Legal
Terms of Service
Last updated: August 22, 2026
The short version
- - You pay only when the payer pays: 15% of verified recoveries, nothing upfront.
- Your patient data is destroyed on a clock; the BAA, not this page, governs PHI.
- - Audit results are estimates, not guarantees; you stay responsible for billing decisions.
- - No long-term lock-in. Stop anytime; outstanding fees on recovered money remain due.
This summary is for convenience only. The full terms below govern.
1.Who we are
The Service known as Hypex (hypexrcm.com, app.hypexrcm.com, and api.hypexrcm.com) is operated by the Hypex RCM business registered in Pakistan under the trade name Hypex, FBR NTN 3130464618146 ("Hypex," "we," "us"). We provide claim-denial analysis, appeal drafting, follow-up management, claim resubmission support, and recovery reconciliation ("the Service") to medical billing companies, healthcare practices, and healthcare organizations ("you," "Customer").
These Terms govern your use of the Service. If we sign a Master Services Agreement, Statement of Work, or Business Associate Agreement with you (each an "Engagement Agreement"), that document controls over these Terms where they conflict. The Business Associate Agreement ("BAA") always controls over these Terms with respect to PHI.
2.HIPAA and Business Associate status
When providing the Service involves access to protected health information (PHI), Hypex acts as a Business Associate as defined at 45 CFR 160.103, and a BAA is executed with the Customer before any PHI is processed, as required by 45 CFR 164.504(e). Our BAA covers all eight elements required by that section: permitted uses and disclosures, safeguards, reporting obligations, subcontractor flow-downs, access by individuals, amendment, accounting of disclosures, and return-or-destruction at termination.
Zero-PHI-storage architecture. Hypex receives PHI only to perform the contracted work. Raw PHI is held solely in an encrypted vault with a 24-hour time-to-live that self-destructs automatically and has no manual override; on successful processing it is purged sooner. PHI is never written to our persistent database, object storage, or any language model. Only de-identified data (codes, amounts, dates of service, and opaque tokens) is stored beyond the vault window.
The Customer remains responsible for: (a) the lawfulness of the PHI it discloses to the Service, (b) all professional billing and coding decisions, (c) the accuracy and completeness of source documentation, (d) its payer contracts, and (e) its obligations as a covered entity or business associate under HIPAA.
3.Scope of the Service
The Service analyzes denied claims; attributes root causes using CARC/RARC mappings and payer-specific rules; drafts appeal letters (deterministic templates by default, with an optional AI-assisted path); stages follow-up correspondence; generates X12 837 resubmission transactions; reconciles 835 remittances against appealed claims; and reports on outcomes.
Estimates are not guarantees. Any output of the free recovery audit, ROI calculator, recoverable-range figures, win-rate bands, or denial probability scores is a computed estimate for evaluation and planning only. It is not a promise, warranty, or projection of actual recovery. Actual outcomes depend on payer adjudication, documentation quality, and factors outside the Service's control.
The Service supports your billing operations; it does not provide legal, medical, or coding advice, and it does not replace the professional judgment of qualified billing, coding, or compliance staff.
4.Data handling and acceptable use
PHI: received only through designated intake endpoints, held in the vault described in Section 2, de-identified under the HIPAA Safe Harbor method (45 CFR 164.514(b)), and destroyed. See the Privacy Policy for the complete data inventory.
De-identified data: retained per your retention setting for analytics, attribution accuracy, and service improvement. It contains no patient identifiers and is not re-identified. Aggregated, de-identified insights (such as payer behavioral patterns) remain Hypex property as described in Section 10.
You agree not to: (a) submit data you have no right to use; (b) use the Service in violation of law, payer contract, or these Terms; (c) attempt to reverse engineer, scrape, or circumvent the Service; (d) share access credentials between organizations; (e) submit PHI through any channel other than designated intake endpoints; or (f) use the Service to submit claims you know or should know to be false, inflated, duplicated, or otherwise improper. We may suspend access immediately for violations that create compliance or security risk.
5.Fees and payment
Contingency model (default). Hypex is paid a success fee - typically 15% of recovered amounts, or another percentage stated in your Engagement Agreement, computed only on dollars the payer actually pays on claims the Service worked, as confirmed by matching the payer's 835 remittance. There is no upfront fee, no subscription, and no minimum. If a claim does not recover, you owe nothing for it.
Partial payments and takebacks. Where a payer pays a claim in multiple installments, the fee applies to each verified installment. Where a payer reduces or reverses a previously paid amount (a takeback), the affected invoice is voided and replaced with one computed only on amounts you actually retained.
Fee protection period. For claims the Service drafted or materially prepared, the success fee applies to payments received within 180 days of the prepared appeal, regardless of who transmits the submission, as further set out in the Engagement Agreement. Each prepared appeal carries a Hypex Appeal Reference identifying it.
Invoicing and terms. Invoices are issued upon confirmed recovery and are payable net 30 days. The free audit is free: it creates no paid engagement and no obligation.
6.No guarantee of recovery
Claim adjudication belongs entirely to payers. Hypex does not guarantee that any denial will be overturned or that any amount will be recovered, and nothing in the Service constitutes a representation about likely payer behavior. Denial root-cause attribution is decision support for your billing team, not a legal or clinical determination.
7.Service availability
We target high availability but do not warrant uninterrupted service. Maintenance is communicated in advance where practical. The vault's 24-hour TTL operates independently of availability: PHI continues to self-destruct on schedule even during an outage.
8.Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or goodwill. Each party's aggregate liability arising from the Service is capped at the total fees paid or payable by you to Hypex in the twelve (12) months preceding the event giving rise to the claim. If no fees have been paid (for example, during a free audit), Hypex's aggregate liability is capped at USD 100.
These limits do not apply to anything that cannot be limited under applicable law, including either party's HIPAA breach-notification and BAA obligations, or liability arising from a party's fraud, willful misconduct, or unauthorized disclosure of the other party's PHI.
9.Term and termination
You may stop using the Service at any time. We may suspend or terminate access for material breach (with notice and a cure period where reasonable) or for conduct creating legal, compliance, or security exposure. Upon termination of an engagement: (a) fees on amounts already recovered and verified remain due; (b) no new fee protection period accrues after the effective date; (c) vaulted PHI self-destructs within 24 hours; (d) de-identified data is returned or destroyed at your election; and (e) a certificate of destruction is provided on request.
10.Intellectual property
Hypex retains all rights in the Service, including the attribution engine, templates, payer-rule library, follow-up logic, software, and documentation. You retain all rights in your data. De-identified, aggregated insights derived from processing claims (such as payer behavioral patterns and recovery benchmarks) remain Hypex property and may be used to improve the Service; they never identify you or any patient.
11.Disclaimers
The Service is provided "as is" and "as available," with all faults, to the fullest extent permitted by law. Hypex disclaims all other warranties, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. We do not warrant that the Service will detect every recovery opportunity, that payer rules are current as of any moment, or that outputs are error-free.
12.Indemnification
You agree to indemnify Hypex against third-party claims arising from data you submit without right, billing or coding decisions you make using Service output, or your violation of law or payer contracts. Hypex agrees to indemnify you against third-party claims arising from our unauthorized disclosure of PHI or our gross negligence or willful misconduct.
13.Changes to these terms
We may update these Terms; material changes are posted here with a new "last updated" date and, where we have your contact on file, we will also notify you by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance. If a change materially reduces your rights, you may terminate the affected engagement before it takes effect.
14.Governing law and disputes
These Terms are governed by the laws of Pakistan, without regard to conflict-of-laws rules. For US customers, the BAA governs all HIPAA-related obligations and is construed under applicable US federal law. The parties will first attempt good-faith resolution of any dispute for 30 days; unresolved disputes go to binding arbitration under the rules of the Singapore International Arbitration Centre, seated in Singapore, in English. Either party may seek injunctive relief for confidentiality or security breaches in any competent court.
15.Contact
Questions about these Terms: founder@hypexrcm.com. See also our Privacy Policy and Security page.
These Terms are provided for the Service described above and are not a substitute for advice of counsel. Each party should have its own legal review before executing an Engagement Agreement.