Home Platform Soro Data Patient portal The app (soon) Solutions For teams For patients Open it Soro Data ↗ Capabilities Bill audit Hospital rates Payer rates Security Company Pricing Resources About Contact Log in Get started
Legal

Privacy policy

Last updated: September 2026

1. Information we collect

We collect the details you give us when you contact us or open an account, such as your name, email, and phone number. When you ask us to review a bill, we also handle your medical bills, explanations of benefits, and the related health information, under HIPAA and the authorization you sign.

2. How we use information

We use your contact details to respond to you and to run our services. We use claims data only to audit claims and recover overpayments for the plan that engaged us.

3. Protected health information and HIPAA

Any protected health information we handle is governed by a Business Associate Agreement and by HIPAA. We use it for one purpose: the audit. We do not sell it, use it for marketing, or fold it into other products.

4. How we share information

We do not sell your information. We share it only with the service providers we need to run the audit, and only under agreements that require them to protect it.

The contact forms on this site are delivered by Formspree, a third-party form processor. Those forms collect contact details only: your name, your email address and, if you give it, your phone number. Nothing about your care, your bill or your records goes through them. Your documents and the details of your claim are collected in the secure portal we open for you, which runs on our own infrastructure under a signed Business Associate Agreement.

5. Security

We encrypt data in transit and at rest, limit access to the people who need it, and log that access. Our full safeguards are described on our security page.

6. Retention

We keep information only as long as we need it for the audit and for legal or contractual obligations. After that we return or destroy it, with written certification when a plan requests it.

7. Your choices

You can ask us what we hold about you, correct it, or ask us to delete it. Email maximus@soro.health and we will respond.

8. Cookies and analytics

We do not use advertising cookies, social media pixels, or any third-party tracker. Nothing on this site sends your visit to Google, Meta, or an ad network, and we do not build advertising profiles or sell what we learn here.

We count page views using our hosting provider's built-in analytics, which sets no cookie and stores no IP address. It tells us which pages are read and roughly where readers are, and it cannot follow you to any other website.

If you accept cookies, we also store one small first-party cookie that remembers whether you came to us about a medical bill or about our rate data. It holds a single label and the first page you landed on. It carries no name, no email, and nothing about your health or your bills, and it never leaves our own site.

The cookies we may set:

  • soro_consent — records the choice you made on the cookie banner, so we stop asking. Set whichever way you answer. Expires after 180 days.
  • soro_aud — the audience label described above. Set only if you accept. Expires after one year.
  • soro_sess — marks that this visit has already been counted, so one visit is not recorded many times. Set only if you accept, and deleted when you close your browser.

You can change your mind at any time using the Cookie settings link in the footer of every page. Choosing to reject deletes the cookies above straight away and nothing on this site works any differently.

Our patient portal, client portal, and internal platform carry no analytics at all. We do not put tracking of any kind on a page you have to sign in to reach.

9. Changes to this policy

If we change this policy, we will post the new version here with an updated date.

10. Contact

Questions about privacy go to maximus@soro.health.