Skip to main content
DoulaPaid
Menu

Privacy

Privacy and accepted information

Use DoulaPaid for guides, account access, billing checks, directory profile activity, Review Desk, and State Watch without client data.

Use public pages for general checks only.
DoulaPaid does not accept client data.
Give account access only to people who need it.

Information DoulaPaid accepts

Effective July 11, 2026, this Privacy Policy explains how Dahlia Enterprises, LLC, doing business as DoulaPaid, handles public Medicaid doula billing guides, account creation, billing tools, and worksheets and Washington and Michigan billing-pilot intake without client details or client information. Public pages are not for client names, Medicaid IDs, dates of birth, visit notes, or claim details.

DoulaPaid does not accept patient or claim details on public pages, in saved tools, in Review Desk, in directory profiles, or in State Watch. Do not upload or submit client, patient, member, SSN, W-9, bank or routing details, screenshots, private portal messages, application documents, or claim-specific details. Keep private client and claim details in your practice's approved system.

Accidental client or private provider data is rejected, deleted unreviewed when found, and logged only as a redacted category. Each practice is still responsible for client consent, staff access, payer rules, and records in its own systems.

DoulaPaid does not offer a Business Associate Agreement for this service and does not accept patient, member, claim, or payer-message data. Whether a Business Associate Agreement or another privacy obligation applies to an organization depends on the facts and applicable law. Each organization remains responsible for its own legal, privacy, security, and procurement review. DoulaPaid does not offer client records, document review, claim submission, or billing.

Privacy questions may be sent to privacy at doulapaid.com. Consumer health data requests may be sent to data-rights at doulapaid.com.

Washington consumer health data

Washington's My Health My Data Act, RCW 19.373, may treat some public website or account data as consumer health data. That can include guide views, searches, tool choices, IP addresses, device details, referrers, or account events when they relate to doula billing, pregnancy, birth, postpartum, reproductive health, or health care.

The Washington notice explains what may be collected, why it is used, who may process it, and how to make a data request.

Billing tool data

DoulaPaid may store account data, purchase status, public provider business facts, state, billing route, service category, listed codes and modifiers, provider setup statuses, official public source URLs selected by DoulaPaid, and aggregate funnel counts. A customer does not paste or supply source URLs. The Washington and Michigan pilot applications store a provider business email, state, fee-for-service billing route, and provider-level credential, enrollment, portal, volume, and support-goal selections. The Michigan scope excludes all Medicaid Health Plans. Intake does not accept free text, uploads, client names, dates of birth, Medicaid IDs, claim numbers, service dates tied to a person, addresses, phone numbers, client or family email addresses, diagnosis details, visit notes, SSN values, W-9 values, bank routing or account values, screenshots, private portal messages, application documents, or claim details. A billing-company application separately stores the company name, normalized public domain, business email, and fixed readiness selections about the two billing routes, capacity, insurance, exclusion screening, agreements, and security program. It does not accept a person's health information, payer identifiers, proof documents, narrative text, or uploads.

Washington and Michigan billing-pilot applications

A pilot application uses the provider's business email and fixed provider-readiness selections so DoulaPaid can assess demand and contact the applicant in writing. DoulaPaid stores the application only after the applicant confirms control of that email through an encrypted, expiring link. It does not collect patient-identifying, client, family, member, claim-specific service or submission, financial, document, upload, or free-text data. An application is intake only—not a purchase, billing service, or assurance that a partner or service will be available. No billing company has been selected, and applying does not guarantee acceptance, claim submission, reimbursement, or payment.

Application consent permits DoulaPaid to contact the provider about the pilot only. It does not permit DoulaPaid to send the application to a billing company. Before any introduction, DoulaPaid would name the company and request separate affirmative permission to share only the provider's business contact for that introduction. The application answers remain available to DoulaPaid for review. DoulaPaid will not forward patient, member, claim, document, portal, or payment data. Any patient-data work would occur outside DoulaPaid under a direct provider-partner services agreement and, where required, a business associate agreement.

DoulaPaid retains the provider business email for the pilot and up to 12 months of follow-up unless a longer period is legally required. An applicant may use the data-rights request page to ask DoulaPaid to erase that contact address sooner. After verification, the address is removed. A deletion date and non-contact audit history may remain for legal, security, fraud-prevention, or audit purposes.

Billing-company applications

The billing-partner application collects company qualification information. DoulaPaid uses the verified business email and answers to review qualifications and follow up in writing. Email providers process the application messages and company information needed to send them. Submitting an application is not approval, a contract, a referral commitment, or authorization to receive provider, patient, member, claim, portal, banking, or remittance data.

Before email confirmation, DoulaPaid does not store the company application or its form answers. It uses short-lived, keyed abuse counters for the applicable rate-limit window to prevent repeated verification messages. The counters contain no readable email address or form answers and expire automatically.

Do not send credential IDs, portal credentials, policies, certificates, screenshots, state approval records, contracts, or other documents through the application, support inbox, or reply email. If a company is shortlisted, DoulaPaid may request company documents through a secure business channel. DoulaPaid records the result and a reference number, not the documents.

DoulaPaid retains the company business email and application for up to 12 months of qualification and follow-up unless a longer period is required for legal, security, fraud-prevention, contract, or audit purposes. An authorized company representative may request erasure through the data-rights request page. Contact information is removed. A deletion date and non-contact audit history may remain where necessary.

Data security

Keep client and claim records in your approved system. Limit DoulaPaid account access to people who need it.

Billing work without client records

Current billing tools store states, service categories, checklist status, and official source links. They do not accept patient or claim details.

Access controls

Organizations should limit account access to people who need it for setup, billing, payment, or follow-up, and should remove access when roles change.

Service providers

Organizations are responsible for their own secure records, payer systems, privacy policies, and any required vendor reviews.

Shared responsibility

DoulaPaid supports billing steps without patient or claim details. Each organization remains responsible for privacy policies, consent, staff training, payer rules, legal obligations, secure records, and business associate agreements when HIPAA requires them.

Other data limits

Account email is used for login, verification, password reset, purchase receipts, delivery notices, and account messages. Payment providers are used only for DoulaPaid's one-time Review Desk purchases, not Medicaid claim data. A provider business email may also be used for a requested Washington or Michigan pilot confirmation and written application follow-up.

Do not send screenshots, visit notes, claim numbers, Medicaid IDs, service dates tied to a person, or other client details through public forms, support messages, email, payment fields, analytics feedback, or AI-assisted research.

DoulaPaid does not use targeted advertising, retargeting pixels, or geofencing around health care locations. Search is self-hosted, payments are for one-time DoulaPaid services only, and DoulaPaid does not sell consumer health data.