Security
Last updated: May 10, 2026
Ordani is built for HIPAA-context practice. Security isn't a feature; it's the foundation. This page describes the controls we have in place today. We'll keep it current as the platform evolves.
HIPAA and BAA
We sign a Business Associate Agreement (BAA) with every provider at trial start, before any client data enters the platform. Ordani acts as a Business Associate to your practice; the BAA captures our commitments under HIPAA § 164.504(e). Every provider on the platform operates under a signed BAA — there is no “PHI without paperwork” mode.
Encryption
All traffic is encrypted in transit with TLS 1.2 or newer. Data at rest is encrypted with AES-256 at the database layer, and backups carry the same encryption. Row-Level Security policies are enforced on every table that touches PHI; database-level access controls are the last line of defense, not the first.
Authentication
Provider accounts authenticate with email and password. Multi-factor authentication is available for every account and is enforced for administrative operations. Sensitive workflows (admin actions, audit access) require step-up authentication (AAL2) per HIPAA § 164.312(d). Password requirements are enforced server-side and session tokens are rotated on a regular schedule. Failed sign-in attempts are rate-limited and logged.
Audit logging
Every read and write on PHI tables is recorded by a database trigger into an append-only audit log. The trigger path is covered by automated regression tests so the logging cannot be silently bypassed by a future code change. Logs are retained for six years per HIPAA § 164.530(j) and are available to your account's designated privacy officer.
Antivirus scanning on uploads
Every uploaded file — documents, photos, intake PDFs, signed forms — is scanned by ClamAV before it becomes accessible. Files that fail the scan are quarantined and cannot be downloaded. A defense-in-depth signed-URL guard refuses to issue links for non-clean files at the API layer, so a stale URL cannot exfiltrate a quarantined file.
Backup and recovery
Automated daily backups run on every database. Point-in-time recovery is available within the last seven days. Our disaster recovery targets are a 24-hour Recovery Time Objective (RTO) and a 1-hour Recovery Point Objective (RPO). Backup integrity is verified on a regular schedule.
Infrastructure
Ordani is hosted on BAA-covered cloud infrastructure providers in the United States. All vendors who could ever touch PHI are covered by signed BAAs. The full subprocessor list is available to providers on request.
Vulnerability management
Static analysis and secret scanning run on every code change as mechanical enforcement, not as advisory checks. A typed, test-covered codebase makes regressions cheap to catch. We track and patch vulnerabilities in our dependencies on a regular schedule, and we run additional review for changes that touch authentication, authorization, or PHI flow.
Reporting and disclosure
To report a vulnerability or ask a compliance question, email security@ordani.com. We respond within two business days. Responsible disclosure is welcomed and acknowledged.
Contact
Security questions: security@ordani.com.