Data & PHI notice

EstimateHarbor stores Good Faith Estimate data — not a clinical or medical record. A client’s name and date of birth are, on their own, protected health information under HIPAA once they’re tied to a health service, which is exactly what a GFE is. We treat them that way even though the estimate itself contains nothing about diagnosis, treatment, or session content beyond an optional, provider-entered note.

What’s minimized

  • No session notes, treatment plans, or progress documentation — the form doesn’t have a field for them.
  • No insurance ID numbers or payer information — GFEs are for self-pay and non-billed care.
  • Diagnosis is optional and free-text, entered only if you already have one and choose to include it.
  • We don’t require a client to create an account or log in to view their estimate.

What’s encrypted

Client name, date of birth, client email, and your practice’s TIN are encrypted at rest with AES-256-GCM, using a key that isn’t stored alongside the database. Provider name, NPI, and service address are stored in the clear — they’re public information under the NPI registry and generally printed on your own website already.

Business Associate Agreements

If your practice needs a signed BAA to use a vendor that touches PHI-adjacent data, email support@estimateharbor.com. We haven’t pursued a SOC 2 or HITRUST audit — if that’s a hard requirement for your practice, this may not be the right tool yet.

Not legal advice

This page describes how the product handles data. It isn’t a legal opinion about whether your specific use of EstimateHarbor satisfies HIPAA or any other law that applies to your practice.

Data & PHI notice — EstimateHarbor