Privacy Policy
Ordavo Health LLC ("Ordavo," "we," "us") operates ordavohealth.com and provides software that enables health care agencies to obtain electronic physician signatures on medical orders. This Privacy Policy explains how we handle information.
Important distinction. This policy covers information we collect through our website and from the business contacts of our customers. It does not govern patient health information. Patient information that a customer agency submits to our software is Protected Health Information handled under HIPAA and under a Business Associate Agreement with that agency. Section 4 explains that relationship.
1. Information We Collect
1.1 Information you give us. When you request access, contact us, or correspond with us, we collect your name, business email address, telephone number, company name, city and state, role, and anything you choose to write to us.
1.2 Customer account information. When an agency becomes a customer, we collect account credentials, agency contact and business details, and the names and business contact information of the physicians and staff the agency chooses to add.
1.3 Information collected automatically. When you visit our website we may collect your IP address, browser type, device type, referring page, and pages viewed. We use this for security and to understand general site usage.
1.4 We do not use advertising trackers. We do not sell your information, and we do not permit third-party advertising networks to track you on our site.
2. How We Use Information
We use the information described above to:
- Respond to your inquiry and communicate with you about Ordavo
- Provide, maintain, secure, and improve our software
- Authenticate users and protect against unauthorized access
- Send service-related notices, including security and billing notices
- Comply with legal obligations and enforce our agreements
We will not sell your information. We will not use information you provide to train machine learning models.
3. How We Share Information
We share information only as follows:
3.1 Service providers. With vendors who help us operate, such as cloud hosting, email delivery, and payment processing. These vendors are bound by contract to protect the information and to use it only to provide services to us. Where they may handle Protected Health Information, we execute a Business Associate Agreement with them.
3.2 Legal requirements. When required by law, subpoena, or valid legal process, or to protect the rights, safety, or property of Ordavo, our customers, or others.
3.3 Business transfer. In connection with a merger, acquisition, or sale of assets, subject to the acquirer honoring commitments made in this policy.
3.4 With your direction. When you ask us to.
We do not share information with advertisers or data brokers.
4. Patient Health Information
4.1 When an agency uses our software, patient information belongs to that agency. Ordavo acts as a Business Associate under HIPAA and processes that information only as permitted by our Business Associate Agreement with the agency and as necessary to provide the software.
4.2 We do not use patient information for our own purposes, do not sell it, and do not use it for marketing or model training.
4.3 If you are a patient with a question about your health information, please contact the agency providing your care. They are the Covered Entity and control your records. We will direct any request we receive from a patient to the relevant agency.
4.4 If you are a physician signing an order through Ordavo, we process your name, professional identifiers such as your NPI, your signature image, and records of your interaction with the order (such as when you opened and signed it) in order to create a valid, auditable signature record. This information is provided by, and belongs to, the requesting agency.
5. How We Protect Information
We maintain administrative, physical, and technical safeguards designed to protect information, including encryption in transit and at rest, strict access controls, tenant isolation so that no customer can access another customer's data, audit logging, automatic session termination, and periodic review of our security practices.
No system is perfectly secure, and we cannot guarantee absolute security. If we experience a breach affecting your information, we will notify you and any affected agency as required by law.
6. Retention
We retain website inquiry information for as long as needed to respond and for our records, and business account information for the life of the customer relationship plus a reasonable period thereafter.
Patient health information is retained and disposed of according to the Business Associate Agreement with the relevant agency, which requires return or destruction upon termination.
7. Your Choices and Rights
- Access and correction. You may ask us what business contact information we hold about you and request correction.
- Deletion. You may ask us to delete your business contact information, subject to our legal and recordkeeping obligations.
- Marketing. You may opt out of non-essential communications at any time. We will still send necessary service and security notices to active customers.
To exercise any of these, email privacy@ordavohealth.com.
Requests regarding patient health information must be directed to the agency providing care, as described in Section 4.3.
8. Other Terms
8.1 Children. Our software is a business tool and is not directed to children. We do not knowingly collect information directly from children through our website.
8.2 Third-party links. Our website may link to other sites. We are not responsible for their privacy practices.
8.3 United States. Ordavo is based in Texas and our services are intended for use in the United States. Information is processed in the United States.
8.4 Changes. We may update this policy. If we make material changes we will update the "Last Updated" date and, for active customers, provide notice.
9. Contact Us
Email: privacy@ordavohealth.com
Website: ordavohealth.com