HomeAnswersTrust & security

Is Orion HIPAA compliant?

The short answer

Yes, and not as a slogan: every practice executes a Business Associate Agreement (BAA) with Orion at onboarding. Orion encrypts protected health information in transit and at rest and enforces role-based access controls. HIPAA requires that written agreement before a vendor handles protected health information on a practice's behalf (45 CFR 164.502(e)). Orion adds two controls the clinic holds directly: IP allowlisting, so only the networks you approve can reach your data, and an exportable audit log, so you can prove who did what.

HIPAA compliance is the floor, not the ceiling, and the floor is more specific than the phrase suggests. A company that creates, receives, maintains, or transmits protected health information on your behalf is what HIPAA calls a business associate (45 CFR 160.103), and a practice may only hand that information over once it has “satisfactory assurance that the business associate will appropriately safeguard the information,” documented “through a written contract” (45 CFR 164.502(e)). That contract is the BAA, and at Orion it is not an on-request extra: executing one is part of onboarding, before any patient data moves. “HIPAA-ready” on a vendor homepage costs nothing to write; a countersigned BAA carries breach-notification duties the vendor answers for.

Past the paperwork, the Security Rule’s technical safeguards (45 CFR 164.312) are the checklist worth holding any vendor to. Audit controls are a standard there, not an optional specification: the rule requires mechanisms that “record and examine activity in information systems that contain or use electronic protected health information.” Encryption is listed as “addressable,” which obliges a vendor to assess it rather than simply implement it. Orion encrypts protected health information in transit and at rest, keeps access role-based, and hands the clinic two controls of its own: an IP allowlist that restricts access to the networks you approve, and an exportable audit log, so the record of who did what is a file you hold rather than a report you request.

On the marketing side, no protected health information is ever collected through this website. The contact and demo forms ask for your name, work email, and practice name, and both say it plainly on the page: no patient information, please.

Ready when you are

See Orion on your own patients.

See Orion run your practice in a live demo, or take a guided Test Drive in a safe sandbox. Your current EHR keeps running the whole time.