Privacy Policy

Effective and last updated: July 14, 2026

About this policy

Cenrus LLC ("Cenrus," "we," "us," or "our") provides healthcare financial reconciliation software to medical bill review companies, patient advocacy organizations, and other business customers. This Privacy Policy explains how we collect, use, disclose, retain, and protect information through our website, payer connections, software, and related services (the "Service").

A customer may submit provider bills and available payment evidence to Cenrus. A patient may also authorize a connection to an insurer as part of the customer's workflow. Cenrus uses the available records to match provider requests to payer adjudication and return evidence-based results to the customer.

Our role

Our business customers decide why and how they use Cenrus for their cases. When we process personal information for a customer, that customer controls the information and its privacy notice and agreement with Cenrus govern the processing. This policy also covers information that Cenrus controls directly, including website inquiries, business contacts, and product administration data.

Contact the organization that submitted your case to exercise rights relating to its records. We will support the customer in responding when our agreement or applicable law requires it.

Information we collect

Customer and business information

  • names, work contact details, company information, and account credentials
  • contract, billing, support, pilot, and product feedback records
  • information submitted through our website or in communications with us.

Case information

  • provider bills, statements, account details, service dates, charges, and requested balances
  • available receipts, transaction records, and other payment evidence
  • case notes, reviewer decisions, corrections, and outcomes that a customer submits
  • patient identity, contact, coverage, and authorization information needed to connect and match records.

Payer information

After a patient authorizes a payer connection, we receive the information covered by that authorization. This can include claims, Explanations of Benefits, coverage data, provider and service information, submitted and allowed amounts, payer adjustments, deductible, copay, coinsurance, patient responsibility, available payer payment information, connection status, authorization tokens, and retrieval records.

Patients authenticate through the payer or its authorized connection flow. Customers and patients should not send payer passwords to Cenrus.

Results Cenrus creates

Cenrus creates normalized records, potential bill-to-claim matches, matching signals, financial comparisons, confidence indicators, change events, recommended actions, and verdicts such as consistent with payer, amount discrepancy, ambiguous match, or human review required. These results can contain or reveal health and financial information.

Technical information

We collect device, browser, IP address, login, event, error, security, and diagnostic information needed to operate, support, and protect the Service.

How we use information

We use information to:

  • provide, configure, and support the Service
  • establish and maintain patient-authorized payer connections
  • retrieve, normalize, and monitor payer records
  • ingest provider bills and available payment evidence
  • match records, reconstruct payer financial allocations, and produce reconciliation results
  • send change events and prepare uncertain or discrepant cases for human review
  • measure and improve reliability, matching quality, and reviewer agreement
  • secure the Service and investigate errors, misuse, fraud, and security incidents
  • manage customer relationships and respond to inquiries
  • comply with law and enforce our agreements.

We do not use patient information for targeted advertising or sell patient information. We do not use identifiable healthcare information to train generalized artificial intelligence models.

Automated processing and human review

Cenrus uses automated systems to organize records, rank potential matches, compare financial values, detect changes, and produce results. A result reflects the records available to Cenrus. It does not establish a provider's current accounts receivable balance or prove that a patient still owes a payer-assigned amount.

Cenrus routes uncertain cases to the customer for human review. Authorized Cenrus personnel can access case information when needed to provide support, investigate an error or security issue, assess a disputed result, or meet a legal duty. We limit access based on job responsibilities.

How we disclose information

We disclose information in these circumstances:

  • Customers and authorized users. We return case information and results to the customer that submitted or manages the case and to users that the customer authorizes.
  • Service providers. Vendors process information for hosting, security, communications, analytics, support, and other functions under agreements with Cenrus.
  • Patient-directed connections. We exchange information with payers and connection providers as needed to complete and maintain a patient-authorized connection.
  • Legal and safety needs. We disclose information when law requires it or when we reasonably need to protect a person, investigate misconduct, enforce an agreement, or protect the Service.
  • Business transactions. Information can transfer as part of a financing, merger, acquisition, reorganization, or sale of assets, subject to applicable law and contractual restrictions.

Retention and deletion

We retain information for the periods in our customer agreements, documented customer instructions, and internal retention schedules. The period depends on the type of record, the purpose for processing it, and legal, security, and operational needs.

When a payer connection ends, we stop future retrieval after we process the disconnection. When a customer requests deletion or its agreement ends, we delete or return customer information as the agreement requires. Deletion from backups follows our backup lifecycle. We can retain limited records when law requires it or when we need them to investigate security, fraud, misuse, or a legal claim. We restrict retained records from ordinary product use and delete them when the reason for retention ends.

Choices and requests

Customers can manage authorized users and submit access, correction, export, connection, and deletion requests under their agreement with Cenrus. A patient can revoke a payer connection through the available payer or customer workflow. Revocation stops future retrieval after it takes effect. It does not change source records held by a payer or provider and does not automatically delete records that a customer must retain.

Privacy rights vary by location. Submit a request to the customer that manages your case or contact us at the address below. We can ask for information needed to verify identity and authority before completing a request.

Security

We use administrative, technical, and organizational safeguards designed to protect the information we process. We review access, monitor systems, and assess service providers based on the sensitivity of their work. No security measure can prevent every incident.

Report a suspected vulnerability, unauthorized access, or data exposure to security@cenrus.com. We investigate reports and provide notices required by law and our customer agreements.

Changes to this policy

We can update this policy as our Service and legal duties change. We will post the revised policy and provide any additional notice required by law or our customer agreements. A revised policy does not give us a new right to use customer-controlled information outside our agreement and documented instructions.

Contact us

Cenrus LLC
2578 Broadway
New York, NY 10025-5642, United States

Privacy questions and requests: privacy@cenrus.com
Security reports: security@cenrus.com