Skip to content
Oli Health
Security & Privacy at Oli Health

Trust Center

When we handle protected health information for a covered-entity customer, Oli Health acts as its HIPAA Business Associate. This page summarizes how we protect practice and patient data and how to request detailed compliance information.

Request Compliance Information

Last updated: July 13, 2026

How does Oli Health protect practice and patient data?

Protecting health information shapes how we host and encrypt data, control production access, prepare for recovery, and govern AI features.

Where does Oli Health host your data?

Oli Health runs on managed enterprise cloud infrastructure. Production workloads use managed infrastructure and data services covered by Oli Health’s agreements with its providers.

  • Production workloads run on managed cloud infrastructure.
  • In-scope services are covered under Oli Health’s agreements with infrastructure providers.

How is your data encrypted?

Production data is encrypted at rest and in transit. Credentials use managed secret storage, and service connections use encrypted channels.

  • Production data is encrypted at rest and in transit.
  • Credential material and service connections use managed secret storage and encrypted channels.

Who can access production systems?

Only authorized staff can use secured administrative paths to reach production systems. Staff do not access patient data on local devices, and production access is logged.

  • Administrative access is restricted to secured production paths.
  • Production access is recorded in audit logs.

How does Oli Health recover from an outage?

We run scheduled backups and regularly test restore integrity. Critical production systems have 24-hour recovery-time and recovery-point targets unless a customer agreement requires stricter commitments.

  • Backups and restore-integrity tests run on a schedule.
  • Critical systems have 24-hour recovery-time and recovery-point targets by default.

How do AI features use patient data?

AI services process patient data only when a customer uses an AI feature. Approved providers are contractually prohibited from using identifiable protected health information to train third-party foundation models.

  • AI services process data only for customer-directed service delivery.
  • Identifiable protected health information is not used for third-party model training.

How does Oli Health review and select vendors?

Before Oli Health relies on a third party, we review its security posture, data handling, and role in the service. The review determines the contractual safeguards and minimum-necessary controls required for that use.

  1. 1

    Diligence before selection

    We assess the vendor’s security posture, data handling, hosting arrangements, and role in the service before approving a new data flow.

  2. 2

    Agreement requirements

    We document whether the vendor’s role requires a Business Associate Agreement or other contractual safeguards for the proposed use.

  3. 3

    Minimum-necessary access

    Approved vendors receive only the data required for their specific role, with controls tailored to the service path they support.

  4. 4

    Ongoing review

    We review vendor reliance on a schedule and when the product, data flow, or vendor relationship materially changes.

This documented process keeps vendor access deliberate, limited to its approved purpose, and subject to ongoing review.

Which standards inform Oli Health’s approach?

Want to go deeper? These government sources provide official context for the HIPAA, PIPEDA, and state and provincial privacy topics that inform Oli Health’s approach.

Related reading: Security & Compliance features · Privacy Policy · Terms of Service · Contact Us

Need more compliance information?

Need our HIPAA Attestation, BAA information, or help with a security concern?

Email our Security & Compliance team

Or write directly to security@olihealth.ai