Data Security
A structured, BAA-based process before patient-related billing data is reviewed.
Business inquiry first. Sensitive data later.
OriNova website forms are limited to general business information. Patient-related billing data is only considered after the project scope, service agreement, BAA when applicable, and approved secure transfer process are in place.
- Minimum-necessary data requests
- Named-user access and role limitations
- Approved secure transfer and storage methods
- Quality and scope controls
- Closeout, retention, and deletion decisions
Agreement first
Applicable service agreements and BAAs are completed before PHI review.
Minimum necessary
Only the records needed for the agreed scope and review period are requested.
Limited use
Client-provided information is used only for the agreed operational review and deliverables.
No bank access
OriNova does not require access to clinic bank accounts.
No website uploads
Do not upload EOBs, screenshots, or patient-level files through public website forms.
Escalation
Security, legal, coding, clinical, and payer-specific questions are escalated when required.
