DocketHealth DocketHealth

What DocketHealth does, and how it protects your data

This page is open to everyone — no account or sign-in required. Read it before you start a trial, or send it to whoever at your practice needs to sign off on security.

What DocketHealth does

One platform for documentation compliance and prior authorization, built for home health and specialty practices.

NoteProof: documentation compliance

Every note is scored against payer and state rules before it's billed — catching missing signatures, homebound status, and other fatal gaps automatically.

AuthRunner: prior authorization tracking

Know exactly what each payer requires, submit electronically via FHIR Da Vinci PAS, and never miss a deadline with automatic 72/168-hour clocks.

Denials & appeals

Capture the denial reason, get an AI-drafted appeal grounded in the patient's own documentation, review and edit it, and track your win rate by payer.

Payer scorecards

See approval rates and turnaround time by payer, so you know who to call and what to expect before you submit.

Flexible intake

Import patients from CSV, pull directly from any FHIR R4 EHR, or fax and scan documents in — OCR and AI structure them for your review, with a confidence score per field so you know exactly what to double-check.

Team, audit & billing

Role-based access, a tamper-evident audit log, and usage-based billing that scales with your practice.

AI-assisted accuracy, always human-reviewed

Semantic note review, payer-policy extraction, denial-risk scoring that factors in your documentation, and grounded appeal drafting — every AI suggestion is reviewed by your staff before it touches a claim. AI never makes a coverage or clinical decision on its own.

Active security monitoring

Behavioral anomaly detection flags unusual PHI access on your audit log, fraud/waste/abuse screening watches PA submission patterns, prompt-injection and PHI-leak guardrails scan every AI-generated draft, and login-risk scoring automatically requires a step-up code for a sign-in that looks unusual — all deterministic and explainable, reviewed by your team, never a black-box model.

Built for PHI, secured by default

Every organization gets the same protection, on every plan — not an add-on.

Security, privacy & AI FAQ

Is patient data encrypted?

Yes. All PHI (patient names, dates of birth, MRNs, payer member IDs), free-text PA and clinical narratives, and uploaded documents are encrypted at the application layer with AES-256-GCM before they're ever written to disk — so a leaked database credential, a stolen backup, or a disk snapshot exposes ciphertext, not usable PHI. The database connection itself is also TLS-encrypted in transit.

Is DocketHealth HIPAA compliant?

DocketHealth is built with the technical safeguards a HIPAA-regulated practice requires: encryption at rest and in transit, role-based access control, database-enforced tenant isolation, and a tamper-evident audit log. HIPAA compliance itself is a shared responsibility that also depends on your organization's own policies, training, and a signed Business Associate Agreement — please talk to our team before processing real PHI in production.

Can other organizations see my data?

No. Every organization's data is isolated twice over — once in the application layer, and a second time at the database layer via PostgreSQL Row-Level Security — so even a bug in one query can't leak another org's records.

How do you verify who's signing up?

Every new account must enter a one-time code sent to the email address used at signup before it can log in for the first time, so no one can create an active account with an email address they don't actually own.

Do you support single sign-on and multi-factor authentication?

Yes — TOTP-based multi-factor authentication with backup codes (which an admin can require org-wide), plus enterprise single sign-on via SAML 2.0 or OIDC.

Is there an audit trail of who did what?

Yes. Every sensitive action is written to a hash-chained audit log designed to make tampering detectable, and org admins can export it at any time.

Where is my data hosted?

On a managed PostgreSQL instance with Row-Level Security enforced at the database level, behind a TLS-terminated web service. See our documentation for the full technical architecture.

Does DocketHealth use AI? Is that safe for patient data?

Yes, in five specific places: semantic note review, payer-policy extraction, documentation-aware denial-risk scoring, appeal-narrative drafting, and per-field confidence on scanned/faxed intake. In every case the AI is given only the minimum data needed for that task and used strictly for extraction or analysis — text sent to the model is used to generate that one response and isn't used to train the underlying model. AI output is never written to a record or a claim without a human reviewing it first.

Does AI ever make the actual coverage, clinical, or billing decision?

No, never. Every AI feature in DocketHealth produces a suggestion, a draft, or a flag for a person to review — not a determination. Denial-risk scoring, for example, is a deterministic, explainable calculation (not an opaque model output) that only adjusts based on facts already in the record, like whether a note has a missing signature.

What happens if the AI is unavailable or gets something wrong?

Nothing stops working. If AI isn't configured or a call fails, the underlying action (saving a note, submitting a request, uploading a document) still completes — the AI step is simply skipped and marked as unavailable. Appeal drafting goes further: a deterministic template narrative is always prepared first, so staff never end up with nothing to review even if the AI-grounded draft can't be generated.

Do you monitor for suspicious account access?

Yes. Every login is scored against that user's own history — a brand-new IP, a rapid change from their last known IP, a new device, or a wildly atypical hour — and a risky sign-in automatically requires a one-time emailed verification code before it's granted, even for accounts without MFA enabled. Separately, a behavioral anomaly detector watches the audit log itself for patterns like an unusually large volume of PHI access or an off-hours bulk export, and surfaces them to your admins on the Security tab.

How do you protect against AI prompt-injection or hallucinated data in AI-drafted content?

Every document fed to an AI feature (a faxed referral, a pasted payer bulletin) is scanned for known prompt-injection patterns — text crafted to look like instructions rather than data — before extraction runs. Every AI-generated output (an appeal narrative, an extracted field) is separately scanned for PHI-shaped values that don't actually trace back to the source document, since those are either a hallucination or an over-disclosure. Both checks are advisory and logged; they never replace the human-review requirement every AI feature already has.

Do you help detect billing fraud or abuse?

Yes, as an advisory compliance signal, not an accusation or an automatic block. DocketHealth screens prior-authorization submission patterns for things like the same patient and procedure code resubmitted repeatedly in a short window, one submitter's volume unusually concentrated on a single procedure code, or a denial rate well above your organization's own baseline — the same kind of patterns a payer's own program-integrity team would eventually notice, surfaced first, internally, with time for your compliance officer to review and correct course.

Ready to try it? Start a free trial — or sign in if you already have an account.