Trust

Security and data protection

Protecting patient information is foundational to a clinical product. Here's how we approach it, described plainly, without overstating where we are.

Our approach

Oriva is an early-stage company, and we're building our security program to mature alongside the product. These are the practices we follow today.

Encryption

Data is encrypted in transit and at rest using standard, widely-used protocols.

Access controls

Access to systems and data follows least-privilege principles and is limited to those who need it.

HIPAA & BAAs

For practices, we sign a Business Associate Agreement that governs how protected health information is handled. See HIPAA & compliance.

Reputable infrastructure

The Services run on established cloud infrastructure with its own physical and network protections.

Data minimization

We aim to collect only what's needed to deliver triage and scheduling, and to retain it only as long as necessary.

Auditability

The triage engine is deterministic and its steps are recorded, so outputs can be traced and reviewed.

Where we are honestly. Formal third-party attestations such as SOC 2 are on our roadmap, not yet in place. If your organization has specific security requirements, contact us at hello@oriva.health and we'll share current details.

Questions about security?

We're happy to walk your team through our current setup.

Contact us