Effective date: July 26, 2026
Coda is a coding and documentation support application made by UNIRA for hospitals. It is used by hospital workforce members such as physicians, coders, and administrators. It is not a patient-facing service. This notice explains what the application handles and how it is protected.
UNIRA operates Coda as a service provider to the hospital. For protected health information, the hospital is the covered entity and UNIRA is a Business Associate under HIPAA. We process clinical data only on the hospital's instructions, under a signed Business Associate Agreement.
Because the hospital controls the information, requests from individuals about their own health information (access, amendment, or an accounting of disclosures) are handled by the hospital. If such a request reaches us directly, we do not answer it ourselves: we relay it to the hospital promptly and support them in responding.
Account information for workforce users: name, work email address, and role, entered by the hospital's administrators. Sign-in requires multi-factor authentication.
Clinical documentation: operative note text and related case information entered by workforce users, which may include protected health information, together with an optional patient reference the hospital chooses to record.
Operational records: security and audit records of who accessed what and when, including sign-in events and their network origin. These exist to meet HIPAA audit obligations and to protect the information.
We do not sell data, ever.
We do not use customer data, including protected health information, to train or improve any AI model.
We do not use advertising technology, analytics trackers, or web-tracking pixels inside the application. Our public marketing website is separate and does use advertising measurement, which is described in the website privacy policy; it carries no clinical or institutional data.
We do not combine one hospital's data with another's. Each hospital operates in its own dedicated, isolated environment.
We do not disclose information to law enforcement without valid legal process such as a warrant or subpoena, and we notify the hospital unless the law prohibits it.
Coda uses commercial AI models to analyze documentation and propose billing codes with cited reasoning. AI runs only when a user starts it on a specific case; there is no background scanning. Every AI suggestion is reviewed by a person, and the system takes no autonomous billing action. AI processing operates under agreements requiring zero data retention: the model providers do not keep inputs or outputs and do not train on them. Our AI transparency page describes this in more detail.
Information is encrypted in transit and at rest. Each hospital's data lives in its own dedicated cloud environment in the United States. Access is role-based and denied by default, protected by multi-factor authentication. A tamper-evident audit trail records every access to clinical information, by people and by AI alike, and the hospital's own compliance staff can review it directly in the application.
Clinical information is retained for the duration of the agreement with the hospital. On termination it is returned in standard formats and then destroyed, with backups expiring on a fixed schedule. Audit records are retained for six years to meet HIPAA documentation requirements.
All storage and processing takes place in United States data centers operated by Amazon Web Services. Data is not transferred outside the United States.
We use a small, published set of service providers. Any provider that can handle protected health information operates under a Business Associate Agreement: Amazon Web Services for hosting and in-environment AI processing, and OpenAI for a secondary AI path under a zero-data-retention agreement. A current list is available on request.
If a security incident affects a hospital's information, we notify that hospital within the period its Business Associate Agreement requires and support the hospital's own notification obligations.
Privacy questions: info@unira.io
We post updates to this page with a new effective date and notify hospital customers of material changes.