OrthoRecords

Privacy Policy


Effective Date: April 2026

OrthoRecords is operated by [Practice Name] ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our dental practice management platform.

Information We Collect

We collect information you provide directly, including practice and organization details (name, address, contact information), user account credentials (name, email, professional role), patient records and protected health information (PHI) entered by authorized users, clinical photographs and radiographic images, treatment planning and appointment data, and billing and subscription information.

We also collect certain information automatically, including log data (IP addresses, browser type, pages visited), device information, and aggregate usage analytics.

How We Use Your Information

We use collected information to provide, operate, and improve our platform, process transactions and send related communications, respond to support requests, and comply with legal obligations. Patient health information is used solely to facilitate patient care and practice management as directed by the covered dental practice.

HIPAA and Protected Health Information

OrthoRecords operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We handle Protected Health Information (PHI) on behalf of dental practices (Covered Entities) pursuant to a Business Associate Agreement (BAA). We do not use or disclose PHI except as permitted by our BAA and applicable law. To obtain a BAA, contact: privacy@orthorecords.com.

Data Security

We implement administrative, physical, and technical safeguards to protect your information, including encryption of data at rest and in transit (AES-256 / TLS 1.2+), role-based access controls, audit logging, and regular security assessments. Our platform is hosted on Amazon Web Services (AWS).

Data Retention

We retain practice and user data for the duration of your subscription and for up to 7 years following termination, unless a longer period is required by applicable law. Patient records are retained in accordance with state and federal dental recordkeeping regulations.

Disclosure of Information

We do not sell, trade, or rent personal information or patient data to third parties. We may share information with service providers who assist in our operations, subject to confidentiality obligations. We may disclose information as required by law or to protect the rights and safety of our users and the public.

Your Rights

Users may access, update, or delete their account information by contacting us. Patients wishing to exercise rights under HIPAA — including access, amendment, or accounting of disclosures — should contact their dental provider directly.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the platform after changes constitutes acceptance of the updated policy.

Contact Us

[Practice Name] privacy@orthorecords.com OrthoRecords.com