Compliance & Security
How LevelWise handles clinical data, and where it stands today.
Advisory only
LevelWise suggests an E&M / CPT level with supporting rationale. The treating provider reviews and confirms every code before billing. It is a second-check and documentation aid — not a replacement for professional coding judgment.
How clinical data is protected
You sign one BAA, and it's with us. LevelWise is the business associate: it carries the HIPAA obligations for a note once it leaves your office, and it holds the agreement with the cloud that runs the analysis. You don't open a cloud account, sign anything with a cloud vendor, or get a second bill.
Production: real patient notes are read by Claude running on Google Cloud, inside a Business Associate Agreement held by LevelWise — HIPAA-permitted handling under contract, not reliance on de-identification alone. The note is never stored: it is analyzed in the request and discarded.
Defense-in-depth: as a second layer, clinical notes are scanned against the 18 HIPAA Safe Harbor identifiers (45 CFR §164.514(b)) in your browser, and you review the redactions, before anything is sent.
Status: real-patient use is gated — the BAA must be executed and the compliance roadmap completed first. Until then, the public site runs in sample mode with no real PHI, and the production endpoint fails closed rather than returning a sample result.
Demo / sample mode
The public site runs in sample mode: results are illustrative and are clearly badged as such. Do not enter real patient information in the public demo.
Data & access
- Accounts and saved analyses are stored in Supabase with row-level security — each user sees only their own records.
- Saved audit records contain only de-identified coding data (level, CPT, MDM rationale, your final billed code).
- No live model key is exposed in the public deployment.