Shteg.ai Privacy Policy
1. Introduction
Shteg.ai ("we," "us," or "our") is committed to protecting the privacy and security of data entrusted to us by healthcare providers, medical practices, and their patients. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our standalone financial and credentialing platform.
2. Roles and Compliance
- HIPAA Compliance: Shteg.ai operates as a Business Associate to our covered entity clients. We handle Protected Health Information (PHI) in strict accordance with HIPAA and the HITECH Act.
- SOC 2 Standards: We maintain internal controls based on SOC 2 Type II Trust Services Criteria to ensure the security and confidentiality of all data processed through our Google Antigravity-powered infrastructure.
3. Information We Collect
We collect information necessary to perform specialized financial routing, rate negotiation, and credentialing:
- Practice Data: Business names, NPIs, Tax IDs, and fee schedules.
- Provider Data: Full names, birth dates, license numbers, and professional history (retrieved via FSMB and NPDB APIs).
- Patient Data (PHI): Minimal necessary data retrieved from your EMR via FHIR APIs (e.g., ICD-10 codes, CPT codes, insurance eligibility) to facilitate financial routing.
- Usage Data: Technical logs, IP addresses, and interaction data within the Shteg.ai platform.
4. How We Use Your Information
We use collected data exclusively to:
- Credentialing: Automate provider primary source verification via FSMB, NPDB, and CAQH.
- Market Parity: Perform rate audits against CMS Schema 2.0 Machine-Readable Files.
- Negotiation: Generate data-driven negotiation packages for insurance payers.
- Financial Routing: Provide real-time insurance routing and patient cost estimates.
5. Data Sharing and Disclosure
We only share information with third parties in the following contexts:
- Federal & State Agencies: Submitting queries to the NPDB, FSMB, and CAQH for credentialing at your direction.
- Insurance Payers: Facilitating rate negotiations and contract renewals at your explicit direction.
- Service Processors: Secure cloud infrastructure (Google Cloud) and specialized data APIs (Serif Health, andros) under strict BAA and SOC 2 agreements.
6. Data Security
- Encryption: AES-256 at rest · TLS 1.3 in transit. Financial and clinical data never traverses unencrypted channels.
- Access Control: Mandatory FIDO2-compliant Multi-Factor Authentication (MFA) for all system access.
- Zero-Knowledge Storage: Federal system credentials are encrypted in hardware-security modules (HSMs). Shteg.ai staff cannot access them.
7. Data Retention and Your Rights
We retain data only as long as necessary or as required by law (typically 6–10 years for HIPAA-related records). Providers have the right to:
- Access & Export: Request a copy of their practice and credentialing data at any time.
- Deletion: Request deletion of non-legally-mandated data.
- Breach Notification: Receive prompt notification in the event of a data breach (per HIPAA §164.404).
8. Changes to This Policy
As federal mandates (CMS, TEFCA) evolve, we may update this policy. We will notify you of material changes via the Shteg.ai dashboard or email.
9. Contact Us
For privacy-related inquiries or to exercise your data rights, contact our HIPAA Privacy Officer:
📍 Ridgefield, Connecticut