AI Patient Advocate is a Personal Health Record (PHR) and claims auditing tool operated by Richard Scheipe ("we," "us," or "our"). The application is designed to help Medicare beneficiaries and their authorized caregivers review Explanation of Benefit (EOB) records, identify billing discrepancies, and prepare appeal documentation.
When you authorize AI Patient Advocate to connect to your Medicare account, we retrieve the following data through the Blue Button 2.0 API:
We do not collect passwords, Social Security numbers, financial account numbers, or any data beyond what the Blue Button 2.0 API provides.
Your Medicare data is used exclusively for the following purposes:
We do not use your data for advertising, marketing, research, or any purpose other than those described above.
Local-First Architecture: All Medicare data retrieved through the Blue Button API is stored exclusively on your personal computer. We do not operate centralized servers, cloud databases, or remote storage of any kind for your health data.
We do not share your data. Specifically:
We do not de-identify, anonymize, pseudonymize, or aggregate your data for any purpose. Your data remains in its original form on your local device and is not processed or transformed for secondary use.
You may revoke AI Patient Advocate's access to your Medicare data at any time through your account settings at Medicare.gov. Upon revocation:
data/ directory.Because all data is stored locally on your device, there are no "accounts" to become dormant or closed in the traditional sense. OAuth tokens expire naturally (access tokens expire after 10 hours; refresh tokens expire per CMS policy). No data is retained on any server or system outside your control.
If we update this privacy policy, we will post the revised policy at this URL with an updated "Last Updated" date, display a prominent notice within the application, and submit draft changes to CMS for review before publication, as required by the Blue Button 2.0 API Terms of Service. Material changes will not take effect for existing users until 30 days after notification is posted.
In the event that we discover a vulnerability in the application that could compromise the security of your locally stored data, we will notify affected users within 60 days of discovery through the application interface and, if available, via email. This is consistent with the FTC's Health Breach Notification Rule requirements for personal health record vendors.
In the event that AI Patient Advocate or its assets are sold or transferred, you will be notified at least 30 days before any transfer that could change how your data is handled. Because your data is stored only on your local device, no health data would be transferred as part of such a transaction.
AI Patient Advocate is intended for use by Medicare beneficiaries and their authorized caregivers. We do not knowingly collect data from children under the age of 13.
As a user of AI Patient Advocate, you have the right to: