PRIVACY POLICY

Ordina Health | Order Management Platform for Agencies and Physicians

Let me be clear. You walked into our platform because you needed the best. Faster order processing, seamless physician sign-offs, analytics that actually mean something. And when you walk through that door, your data walks in with you. So let me tell you exactly what we do with it. Because unlike most companies, we don't hide behind sixty pages of legal jargon nobody reads. We lay it out.

1. WHO WE ARE

Ordina Health operates the order management platform at ordina.health. We build workflow solutions for healthcare agencies and physicians: order creation, e-signatures, EMR integration, eFax delivery, real-time tracking, and smart analytics. We're not a hospital. We're not an insurance company. We're the infrastructure that makes healthcare order management actually work.

When this policy says "we," "us," or "Ordina," it means Ordina Health. When it says "you," it means you: the agency administrator, the physician, the staff member, or anyone else using our platform or visiting our website.

2. WHAT WE COLLECT

I don't believe in surprises. Here's what comes through the door when you use Ordina:

  • Account & Identity Information. Your name, email address, phone number, professional credentials, NPI number, organization name, and role. The basics. You can't sign orders as "Anonymous."
  • Patient & Order Data. Order details, patient identifiers, clinical information, physician annotations, e-signatures, and delivery confirmations. This is the work product. This is what flows through our platform between agencies and physicians.
  • Usage & Technical Data. IP addresses, browser type, device information, pages visited, clicks, timestamps, and session data. We track how you use the platform so we can make it better. Not to sell you shoes.
  • Communication Data. Emails, support tickets, phone calls, and any messages exchanged through our platform. If you talk to us, we remember what was said.
  • Payment & Billing Information. Billing addresses, transaction records, and subscription details. Credit card numbers are processed by our payment partners. We don't store them. We're good, but we're not a bank.

3. HOW WE USE IT

Every piece of data we collect has a job. No exceptions.

  • To deliver the platform. Order creation, routing, e-signatures, EMR synchronization, eFax delivery, real-time tracking. Everything you signed up for.
  • To keep things running. System monitoring, performance optimization, bug fixes, security enforcement. The 24/7 live updates and 87% faster processing we promise? That doesn't happen by accident.
  • To generate your analytics. Those 50+ report types and revenue tracking dashboards with 98% reconciliation accuracy? Built from your operational data.
  • To communicate with you. Service updates, security alerts, support responses, and (only if you opted in) product announcements.
  • To comply with the law. HIPAA, state health information privacy laws, and any regulation that applies. We don't cut corners on compliance.
  • To improve the platform. Aggregated, de-identified usage patterns help us build better features. Your specific data stays yours.

4. PROTECTED HEALTH INFORMATION & HIPAA

Now pay attention, because this is where it matters most.

Ordina processes Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). We operate as a Business Associate to covered entities: healthcare agencies and physician practices that use our platform.

That means we enter into Business Associate Agreements (BAAs) with every covered entity we work with. No BAA, no PHI processing. Period.

We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule. We encrypt PHI in transit and at rest. We restrict access through role-based controls. We log access events. We train our people. And when the law says we report a breach, we report it. Within the timeframes required, without excuses.

PHI is never used for marketing. PHI is never sold. PHI is never shared with anyone who doesn't have a legal right and a legitimate need to see it.

5. WHO SEES YOUR DATA

We don't hand out your information like business cards at a networking event. Access is limited to those who need it and are authorized to have it:

  • Within Ordina. Our employees and contractors, bound by confidentiality obligations and trained on data handling. Access is role-based, logged, and audited.
  • Your Counterparties. If you're an agency, the physicians on your orders see relevant order data. If you're a physician, the submitting agency sees your sign-off. That's how the platform works.
  • Service Providers. Cloud hosting, payment processing, eFax transmission, email delivery. They process data on our behalf, under contract, with restrictions. They don't get to do what they want with it.
  • Legal & Regulatory. Law enforcement with a valid subpoena or court order. Regulatory bodies with jurisdiction. We don't volunteer information, but we don't obstruct lawful process either.
  • Business Transfers. If Ordina is acquired, merged, or restructured, your data transfers with the business, under the same protections or better.

We do not sell personal information. We do not share it with data brokers. We do not let advertisers into our platform. Full stop.

6. HOW WE PROTECT IT

Security isn't a feature we added. It's the foundation we built on.

  • Encryption. TLS 1.2+ in transit. AES-256 at rest. Your data is locked down whether it's moving or sitting still.
  • Access Controls. Role-based permissions, multi-factor authentication, session management. You see what you're authorized to see. Nothing more.
  • Infrastructure. Our systems are hosted in SOC 2-compliant data centers with physical security, redundancy, and disaster recovery.
  • Monitoring. Real-time threat detection, intrusion prevention, and security logging. If something looks wrong, we know about it before you do.
  • Incident Response. Documented procedures for identifying, containing, and remediating security incidents. Breach notification as required by HIPAA and applicable state laws.

No system is perfectly immune. But ours is built by people who take this personally.

7. DATA RETENTION

We keep your data as long as there's a legitimate reason to keep it: active account, ongoing service, legal obligation, or dispute resolution. When the reason ends, the data goes. We don't hoard what we don't need.

For PHI, retention follows HIPAA requirements and applicable state medical record retention laws, typically six to ten years depending on jurisdiction.

When data is deleted, it's deleted. Not archived in a folder someone forgot about. Deleted.

8. YOUR RIGHTS

Depending on where you are and what laws apply to you, you may have the right to:

  • Access your personal information and obtain a copy.
  • Correct inaccurate or incomplete data.
  • Delete personal information, subject to legal retention requirements.
  • Restrict or object to certain processing activities.
  • Port your data to another service in a structured, machine-readable format.
  • Withdraw consent where processing is based on consent.
  • File a complaint with a supervisory authority.

For PHI, your rights under HIPAA (access, amendment, accounting of disclosures, restrictions, confidential communications) are handled through your covered entity, meaning the agency or practice, not directly through Ordina. That's how HIPAA works. We assist them in fulfilling those obligations.

To exercise any right, contact us. We respond. We don't stall, and we don't make you jump through hoops.

9. COOKIES & TRACKING

Our website uses cookies. Not because we enjoy it, but because the platform doesn't function without session management and authentication tokens.

  • Essential Cookies. Authentication, security, session persistence. Non-negotiable. The platform breaks without them.
  • Analytics Cookies. Aggregated usage data to understand how the platform is used. No personal profiles. No ad targeting.

We do not use third-party advertising cookies. We do not participate in cross-site tracking networks. We do not build shadow profiles of people who haven't signed up.

You can configure your browser to reject non-essential cookies. If essential cookies are blocked, some platform features won't work. That's not a threat. It's physics.

10. CHILDREN'S PRIVACY

Ordina is a professional healthcare platform. It is not designed for, directed at, or intended for use by individuals under 18. We do not knowingly collect personal information from minors. If we discover we have, we delete it. Immediately.

11. THIRD-PARTY LINKS

Our platform may contain links to third-party websites or services: EMR systems, scheduling tools, external resources. Once you leave our platform, you're in someone else's house. Their rules apply. We're not responsible for their privacy practices, and linking to them is not an endorsement.

12. CHANGES TO THIS POLICY

We reserve the right to update this policy. When we do, we'll post the revised version on our website with a new effective date. For material changes, the kind that actually affect how your data is handled, we'll notify you through the platform or by email.

We won't quietly rewrite the rules and hope you don't notice. That's not how we operate.

13. CONTACT US

You have questions. We have answers. Reach out.

Ordina Health
Email: info@ordina.health
Website: ordina.health

For HIPAA-related inquiries, data subject requests, or if you believe your information has been mishandled, contact us directly. We take every inquiry seriously, and we respond promptly.

You came to Ordina because you wanted the best in healthcare order management. We handle your data the same way: with precision, with purpose, and without apology.