Trust

HIPAA & compliance

Oriva works with dental practices that handle protected health information (PHI). This page explains, in plain terms, how that relationship works.

Plain-language summary. The dental practice is the "covered entity." When Oriva processes PHI on its behalf, Oriva acts as a "business associate," and a signed Business Associate Agreement (BAA) governs how that information is used and protected.

Covered entity and business associate

Under HIPAA, a dental practice is typically a covered entity responsible for patient information. A vendor that processes that information on the practice's behalf is a business associate. Oriva enters into a BAA with practices that use it for PHI, setting out each party's obligations.

How patient information is handled

  • Patient triage and intake information is processed to produce a pre-visit summary for the practice.
  • We aim to collect only what's needed and to retain it only as long as necessary.
  • Access is limited and data is encrypted in transit and at rest. See Security for details.

Triage, not diagnosis

Oriva produces pre-visit triage information for a licensed clinician to review. It does not provide a diagnosis or treatment, and it is not a substitute for professional judgment. See Regulatory for how this fits under FDA clinical decision support rules.

Requesting a BAA

If your practice is evaluating Oriva and needs a Business Associate Agreement, email hello@oriva.health and we'll provide one.

This page is a plain-language overview and not legal advice. HIPAA obligations depend on your specific use; consult your own compliance counsel.