Patient data, protected from the ground up.
Front desks handle patient information all day. Occlu is being built for HIPAA compliance from its foundation, so your team can get useful guidance with your practice’s privacy requirements in mind.
Safeguards
Nine layers of protection, built in.
Every safeguard is part of the product’s design, from the start.
A signed BAA with your practice
Every plan is designed to include a Business Associate Agreement, the contract that defines how patient information is protected.
BAAs across our whole stack
The architecture uses HIPAA-eligible AWS services under the AWS Business Associate Addendum, including the AI service.
Encrypted everywhere
Encrypted connections and encrypted storage protect information as it moves through the system and while it is stored.
Walled-off office data
Each office has its own policies, questions and users. Database-level separation is verified by automated isolation tests.
Two-factor login required
Every staff and manager account uses two-factor authentication. A stolen password alone should never be enough.
Complete audit trail
The production design records access to patient information and retains ID-only audit records for seven years.
Kept out of emails and analytics
Patient details belong in protected application flows. Notifications and usage summaries contain no conversation text.
Never used to train AI
Office information is used to answer your team’s questions, not to train AI models. AI requests stay within AWS’s covered services.
Role-based access
Staff see their own chat history. Managers see usage summaries, not staff questions or answers.
Protected at every step
Your team asks a question
Staff sign in with two-factor login and ask for guidance.
Encrypted in transit
The question travels over an encrypted connection.
Your office’s space
Only your office’s playbook and shared knowledge are searched.
HIPAA-covered AI
The answer is generated within AWS under its BAA.
Logged and stored
The exchange is encrypted at rest and access is recorded.
Shared responsibility
Compliance is a partnership. Here’s who does what.
What Occlu does
- Provide a BAA for your practice
- Use covered services under vendor BAAs
- Encrypt, isolate and audit access to your data
- Monitor, patch and test the systems
- Maintain a risk assessment and security policies
- Follow documented incident and breach procedures
What your office does
- Sign the BAA before using the service
- Give each staff member their own login
- Remove access when someone leaves
- Keep two-factor login devices secure
- Include Occlu in your own HIPAA training
Asked regularly