Effective Date: September 16, 2025
Last Updated: July 28, 2026
Welcome to Ambra ("we," "our," or "us"). Ambra is a revenue operations platform for Emergency Medical Services (EMS) providers and the billing companies that serve them. We work insurance denials and track the status of submitted claims. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By using Ambra, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this privacy policy, please do not access or use our services.
Information We Collect
User Account Information
- • Email address and password (encrypted)
- • Role designation (admin, manager, staff, developer)
- • Practice and billing-company associations
Protected Health Information (PHI)
- • Patient identification (name, date of birth, contact information)
- • Insurance coverage, member identifiers, and eligibility responses
- • Claims, remittance advice, and explanation of benefits documents
- • Denial reasons, adjustment codes, and appeal correspondence
- • Patient care report content where it substantiates a claim
- • Dates of service and incident information from EMS transports
Technical Information
- • IP addresses for security and access control
- • Session identifiers and API usage logs
- • System diagnostics and error logs
How We Use Your Information
- • Identify, classify, and work insurance denials
- • Check and track the status of submitted claims with payers
- • Verify patient insurance eligibility and coordination of benefits
- • Draft appeal letters and assemble supporting documentation packets
- • Submit appeals and records requests to payers by mail or payer portal
- • Exchange claim, remittance, and eligibility data with clearinghouses and payers
- • Integrate with billing and ePCR systems to retrieve the records a claim requires
- • Maintain audit logs for HIPAA compliance
- • Improve the accuracy of denial classification and appeal quality
Data Security & HIPAA Compliance
Everything we do is HIPAA compliant. We implement comprehensive security measures to protect your information:
- • Encryption: All data encrypted in transit (TLS 1.2+) and at rest
- • Access Controls: Role-based access control and JWT authentication
- • Business Associate Agreements: All third-party providers have signed BAAs
- • Audit Logging: Complete audit trails for all PHI access
- • 7-Year Retention: PHI retained as required by HIPAA regulations
- • Incident Response: Comprehensive breach notification procedures
Third-Party Services
We use HIPAA-eligible cloud infrastructure, AI, clearinghouse, and healthcare-integration subprocessors, each under a Business Associate Agreement where PHI is involved. A current list of subprocessors is available on request at founders@ambra911.com.
Data Retention
- • PHI, Claims, and Remittance Records: 7 years as required by HIPAA
- • Appeal Correspondence and Submission Records: 7 years
- • Account Information: Retained while active plus 7 years after closure
- • Audit Logs: 7 years for compliance requirements
Your Rights
- • Access and download your claims, denials, and appeal documentation
- • Export records in PDF format
- • Update account information and patient records
- • Delete individual claims and denials (subject to legal requirements)
- • Control sharing permissions within your organization
Children's Privacy
Ambra is not intended for individuals under 18. Providers and billing companies using our service are responsible for obtaining appropriate consent for handling records relating to pediatric patient encounters.
Breach Notification
In the event of a data breach affecting PHI, we will notify affected users within 72 hours of discovery and report to relevant regulatory authorities as required by law.
Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date.
Company Information
Ambra is operated by ParaScribe Inc., a Delaware C Corporation, doing business as Ambra.
Contact Us
For questions about this Privacy Policy or our privacy practices:
Contact: founders@ambra911.com