SuperbilledSuperbilled

Privacy Policy

Last updated: March 2026

Who We Are

Superbilled is a superbill generator built for HIPAA-covered therapy practices, operated by Superbilled, Inc. For privacy inquiries, contact us at privacy@superbilled.com.

Information We Collect

  • Provider account info: name, email, NPI, EIN, and license number.
  • Client PHI entered by the provider: client name, date of birth, and insurance ID.
  • Session data: CPT codes, ICD-10 codes, session dates, and fees.

How We Use Your Information

  • To generate and store superbill PDFs on your behalf.
  • To send superbills by email when you request it.
  • We do not sell your data. We do not use PHI for training AI models.

Data Storage and Security

Client names, dates of birth, insurance IDs, and billing codes are encrypted at rest with AES-256 and in transit with TLS, on SOC 2-audited infrastructure through Supabase, hosted on AWS. Only your account can access your clients' data. We sign a Business Associate Agreement (BAA) with every provider during onboarding, so you stay compliant with your own HIPAA obligations as a Covered Entity.

Data Retention

  • Provider account data is retained for the life of your account.
  • PHI is retained for 6 years per HIPAA requirements, then permanently deleted.

Third-Party Services

  • Supabase: database and file storage.
  • Stripe: billing (no PHI is shared).
  • Resend: transactional email delivery.
  • Vercel: application hosting.
  • PostHog: product analytics. Usage metadata only — no client PHI is sent.
  • Anthropic: AI code suggestions. Receives session duration and billing codes only — never session notes or client details.

Contact

For privacy-related questions, email us at privacy@superbilled.com.