Data Security

A structured, BAA-based process before patient-related billing data is reviewed.

Controlled handling

Business inquiry first. Sensitive data later.

OriNova website forms are limited to general business information. Patient-related billing data is only considered after the project scope, service agreement, BAA when applicable, and approved secure transfer process are in place.

  • Minimum-necessary data requests
  • Named-user access and role limitations
  • Approved secure transfer and storage methods
  • Quality and scope controls
  • Closeout, retention, and deletion decisions
Data security shield illustration

Agreement first

Applicable service agreements and BAAs are completed before PHI review.

Minimum necessary

Only the records needed for the agreed scope and review period are requested.

Limited use

Client-provided information is used only for the agreed operational review and deliverables.

No bank access

OriNova does not require access to clinic bank accounts.

No website uploads

Do not upload EOBs, screenshots, or patient-level files through public website forms.

Escalation

Security, legal, coding, clinical, and payer-specific questions are escalated when required.