Legal ยท Security

HIPAA & Security

Last updated: August 22, 2026

1. Our Commitment

Oira is built for clinical environments from day one. We sign Business Associate Agreements (BAAs) with covered entities and design our infrastructure, policies, and vendor relationships to meet HIPAA Security Rule requirements.

2. Technical Safeguards

  • All data encrypted in transit using TLS 1.2+ and at rest using AES-256.
  • Strict access controls: only you can access your workspace's encounters and notes.
  • Comprehensive audit logging of system activity.
  • Encounter audio is processed to generate your draft and then deleted per your retention settings.

3. Administrative & Physical Safeguards

  • Security training and confidentiality agreements for all personnel.
  • Least-privilege access with mandatory multi-factor authentication internally.
  • Cloud infrastructure hosted in SOC 2-audited facilities.

4. Your Data Is Not Used for Training

Patient audio, transcripts, and notes are never used to train machine-learning models. Your clinical content belongs to you and your patients โ€” full stop.

5. Subprocessors

We work with a short list of carefully vetted subprocessors (cloud hosting, speech-to-text), each bound by written agreements that impose equivalent privacy and security obligations.

6. Incident Response

We maintain an incident response plan and will notify affected customers without undue delay following discovery of a breach of unsecured PHI, consistent with HIPAA Breach Notification requirements.

7. Contact

Security questions or report a vulnerability: security@oira.doctor.

โ† Back to Legal Hub