Security and data protection
Protecting patient information is foundational to a clinical product. Here's how we approach it, described plainly, without overstating where we are.
Our approach
Oriva is an early-stage company, and we're building our security program to mature alongside the product. These are the practices we follow today.
Encryption
Data is encrypted in transit and at rest using standard, widely-used protocols.
Access controls
Access to systems and data follows least-privilege principles and is limited to those who need it.
HIPAA & BAAs
For practices, we sign a Business Associate Agreement that governs how protected health information is handled. See HIPAA & compliance.
Reputable infrastructure
The Services run on established cloud infrastructure with its own physical and network protections.
Data minimization
We aim to collect only what's needed to deliver triage and scheduling, and to retain it only as long as necessary.
Auditability
The triage engine is deterministic and its steps are recorded, so outputs can be traced and reviewed.