EstimateHarbor stores Good Faith Estimate data — not a clinical or medical record. A client’s name and date of birth are, on their own, protected health information under HIPAA once they’re tied to a health service, which is exactly what a GFE is. We treat them that way even though the estimate itself contains nothing about diagnosis, treatment, or session content beyond an optional, provider-entered note.
Client name, date of birth, client email, and your practice’s TIN are encrypted at rest with AES-256-GCM, using a key that isn’t stored alongside the database. Provider name, NPI, and service address are stored in the clear — they’re public information under the NPI registry and generally printed on your own website already.
If your practice needs a signed BAA to use a vendor that touches PHI-adjacent data, email support@estimateharbor.com. We haven’t pursued a SOC 2 or HITRUST audit — if that’s a hard requirement for your practice, this may not be the right tool yet.
This page describes how the product handles data. It isn’t a legal opinion about whether your specific use of EstimateHarbor satisfies HIPAA or any other law that applies to your practice.