Security, in plain English.
Hosting and BAA
Obexa runs on Google Cloud under Google's Business Associate Agreement, using services covered by that agreement. Obexa signs a BAA with each healthcare customer.
Encryption
All traffic uses HTTPS (TLS). Data is encrypted at rest by the cloud provider, including databases and backups.
Data minimization
Patients are identified by chart number, not name. Insurance documents and photos are read in memory and are not stored. Names, birth dates, member IDs, phone numbers and addresses are removed from what the system keeps.
Short retention
Chairside notes, dictation text, intake highlights and medical history answers are erased automatically 7 days after checkout. Voice recordings are never stored.
Access controls
Every account is individual and role-based. Two-step sign-in with an authenticator app, automatic sign-out after 15 minutes idle, sign-in attempt limits, and an extra Google sign-in layer in front of the staff app.
Tenant isolation
Each practice and each office only sees its own data. The public demo runs on a completely separate database with sample data only.
Audit logging
Estimates, plan and fee schedule changes, user and password changes, and chairside actions are written to an audit log with who did it and when.
Backups
Encrypted nightly backups with versioning and retention, stored separately from the application.
AI and subprocessors
Speech-to-text and document reading use Google Cloud services covered by Google's BAA. Patient data is not used to train AI models. Insurance math and code rules run in Obexa's own engine.
Incidents
Suspected incidents are investigated right away and customers are notified as required by HIPAA and their BAA.
Deletion
Customers can ask for their data to be deleted when they leave. Backups age out on their retention schedule.
Your responsibilities
Keep accounts individual, turn on two-step sign-in for every user, and remove staff accounts promptly when someone leaves.
Need more detail for your compliance review?
We share our BAA, security summary and subprocessor list with customers and serious prospects. Ask below.
Ask for our security packet.
Tell us what your compliance review needs. We will send the BAA, security summary and subprocessor list.