Coda Privacy Notice

Effective date: July 26, 2026

Coda is a coding and documentation support application made by UNIRA for hospitals. It is used by hospital workforce members such as physicians, coders, and administrators. It is not a patient-facing service. This notice explains what the application handles and how it is protected.

THE ROLE WE PLAY

UNIRA operates Coda as a service provider to the hospital. For protected health information, the hospital is the covered entity and UNIRA is a Business Associate under HIPAA. We process clinical data only on the hospital's instructions, under a signed Business Associate Agreement.

Because the hospital controls the information, requests from individuals about their own health information (access, amendment, or an accounting of disclosures) are handled by the hospital. If such a request reaches us directly, we do not answer it ourselves: we relay it to the hospital promptly and support them in responding.

WHAT THE APPLICATION PROCESSES

Account information for workforce users: name, work email address, and role, entered by the hospital's administrators. Sign-in requires multi-factor authentication.

Clinical documentation: operative note text and related case information entered by workforce users, which may include protected health information, together with an optional patient reference the hospital chooses to record.

Operational records: security and audit records of who accessed what and when, including sign-in events and their network origin. These exist to meet HIPAA audit obligations and to protect the information.

WHAT WE DO NOT DO

We do not sell data, ever.

We do not use customer data, including protected health information, to train or improve any AI model.

We do not use advertising technology, analytics trackers, or web-tracking pixels inside the application. Our public marketing website is separate and does use advertising measurement, which is described in the website privacy policy; it carries no clinical or institutional data.

We do not combine one hospital's data with another's. Each hospital operates in its own dedicated, isolated environment.

We do not disclose information to law enforcement without valid legal process such as a warrant or subpoena, and we notify the hospital unless the law prohibits it.

ARTIFICIAL INTELLIGENCE

Coda uses commercial AI models to analyze documentation and propose billing codes with cited reasoning. AI runs only when a user starts it on a specific case; there is no background scanning. Every AI suggestion is reviewed by a person, and the system takes no autonomous billing action. AI processing operates under agreements requiring zero data retention: the model providers do not keep inputs or outputs and do not train on them. Our AI transparency page describes this in more detail.

SECURITY IN BRIEF

Information is encrypted in transit and at rest. Each hospital's data lives in its own dedicated cloud environment in the United States. Access is role-based and denied by default, protected by multi-factor authentication. A tamper-evident audit trail records every access to clinical information, by people and by AI alike, and the hospital's own compliance staff can review it directly in the application.

RETENTION AND DELETION

Clinical information is retained for the duration of the agreement with the hospital. On termination it is returned in standard formats and then destroyed, with backups expiring on a fixed schedule. Audit records are retained for six years to meet HIPAA documentation requirements.

WHERE DATA LIVES

All storage and processing takes place in United States data centers operated by Amazon Web Services. Data is not transferred outside the United States.

SERVICE PROVIDERS

We use a small, published set of service providers. Any provider that can handle protected health information operates under a Business Associate Agreement: Amazon Web Services for hosting and in-environment AI processing, and OpenAI for a secondary AI path under a zero-data-retention agreement. A current list is available on request.

SECURITY INCIDENTS

If a security incident affects a hospital's information, we notify that hospital within the period its Business Associate Agreement requires and support the hospital's own notification obligations.

CONTACT

Privacy questions: info@unira.io

CHANGES TO THIS NOTICE

We post updates to this page with a new effective date and notify hospital customers of material changes.