HIPAA compliance & security
Your patients trust you with their health information, and you're trusting a software vendor with it the moment records go in. That deserves specifics — not a badge. Here is exactly how OrthoRecords protects protected health information (PHI), safeguard by safeguard.
First, some straight talk: nobody is “HIPAA certified”
The Department of Health and Human Services does not certify software, so a vendor waving a “HIPAA certified” badge is telling you about their marketing, not their engineering. What HIPAA actually requires is that covered entities and their business associates implement the Security Rule's administrative, physical, and technical safeguards — and be able to show their work.
OrthoRecords operates as a business associate under HIPAA when it stores or processes PHI on behalf of your practice, and executing a Business Associate Agreement (BAA) with your practice is part of onboarding. The rest of this page is the “show your work” part.
Technical safeguards, in the product today
These map directly to the HIPAA Security Rule's technical safeguard standards — access control, audit controls, integrity, authentication, and transmission security.
Encrypted in transit
Every connection to OrthoRecords — browser, phone photo capture, integrations — runs over HTTPS/TLS. There is no unencrypted path to patient data.
Encrypted at rest
The production database and all clinical photos, x-rays, and documents are encrypted at rest with AES-256. Files are never public: they're served only through short-lived signed links issued to an authenticated, authorized session.
Role-based access control
Owner, admin, doctor, and staff roles carry granular server-enforced permissions. Every record is scoped to the practice that owns it — one practice can never query another's data.
Automatic logoff
Sessions expire after 15 minutes of inactivity by default — HIPAA's automatic-logoff safeguard, on out of the box. Signed-out screens are never served from cache, so the back button can't resurface a chart.
Audit trails
Patient record changes, clinical note signing, appointment updates, billing entries, insurance claims, and staff-management actions are written to an audit log with the user, role, action, and timestamp.
Account security
Passwords are stored only as bcrypt hashes — never in plain text — and every password is screened against known breach corpuses: new ones when set, existing ones at sign-in, with a required update when one falls below current policy. Sign-in attempts are rate-limited with automatic lockout, new accounts verify their email, and bot registrations are screened out at the door.
A clinical record you can defend
HIPAA's integrity standard asks a simple question: can PHI be improperly altered or destroyed? OrthoRecords is built so the honest answer is no.
- Signed clinical notes lock. Once a note is signed, its clinical content can't be silently edited — corrections happen as dated, attributed addenda, the same standard a paper chart audit expects.
- The financial ledger is append-only. Charges and payments are never edited or deleted in place; corrections post as explicit reversing entries, so the money trail always reconciles.
- Records archive instead of vanishing. Patient records are deactivated and retained, not hard-deleted by day-to-day workflows.
- Layered backups. The database keeps 35 days of point-in-time recovery and clinical imaging is versioned with a 90-day undo window; both are backed up daily to a dedicated backup vault, with monthly copies replicated to a second AWS region and retained for a year. Deletion protection is enforced at the infrastructure level.
AI features: security & compliance
OrthoRecords includes AI-assisted tools — cephalometric tracing, case review, treatment second opinions, document scanning. AI raises fair questions about where patient data goes, so here are the answers.
De-identified by design
Clinical AI prompts are assembled server-side and reference the patient's age instead of their name or date of birth. The AI is explicitly instructed it is reviewing a de-identified case.
Never used for training
AI features run under enterprise API terms in which your inputs and outputs are not used to train models. A HIPAA-eligible AWS processing path is also available for AI workloads.
Every run is logged
Each AI request records who ran it, which feature, which patient record it concerned, and when — the same accountability standard as the rest of the chart.
Clinician in the loop
AI output is decision support, clearly labeled, and presented to the treating clinician for review. Nothing an AI produces enters the clinical record as fact without a human accepting it.
AI is also opt-in at every level: features are enabled per plan and per practice, runs are confirmed before credits are used, and including clinical imagery in an analysis is an explicit per-run choice. If your practice prefers no AI at all, everything else in OrthoRecords works without it.
Infrastructure
OrthoRecords runs on Amazon Web Services in the United States. Physical safeguards — guarded facilities, hardware lifecycle controls, environmental protections — are inherited from AWS data centers, which hold independent SOC and ISO 27001 attestations and serve most of American healthcare and banking.
On top of that foundation, every practice's data is logically isolated: each query the application makes is scoped to the requesting practice, enforced in the data layer rather than left to individual screens to remember. Patient-facing links (treatment proposals, consent signing, appointment confirmations) use single-purpose, unguessable tokens and expose only the document they were created for.
What stays in your hands
No vendor can make a practice compliant by itself — HIPAA is a shared responsibility, and pretending otherwise is another red flag. OrthoRecords gives you the controls; your practice operates them:
- Assign each team member the least role that does their job — permissions follow the role.
- Use strong, unique passwords and deactivate accounts the day someone leaves.
- Keep workstations locked and let the automatic session timeout do its job.
- Maintain your practice's own HIPAA policies, training, and risk analysis — your BAA with us covers our side.
Frequently asked questions
Is OrthoRecords HIPAA compliant?
Yes. OrthoRecords is built to the HIPAA Security Rule's administrative, physical, and technical safeguard requirements: encrypted transport, encrypted media storage, role-based access control with practice-level data isolation, automatic session logoff, audit trails on clinical and financial actions, and tamper-resistant clinical records. As a business associate, OrthoRecords executes a Business Associate Agreement (BAA) with the practices it serves.
Will OrthoRecords sign a Business Associate Agreement (BAA)?
Yes. Under HIPAA, OrthoRecords operates as a business associate when it stores or processes protected health information on behalf of your practice, and executing the BAA is built into onboarding: the practice owner reviews and electronically signs it at first sign-in, and the executed copy is retained and available from Settings at any time.
Is there such a thing as being "HIPAA certified"?
No — and any vendor claiming an official HIPAA certification is overstating it. The U.S. Department of Health and Human Services does not certify software. What a trustworthy vendor can do is implement the Security Rule's required and addressable safeguards, document them, sign a BAA, and show you specifics — which is what this page does.
How do the AI features handle patient data?
Clinical AI requests are de-identified before they leave the platform wherever possible — prompts reference the patient's age rather than their name or date of birth. Every AI run is logged (who ran it, which feature, when), image inclusion is a per-run choice, and AI output is decision support: it is presented to the clinician for review, never written to the record as fact.
Is my patients' data used to train AI models?
No. AI features run through enterprise API agreements under which inputs and outputs are not used to train models. Your patients' records, photos, and documents stay your data.
Where is patient data stored?
In Amazon Web Services (AWS) data centers in the United States — the same physically secured, independently audited infrastructure used across healthcare and banking. Data is encrypted in transit with TLS, the database and all clinical media are encrypted at rest with AES-256, and imaging is never publicly accessible: files are served only through short-lived, signed links behind an authenticated, permission-checked session.
Who can see a patient's record?
Only authenticated members of your own practice, and only what their role allows. Every query in the platform is scoped to the practice that owns the record, permissions are enforced on the server for each action, and access-relevant events are written to an audit trail with the user, action, and timestamp.
Records your patients can trust you with
90-day free trial. No credit card required to start.