis, guideline matching) so reviewers can verify underlying sources
  • Version-controlled model documentation enabling retrospective audit of past determinations
  • Case-level audit logs accessible to authorized client staff and regulatory auditors

8.4 Data Used for AI Training

We train and improve our AI/ML models using:

  • De-identified data created in compliance with HIPAA 45 CFR §164.514
  • Aggregated, anonymized usage and performance data
  • Publicly available clinical literature, guidelines, and evidence bases
  • Client-authorized training data, only pursuant to specific BAA provisions

We do not use individually identifiable PHI to train AI models without explicit BAA authorization. We do not sell AI-derived insights or model outputs derived from client or patient data to any third party.

8.5 Bias Monitoring and Fairness

We conduct ongoing monitoring of our AI/ML models for performance disparities across patient demographic groups. Any detected bias is documented, investigated, and addressed through model updates or workflow controls. Clients may report suspected bias or unexpected outputs through our support portal.

8.6 Third-Party AI Infrastructure

Where RediMinds uses third-party AI infrastructure or cloud AI services, those providers are vetted against our security and compliance standards, bound by data processing agreements, and prohibited from using client or patient data for their own model training.

9HIPAA Compliance and Business Associate Obligations

RediMinds operates as a HIPAA Business Associate with respect to all clients who are Covered Entities or Business Associates under 45 CFR Parts 160 and 164.

9.1 Business Associate Agreements

No PHI may be submitted to or processed through RediMinds platforms without a fully executed Business Associate Agreement (BAA) in place. Our BAAs address use and disclosure limitations, safeguard requirements, breach notification, subcontractor obligations, and PHI return or destruction upon termination.

9.2 Minimum Necessary Standard

RediMinds applies the HIPAA minimum necessary standard to all PHI processing: we access, use, and disclose only the minimum PHI necessary to accomplish the authorized purpose. Our role-based access controls enforce this standard at the system level.

9.3 Breach Notification

In the event of a breach of unsecured PHI, RediMinds will notify the applicable Covered Entity without unreasonable delay and no later than 60 calendar days following discovery, consistent with 45 CFR §164.410. Our incident response procedures include breach risk assessment, containment, client notification, and regulatory reporting support.

9.4 Subcontractors

Any RediMinds subcontractor or agent that accesses PHI on our behalf is required to execute a Business Associate Agreement with RediMinds containing protections at least equivalent to our own BAA obligations.

In the event of a conflict between this Privacy Policy and an applicable BAA with respect to PHI, the BAA governs.

10California Privacy Rights (CCPA/CPRA)

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides rights for California residents. Because RediMinds processes healthcare data across the United States — including for California-resident patients — these rights apply to our processing even when our direct clients are not California-based organizations.

10.1 Categories of Personal Information Collected

In the preceding 12 months, RediMinds has collected or processed the following categories:

  • Identifiers: names, email addresses, IP addresses, NPI numbers, account usernames, device identifiers
  • Professional information: job titles, organizations, professional licenses, specialties
  • Health/medical information: PHI processed under BAAs (subject to HIPAA exemption noted below)
  • Commercial information: service usage records and transaction histories
  • Internet/network activity: platform interaction data, log files
  • Inferences: workflow routing and preference data derived from platform use

10.2 Your California Rights

  • Right to Know: Request the categories and specific pieces of personal information we have collected, the sources, business purposes, and parties with whom it is shared
  • Right to Delete: Request deletion of personal information, subject to certain legal exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale or Sharing: RediMinds does not sell personal information and does not share it for cross-context behavioral advertising
  • Right to Limit Sensitive Personal Information: Limit our use of sensitive personal information to the purposes necessary to provide the Services
  • Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA/CPRA right

Note: CCPA/CPRA rights generally do not apply to PHI collected, used, and disclosed pursuant to and in compliance with HIPAA, to the extent that applying CCPA would be contrary to HIPAA (Cal. Civ. Code §1798.146).

To submit a California privacy request, use our Privacy Request Form. We respond within 45 days, with a possible 45-day extension for complex requests.

11GDPR Rights — EEA and United Kingdom Residents

Although RediMinds' clients are primarily U.S.-based, we are committed to compliance with the General Data Protection Regulation (GDPR) (EU 2016/679) and UK GDPR for any individuals in the EEA or United Kingdom whose personal data we process. This reflects our commitment to global privacy standards, not merely minimum legal compliance.

11.1 Legal Bases for Processing

  • Contract performance: Processing necessary to provide contracted services
  • Legitimate interests: Security, fraud prevention, platform analytics, and product improvement — balanced against your rights
  • Legal obligation: Compliance with HIPAA, applicable federal and state laws, and regulatory requirements
  • Consent: For non-essential cookies and certain communications; withdrawable at any time

11.2 Your GDPR Rights

  • Right of Access: Receive a copy of personal data we hold about you
  • Right to Rectification: Have inaccurate or incomplete data corrected
  • Right to Erasure: Have personal data deleted in certain circumstances
  • Right to Restrict Processing: Limit how we process your data in certain circumstances
  • Right to Data Portability: Receive data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Rights Related to Automated Processing: Not be subject to solely automated decisions with significant legal effects without human review (consistent with our human-supervised AI model)

Submit GDPR requests via our Privacy Request Form. We respond within 30 days. You may also lodge a complaint with your local supervisory authority.

11.3 International Data Transfers

RediMinds is U.S.-based. Where we transfer personal data from the EEA or UK, we use Standard Contractual Clauses (SCCs) approved by the European Commission or UK International Data Transfer Agreements (IDTAs), or other lawful transfer mechanisms. Contact us for details.

12Federal and Regulatory Compliance

RediMinds operates across multiple regulated healthcare and federal administrative contexts. The following frameworks govern our operations, and our privacy and security practices are designed to meet or exceed each:

12.1 Applicable Regulatory Frameworks

  • HIPAA / HITECH Act: Health privacy and security for PHI; BAA-governed processing for all Covered Entity clients
  • No Surprises Act (42 U.S.C. §300gg-111): Federal IDR process requirements for billing dispute workflows
  • State Workers’ Compensation Laws: Jurisdiction-specific utilization review and recordkeeping requirements
  • State Independent Review Laws: IRO processing requirements vary by state; RediMinds maintains jurisdiction-specific configurations
  • Social Security Act: Federal requirements governing disability adjudication evidence handling
  • URAC Accreditation: RediMinds holds URAC’s AI in Healthcare accreditation, validating our AI systems against URAC’s standards for transparency, auditability, clinical oversight, and responsible AI use in healthcare workflows
  • HITRUST e1 Certification: RediMinds maintains HITRUST e1 certification, validating the implementation of essential cybersecurity controls across our information security program
  • FedRAMP (Pursuing): RediMinds is pursuing Federal Risk and Authorization Management Program authorization, aligning our security controls with NIST SP 800-53
  • NCQA Standards: Our credentialing and clinical workflows are designed to support NCQA accreditation requirements for our client organizations
  • CCPA/CPRA: California consumer privacy rights (see Section 10)
  • GDPR / UK GDPR: European and UK data protection (see Section 11)

12.2 Privacy Impact Assessment

Consistent with FedRAMP and federal privacy best practices, RediMinds conducts Privacy Impact Assessments (PIAs) for new workflows, system changes, and data processing activities that involve new categories of personal information. PIAs are reviewed by our Privacy Officer and documented for audit purposes.

12.3 Records and Audit Support

RediMinds maintains complete audit-ready records for all workflows, including AI inputs/outputs, user actions, case timelines, and determination histories. These records can be made available to authorized client auditors, URAC reviewers, state regulators, and federal agencies pursuant to applicable law and executed agreements.

13Data Sharing and Third-Party Disclosures

RediMinds does not sell, rent, or trade personal information or PHI. We share data only in the following circumstances:

13.1 Authorized Disclosures

  • Client-directed: Sharing data as instructed by the client under the applicable BAA or service agreement (e.g., transmitting IDR determinations to required parties under the No Surprises Act)
  • Service providers and subprocessors: Vetted vendors who support our platform operations (cloud hosting, security monitoring, communication tools) under data processing agreements that restrict use to providing services to RediMinds
  • Legal requirements: Pursuant to valid legal process, court order, or regulatory obligation, with notice to the client where legally permitted
  • Business transfers: In connection with a merger, acquisition, or asset sale, subject to the same privacy commitments
  • Safety: To prevent imminent harm to a person or the public, as permitted by law

13.2 Subprocessor Transparency

We maintain a list of key subprocessors who may have access to Client Data. Clients may request our current subprocessor list by contacting us. We notify clients of material subprocessor changes with reasonable advance notice as specified in applicable agreements.

13.3 No Sale or Sharing for Advertising

RediMinds does not sell personal information or PHI. We do not share personal information for cross-context behavioral advertising. We do not use client or patient data to target advertising to individuals.

14Data Security and Controls

Our security program is designed to meet HIPAA Security Rule requirements, HITRUST CSF and URAC AI validation standards, and NIST SP 800-53 controls consistent with our FedRAMP pursuit. Key controls include:

14.1 Technical Controls

  • Encryption: Data encrypted in transit using TLS 1.2+ and at rest using AES-256 or equivalent
  • Access control: Role-based access controls (RBAC) enforce minimum necessary access; multi-factor authentication (MFA) required for all platform accounts
  • Network security: Firewalls, intrusion detection/prevention systems (IDS/IPS), and network segmentation
  • Audit logging: All user and system actions are logged, tamper-evident, and retained for compliance and forensic purposes
  • Vulnerability management: Regular penetration testing, vulnerability scanning, and patch management

14.2 Administrative Controls

  • Security policies: Comprehensive information security policies aligned with HIPAA and NIST frameworks
  • Employee training: All RediMinds staff complete HIPAA privacy/security and AI ethics training
  • Background checks: Required for all employees with access to PHI or Client Data
  • Vendor assessment: Third-party vendors are assessed for security posture before receiving access to any client data

14.3 Physical Controls

  • Data is hosted in SOC 2 Type II-certified and/or FedRAMP-authorized cloud infrastructure
  • Physical access to systems is restricted and monitored

14.4 Incident Response

RediMinds maintains a documented incident response plan including detection, containment, eradication, recovery, and post-incident review phases. HIPAA breach notification procedures are integrated into our incident response workflow. Clients are notified of security incidents affecting their data within the timeframes specified in applicable agreements and law.

Despite these controls, no system is 100% secure. We encourage platform users to use strong, unique passwords, enable MFA, and report any suspected unauthorized access immediately.

15Data Retention

Retention periods are determined by the applicable regulatory framework, client agreements, and legal requirements:

  • PHI (HIPAA): Minimum 6 years from creation or last effective date, or longer as required by applicable BAA or state law
  • IDR/No Surprises Act records: Retained in accordance with federal IDR recordkeeping requirements
  • Workers’ compensation records: Retained per applicable state workers’ compensation regulations
  • Credentialing records: Retained per NCQA, URAC, and client credentialing policies
  • SSA disability evidence: Retained per client agreement and applicable federal requirements
  • Audit logs and AI output records: Minimum 6 years for HIPAA-covered workflows; longer where required by specific regulations
  • Platform usage and analytics: Generally 24 months, then aggregated or deleted
  • Marketing and contact data: Until consent is withdrawn or as legally required

Upon termination of a client relationship, PHI and Client Data are returned to the client or securely destroyed as specified in the applicable BAA and service agreement.

16Cookies and Tracking Technologies

We use the following types of cookies and tracking technologies on our website:

  • Essential/strictly necessary cookies: Required for site security, authentication, and core functionality. These cannot be disabled.
  • Analytics cookies: Aggregate, anonymized data about site usage (page views, traffic sources, session duration). No individually identifiable data is associated with analytics.
  • Functional cookies: Store user preferences such as language settings and login state.
  • Marketing cookies: Only deployed with your explicit consent where required by law.

You can manage cookie preferences through our cookie consent banner or your browser settings. Our platform environments (as distinct from the public website) do not use third-party advertising or marketing cookies. Session cookies within authenticated platform environments are strictly necessary for security and functionality.

17Children's Privacy

Our website and platform services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us without parental consent, contact us immediately and we will take prompt steps to delete such information.

PHI and clinical data relating to minor patients is processed on behalf of our healthcare clients in accordance with applicable BAAs, HIPAA, COPPA where relevant, and any additional state-law protections for minor health records.

18Changes to This Policy

We will update this Privacy Policy as our Services, regulatory obligations, and privacy practices evolve. When we make material changes:

  • We update the “Last Updated” date at the top of this policy
  • We post a notice on our website and/or within the platform
  • We notify registered users by email where changes materially affect how their information is handled
  • For BAA-covered clients, changes affecting PHI processing are communicated and agreed in accordance with BAA amendment procedures

Continued use of our Services after the effective date of any update constitutes acceptance of the revised policy.

19Contact Us and Privacy Requests

For questions about this Privacy Policy, to exercise your privacy rights, or to report a privacy concern, please use one of the following:

Privacy Request Form (CCPA, GDPR, general)Submit a Privacy Request
Privacy Officer Emailprivacy@rediminds.com
General Inquirieswww.rediminds.com/contact

Mailing Address: RediMinds, Inc., 29777 Telegraph Road, Suite 1670, Southfield, Michigan 48034

When submitting a privacy request, please include sufficient information to verify your identity and locate your records. Response times: CCPA requests within 45 days (extendable by 45 days with notice); GDPR requests within 30 days (extendable by 2 months with notice). For BAA-covered data, we will coordinate with the applicable client Covered Entity.

RediMinds, Inc.Privacy PolicyEffective June 26, 2026See also our Terms of ServiceSubmit a Privacy Request