CareCost CareCost Estimate™
Log in
Features Savings Reference Infusion Index Pricing Demo Log in Try CareCost Free

HIPAA Compliance

Last updated: September 27, 2026

CareCost is designed with a privacy-first architecture that does not need patient identifiers to build an estimate. The math runs in your browser. To look up prices, coverage rules and assistance programs, your browser sends our servers the drug code, the payer, and any diagnosis codes you enter. It never sends a patient’s name, date of birth or member ID, because the estimator never asks for them.

Architecture Overview

Estimate Calculation Flow

When your practice runs a cost estimate, data flows like this:

Your Browser (inputs entered here) → Client-side JavaScript (runs the math) → Browser (results displayed)

Drug pricing reference data (CMS ASP, HCPCS, ICD-10, assistance programs) is downloaded once per session and cached client-side. What goes to CareCost servers: the drug code and name, the payer or insurance type, and any diagnosis codes you enter, used to look up rates, coverage rules and assistance programs. The benefit numbers your staff type (deductible, amount met, coinsurance, out-of-pocket) stay in the browser, except in feedback (below); we log only a one-way code that tells two estimates apart. CareCost does not save estimates. To keep a copy, download the PDF.

What We Do

We Don't Collect PHI

  • The estimator never asks for patient names, dates of birth, member IDs, or any other patient identifiers
  • Estimates use only anonymous coverage parameters (deductible, coinsurance, out-of-pocket max) entered by your staff
  • No PHI is collected, transmitted, or stored — by us or in your browser
  • PDF estimates are made in your browser and saved to your computer. They show the drug, the costs and any diagnosis codes entered. There is no field for a patient’s name
  • When your staff send us feedback from the app, it is stored with a copy of the estimate on screen (drug, dose, patient weight, payer, state, costs and benefit amounts) so we can reproduce the problem. It never includes a patient’s name, and there is no field for one. Please do not type patient names into feedback.

Practice Data Isolation

  • Each practice's data is isolated using PostgreSQL Row-Level Security (RLS) policies
  • Users can only access data belonging to their own practice
  • Admin and staff roles have appropriately scoped permissions

Secure Authentication

  • JWT-based authentication with short-lived access tokens
  • Automatic token refresh
  • All API endpoints require valid authentication

Encryption

  • All data in transit is encrypted via TLS (HTTPS)
  • Database connections use SSL
  • Supabase encrypts data at rest

What We Do NOT Do

  • We do not store, cache, or log any PHI on our servers
  • We do not maintain a patient database or patient records
  • We do not transmit PHI to any third party
  • We do not use patient data for analytics, marketing, or any secondary purpose

BAA Considerations

Because CareCost’s estimate calculations run in the browser and the estimator never asks for patient identifiers, the HIPAA exposure profile is significantly reduced compared to systems that require patient data to function. Our architecture means:

  • Estimate math runs in the browser. The benefit numbers stay there unless your staff send feedback; the drug code, payer and diagnosis codes are sent to our servers for the lookups above
  • CareCost does not save estimates. Staff keep a copy by downloading the PDF
  • No part of the estimator asks for patient identifiers

For practices requiring a Business Associate Agreement (BAA), please contact us at legal@carecostestimate.com to discuss your requirements.

Your Responsibilities

As a covered entity, your practice is responsible for:

  • Ensuring authorized use of the service by your staff
  • Managing user access and removing former employees promptly
  • Using the service on secure, practice-controlled devices
  • Following your own HIPAA policies when handling the cost estimates and eligibility data displayed in your browser

Questions

For HIPAA-related questions or to request a BAA, contact us at legal@carecostestimate.com.

CareCost Estimate™

Cost estimates and payer coverage requirements for infusion centers and specialty practices.

Product
  • Features
  • Savings
  • Drugs
  • Fund Status
  • Pricing
  • Demo
  • Log In
  • Sign Up
Legal
  • Privacy Policy
  • Terms of Service
  • HIPAA Compliance
  • Methodology
  • Insurance Pricing Data
CareCost Estimate is an informational reference for healthcare providers. Outputs are estimates only and are not a guarantee of coverage, payment, or reimbursement. Providers are responsible for verifying coding and coverage with the applicable payer.
© 2026 CareCost. All rights reserved. Built for specialty practices