Privacy Policy

Ambra is a revenue operations platform for EMS providers and the billing companies that serve them. This policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Effective September 16, 2025

Last updated July 28, 2026

founders@ambra911.com

At a glance

HIPAA compliant

Everything we do is HIPAA compliant. Business Associate Agreements are signed with every third party that handles PHI.

Encryption everywhere

All data is encrypted in transit with TLS 1.2 or higher and encrypted at rest.

Access controls

Role-based access control and JWT authentication limit each user to the data their role requires.

Audit logging

Complete audit trails cover all access to Protected Health Information.

7-year retention

PHI, claims, and related records are retained for seven years as required by HIPAA.

Breach response

If a breach affects PHI, we notify affected users within 72 hours of discovery and report to regulators as required by law.

Information we collect

Protected Health Information

• Patient identification: name, date of birth, contact information
• Insurance coverage, member identifiers, and eligibility responses
• Claims, remittance advice, and explanation of benefits documents
• Denial reasons, adjustment codes, and appeal correspondence
• Patient care report content where it substantiates a claim
• Dates of service and incident information from EMS transports

User account information

• Email address and encrypted password
• Role designation: admin, manager, staff, or developer
• Practice and billing-company associations

Technical information

• IP addresses for security and access control
• Session identifiers and API usage logs
• System diagnostics and error logs

The full policy

How we use your information

• Identify, classify, and work insurance denials
• Check and track the status of submitted claims with payers
• Verify patient insurance eligibility and coordination of benefits
• Draft appeal letters and assemble supporting documentation packets
• Submit appeals and records requests to payers by mail or payer portal
• Exchange claim, remittance, and eligibility data with clearinghouses and payers
• Integrate with billing and ePCR systems to retrieve the records a claim requires
• Maintain audit logs for HIPAA compliance
• Improve the accuracy of denial classification and appeal quality

Data security and HIPAA compliance

Everything we do is HIPAA compliant. We implement comprehensive security measures to protect your information:
• Encryption: all data encrypted in transit (TLS 1.2+) and at rest
• Access controls: role-based access control and JWT authentication
• Business Associate Agreements: all third-party providers have signed BAAs
• Audit logging: complete audit trails for all PHI access
• 7-year retention: PHI retained as required by HIPAA regulations
• Incident response: comprehensive breach notification procedures

Third-party services

We use HIPAA-eligible cloud infrastructure, AI, clearinghouse, and healthcare-integration subprocessors, each under a Business Associate Agreement where PHI is involved. A current list of subprocessors is available on request at founders@ambra911.com.

Data retention

• PHI, claims, and remittance records: 7 years as required by HIPAA
• Appeal correspondence and submission records: 7 years
• Account information: retained while active, plus 7 years after closure
• Audit logs: 7 years for compliance requirements

Your rights

• Access and download your claims, denials, and appeal documentation
• Export records in PDF format
• Update account information and patient records
• Delete individual claims and denials, subject to legal requirements
• Control sharing permissions within your organization

Children's privacy

Ambra is not intended for individuals under 18. Providers and billing companies using our service are responsible for obtaining appropriate consent for handling records relating to pediatric patient encounters.

Breach notification

In the event of a data breach affecting PHI, we will notify affected users within 72 hours of discovery and report to relevant regulatory authorities as required by law.

Changes to this policy

We may update this policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the last-updated date. By using Ambra, you agree to the collection and use of information in accordance with this policy.

Company information and contact

Ambra is operated by ParaScribe Inc., a Delaware C Corporation, doing business as Ambra.
For questions about this Privacy Policy or our privacy practices, contact founders@ambra911.com.

Assistive AI built responsibly for EMS.

Developed by a NREMT-certified team with thousands of field hours and 20+ years combined RCM experience.

Proudly made in the USA

Backed by

© 2026 ParaScribe Inc. All rights reserved.