PriorAuth

Terms of service

Last updated 10 September 2026 · PriorAuth

Draft, pending legal review. This document describes how the platform is built and what it actually does. It has not been reviewed by counsel and it is not a contract. Nothing in it should be relied on as a legal representation until it has been.

These terms govern use of PriorAuth by a medical practice and the people it authorises. They sit alongside the Business Associate Agreement and the order form; where those disagree with this page, they win.

What the service is

PriorAuth prepares and submits prior authorization requests to health plans on a practice's behalf, using the X12 278 transaction over a clearinghouse, and reads and writes limited information in the practice's EHR where the practice has enabled that.

It is not a medical device and it does not practise medicine. The platform does not diagnose, does not recommend treatment, and does not make or communicate coverage determinations. It prepares paperwork and it stops for a human on anything consequential. Clinical judgement stays with the clinician, and the practice remains responsible for what it submits.

The human gate

This is a product commitment, not a configuration option, and it cannot be switched off at any autonomy level:

  • No authorization is transmitted to a health plan without a named licensed human releasing that specific request.
  • No adverse determination is communicated or acted on by software.
  • No referral or authorization is attached to a clinical record without a licensed human release.
  • A release is single-use and bound to the exact content approved. Approving one request does not authorise a different one, even a very similar one.

Your responsibilities

  • Accounts are individual. Shared logins defeat the audit trail, which is the thing that protects the practice in a dispute.
  • Access reflects role. The practice manages who has which role and removes access when someone leaves.
  • You are the source of truth for clinical content. We do not verify clinical accuracy of what the practice submits.
  • Lawful use. The service is used only for the practice's own treatment, payment and operations, for patients it has a relationship with.

What we do not warrant

Prior authorization outcomes are decided by health plans. We do not warrant that a request will be approved, that a plan will answer within a regulatory window, or that a plan's systems will be available. Where the platform cannot establish something - a payer rule that has not been verified against a published source, a plan that will not say whether authorization is required - it abstains and tells you rather than estimating. That abstention is the product working correctly, and it is the behaviour we do warrant.

Availability and clearinghouse dependency

The service depends on a clearinghouse and on health plan systems that we do not control. When an upstream link fails, work is queued and retried rather than dropped, and a request that cannot be completed becomes a task for a human. Nothing is silently abandoned. Specific availability commitments, if any, are in the order form.

Data

The practice owns its data. We process it as a Business Associate under the BAA and for no other purpose. We do not train models on it. On termination the practice can export its data, and after the agreed window it is purged with a verification pass. See Privacy for the detail.

Agents acting for you

Where the practice enables software agents, or connects an external agent through an integration, the practice remains responsible for what is submitted under its identity. Every agent action is recorded against the agent, the practice and the purpose. The practice can switch any agent off for itself at any time without contacting us, and we can stop the entire fleet immediately if we believe something is wrong.

Suspension

We may suspend access immediately where there is a credible security or patient-safety concern, and we will say why. Suspension for that reason is not a penalty and it is not a payment dispute; it is us stopping something before it causes harm, and we would rather explain it afterwards than wait.

Fees, term and termination

Fees, term, notice periods and renewal are in the order form. Either party may terminate for material breach that is not cured within the period the order form states. On termination we provide an export and then purge.

Liability

Limits of liability are in the order form. Nothing in these terms limits liability that cannot lawfully be limited - including for death or personal injury caused by negligence, or for fraud.

Changes

We give notice before a change that materially reduces what the practice gets or widens what we do with its data. Changes that add a control or narrow our access take effect when we ship them.

Contact

legal@authprior.com · Security: security@authprior.com


The current deployment operates on synthetic data only and is not in clinical use.