Security and compliance

Built to keep only what it needs, and protect what it keeps.

How Obexa handles protected health information and business data. Written in plain English, for owners and compliance reviewers.

What we do

Security, in plain English.

Hosting and BAA

Obexa runs on Google Cloud under Google's Business Associate Agreement, using services covered by that agreement. Obexa signs a BAA with each healthcare customer.

Encryption

All traffic uses HTTPS (TLS). Data is encrypted at rest by the cloud provider, including databases and backups.

Data minimization

Patients are identified by chart number, not name. Insurance documents and photos are read in memory and are not stored. Names, birth dates, member IDs, phone numbers and addresses are removed from what the system keeps.

Short retention

Chairside notes, dictation text, intake highlights and medical history answers are erased automatically 7 days after checkout. Voice recordings are never stored.

Access controls

Every account is individual and role-based. Two-step sign-in with an authenticator app, automatic sign-out after 15 minutes idle, sign-in attempt limits, and an extra Google sign-in layer in front of the staff app.

Tenant isolation

Each practice and each office only sees its own data. The public demo runs on a completely separate database with sample data only.

Audit logging

Estimates, plan and fee schedule changes, user and password changes, and chairside actions are written to an audit log with who did it and when.

Backups

Encrypted nightly backups with versioning and retention, stored separately from the application.

AI and subprocessors

Speech-to-text and document reading use Google Cloud services covered by Google's BAA. Patient data is not used to train AI models. Insurance math and code rules run in Obexa's own engine.

Incidents

Suspected incidents are investigated right away and customers are notified as required by HIPAA and their BAA.

Deletion

Customers can ask for their data to be deleted when they leave. Backups age out on their retention schedule.

Your responsibilities

Keep accounts individual, turn on two-step sign-in for every user, and remove staff accounts promptly when someone leaves.

Questions

Need more detail for your compliance review?

We share our BAA, security summary and subprocessor list with customers and serious prospects. Ask below.

Ask for our security packet.

Tell us what your compliance review needs. We will send the BAA, security summary and subprocessor list.

Please don't include any client or patient information in this form. See our privacy notice.