> ## Documentation Index
> Fetch the complete documentation index at: https://trust.denialbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Practice settings

> Configure your practice profile, notifications, insurer defaults, sessions, and data controls.

## Practice profile

<AccordionGroup>
  <Accordion title="Basics">
    Legal name, DBA, Tax ID, NPI (group), specialty, primary address, mailing address if different. This information is used to populate appeal letters and for payer-facing metadata.
  </Accordion>

  <Accordion title="Providers">
    Add each provider with their individual NPI, specialty, and any supervising-provider relationships. Providers are the signatories on appeal letters.
  </Accordion>

  <Accordion title="Payers">
    Select your active payers from the master list. Payer-specific appeal templates, deadlines, and contact info auto-populate for each.
  </Accordion>

  <Accordion title="Locations">
    For multi-location practices, add each site with its own POS code and billing address.
  </Accordion>
</AccordionGroup>

## Notifications

<CardGroup cols={2}>
  <Card title="Email" icon="envelope">
    Per-user granular control — daily digest, per-event, or off. Admins can override for compliance-critical events (e.g. audit-log export).
  </Card>

  <Card title="Slack" icon="message">
    Connect a channel for team-wide alerts: deadline warnings, HITL-reviewed denials, overturned appeals.
  </Card>

  <Card title="In-app" icon="bell">
    Always on. Bell icon in the header. Filter by type.
  </Card>

  <Card title="SMS" icon="mobile">
    Not supported. We don't send PHI — even metadata-only — over SMS.
  </Card>
</CardGroup>

### What you can subscribe to

* New denials detected
* HITL review complete (low-confidence denials)
* Deadline approaching (14 / 7 / 1 days)
* Outcome recorded
* Audit events (for admins): 2FA reset, role change, bulk export
* Security events (for admins): failed login spike, lockout, suspicious activity

## Sessions

<AccordionGroup>
  <Accordion title="Idle timeout">
    Default 30 minutes. Can be shortened to 15 minutes for higher-security practices. Cannot be extended beyond 30 minutes (HIPAA §164.312(a)(2)(iii)).
  </Accordion>

  <Accordion title="Concurrent sessions">
    Default: unlimited. Can be restricted to 1 active session per user (any new sign-in terminates prior sessions).
  </Accordion>

  <Accordion title="Re-auth for sensitive actions">
    User deletion, bulk PHI export, 2FA reset, role changes — all can be configured to require password re-entry.
  </Accordion>
</AccordionGroup>

## Insurer defaults

For each of your active payers, you can configure:

* **Default strategy** — e.g. "always try peer-to-peer first for Kaiser medical necessity"
* **Deadline buffer** — how many days before the payer's deadline we surface as urgent
* **Template customization** — practice-specific language blocks to include by default
* **Submission channel preference** — portal, fax, or mail

*See [Insurer guides](/insurer-guides/overview) for payer-specific best practices.*

## Data controls

<AccordionGroup>
  <Accordion title="Data export">
    **Settings → Data → Export** generates a downloadable archive of your practice's denials, appeals, documents, and metadata. Every export is audit-logged. Typical size: several GB for a year of activity.
  </Accordion>

  <Accordion title="Patient data-access request (HIPAA §164.524)">
    Generate a per-patient PHI package. Includes all documents and records Denialbase has for that patient.
  </Accordion>

  <Accordion title="Data deletion">
    Admins can delete a user (see [Team management](/admins/team-management#offboarding)). Practice-level deletion requires contacting [support@denialbase.com](mailto:support@denialbase.com) to avoid accidental catastrophic loss.
  </Accordion>

  <Accordion title="Retention policy">
    Default retention of active data for the life of the account. Denials, appeals, and documents can be archived (hidden from daily workflow) without deleting. Audit logs are retained for 7 years regardless.
  </Accordion>
</AccordionGroup>

## Billing

If you're on the billing-admin role, this is where you manage subscription, seats, and invoices. Stripe billing is planned for Q3 2026 — contact [sales@denialbase.com](mailto:sales@denialbase.com) for your current plan details.
