Legal
Privacy Policy
Effective 2 September 2026 · Orenda Intelligence, LLC · Campbell, California
Orenda Intelligence provides clinical and financial decision support to skilled nursing facilities. Nearly everything we process is protected health information belonging to a facility's residents, and it is not ours. This page describes what we do with it.
01Our role: Business Associate, not Covered Entity
Under HIPAA, the facility that uses the platform is the Covered Entity and Orenda Intelligence, LLC is its Business Associate. We process protected health information (PHI) only to perform the services the facility has engaged us for, and only as its Business Associate Agreement permits.
That has a consequence worth stating plainly: we do not have an independent relationship with a resident, and we cannot act on a resident’s request about their own record on our own authority. Requests for access, amendment, an accounting of disclosures or restriction go to the facility, which holds the record. If a resident contacts us directly, we will refer them to their facility and tell the facility that we did.
02What we process
Resident information, from two sources: referral packets a facility uploads, and — where a facility connects one — a read-only feed from its electronic medical record. This includes identifiers, clinical history, diagnoses, medications, assessments, orders and notes.
Staff account information: name, work email, role, facility, authentication factors, and sign-in and access history.
Operational records: audit entries, request metadata and error diagnostics. These are deliberately kept free of clinical content — see clause 4.
We do not use advertising identifiers, we do not sell information of any kind, and we do not track visitors across other websites.
03Tenant isolation
Every record in the platform carries the identifier of the facility it belongs to, and every request is scoped to the facility of the account making it. An administrator’s privileges are a grant inside their own facility; they do not widen that boundary. Uploaded documents are stored under a per-facility prefix and a request for a document outside the caller’s own prefix is answered as though the document does not exist, because confirming that another facility holds it would itself be a disclosure.
04What we keep out of our logs
Our diagnostic logs contain no resident names, medical record numbers, dates of birth or clinical content, and neither do our error messages. This is enforced in code rather than by policy, because a log is the copy of a record that is hardest to account for and easiest to replicate.
Access to PHI is instead recorded in an append-only audit log — every view, list, export and change, with the acting account, the facility, the record and the time. Entries are never edited or deleted.
05How AI is used, and what the model is shown
The platform drafts clinical documentation and assessments using large language models. Two things about that are load-bearing.
First, inference runs on Amazon Bedrock inside our AWS account, under a signed Business Associate Agreement with AWS. Prompts and completions are not used to train any model. We do not route PHI to any model provider that is not covered by a BAA.
Second, direct identifiers are stripped before a clinical assessment is sent. Our assessment tools are built to run on age, sex and admission date; medical record numbers, names and dates of birth are removed from the material the model receives, and the prompt instructs the model not to reproduce identifiers it may nonetheless encounter in an uploaded document.
Model output is a draft. It is not a diagnosis, it is not a clinical decision, and nothing it produces enters a resident’s medical record unless a licensed clinician has reviewed and signed it. See clause 3 of the Terms of Service.
06Security
Traffic is encrypted in transit; stored data and backups are encrypted at rest. Uploaded documents travel from the browser directly to encrypted object storage over a short-lived signed URL, so a referral packet is never buffered in our application servers. Accounts authenticate with a password and, where enrolled, a second factor; a password change or an explicit revocation signs every other device out immediately. Responses carry no-store caching directives so a shared browser or proxy does not retain a resident record after sign-out.
No control set makes a system incapable of being breached. If a breach of unsecured PHI occurs, we will notify the affected facility without unreasonable delay and within the period its Business Associate Agreement and HIPAA require, and we will give it what it needs to make its own notifications.
07Subprocessors
We keep the list short on purpose. Compute, storage and model inference all run in our own Amazon Web Services account in the United States, under a BAA with AWS. We do not send PHI to analytics providers, advertising networks, customer-messaging tools or offshore support vendors. We will not add a subprocessor that receives PHI without a BAA in place with it, and we will tell affected facilities before we do.
08Retention, and what happens at the end
Audit and compliance records are retained for six years, which is what HIPAA requires of documentation. Resident information is retained for as long as the facility’s agreement provides and it remains necessary for the services.
When an agreement ends, we return or destroy the PHI we hold at the facility’s direction, except where retaining it is itself required by law — in which case we keep protecting it under these terms and limit further use to the purpose that requires the retention.
09Changes to this policy
We will post a revised effective date here when this policy changes, and we will notify facilities directly of a change that materially affects how we handle PHI. Where a facility’s Business Associate Agreement conflicts with anything on this page, that agreement controls.
10Contact
Privacy and security questions, including suspected vulnerabilities: admin@axisorenda.com. Orenda Intelligence, LLC, Campbell, California, United States.