DENTAL DATA SECURITY

Know Exactly How Your Patient Data Is Protected

Every layer of Oryx is built to keep your practice data encrypted, backed up, and compliant with HIPAA and PIPEDA requirements.

Your data. Your practice. Your control.

How Oryx Keeps Patient Data Secure

When a patient sits down in your chair, they’re trusting you with more than their dental health. Their name, insurance details, medical history, and clinical records all pass through your practice software every single day. That’s a significant amount of sensitive information, and it comes with real legal accountability under HIPAA in the United States and PIPEDA in Canada.

Oryx is designed to meet those requirements at every level, not just on paper. Here is exactly what that means for your practice.

HIPAA United States PIPEDA Canada PHIPA Ontario

PROTECTION AT EVERY LAYER

On by Default, Not Configured by You

These controls run behind every Oryx account without anyone on your team setting them up.
Oryx Academy Training Portal icon

HIPAA, PIPEDA, and PHIPA

Designed to support the privacy laws where you operate. In Ontario, Oryx acts as your Electronic Service Provider, so your practice keeps full legal ownership.
Oryx Academy Training Portal icon

Encryption in Transit and at Rest

HTTPS with TLS while data moves, the same standard that protects online banking. AES-256 at rest, covering everything stored on the platform, including your backups.
Oryx Academy Training Portal icon

Automated Daily Backups

Your data is backed up automatically every day and copied across multiple Google Cloud locations, so no single failure can wipe all of them out.
Oryx Academy Training Portal icon

Two-Factor Authentication

A second verification step at login, separate from your password. Even if someone’s credentials are ever compromised, they still can’t reach your Oryx account.
Oryx Academy Training Portal icon

Role-Based Permissions

Assign roles by position, so your front desk, billing staff, and clinical providers each see only the patient information their own work actually requires.
Oryx Academy Training Portal icon

Full Audit Trails and Monitoring

Every chart opened, treatment plan edited, and billing entry updated is logged, timestamped, and tied to a user. Continuous monitoring flags unusual activity.
Oryx Academy Training Portal icon

Limited Access on Our Side

Oryx staff access is restricted to authorized personnel, governed by least-privilege rules, logged and auditable. Administrative access to infrastructure runs through Google Cloud IAM.
Oryx Academy Training Portal icon

AI That Never Trains on Your Data

Identifiable patient information is never used to train AI or machine learning models. Enterprise Google Cloud agreements contractually prohibit it, and nothing is ever sold.
90 Days of Backups

Ninety Days of Backups Nobody Can Delete Early

Your data is backed up every day and held for 90 days across multiple Google Cloud locations, inside Google-managed vaults that block early modification or deletion, even by a compromised administrative account. Point-in-time recovery covers the past seven days.

Your Data, Your Control

Security isn’t only about keeping threats out. It’s also about making sure your practice stays in full control of its own information, from where it’s stored to who can access it.
01
Ownership

Your Data Belongs to You

Patient records, clinical notes, imaging, communications, billing information: all of it belongs to your practice, not Oryx. Your data is never mined for advertising, never sold or shared for external commercial use, and never deleted if you leave until you've had time to export it.

02
Fewer Handoffs

One Platform, One Secure Environment

Every time patient data moves between separate tools, it creates a potential exposure point. Oryx handles clinical records, patient communication, scheduling, and billing in one place, so your practice isn't routing sensitive data through a stack of third-party integrations. Fewer handoffs mean fewer risks.

03
Infrastructure

Built on Google Cloud Platform

Oryx is hosted on the same enterprise infrastructure major health systems and financial institutions rely on for sensitive data. US practices are hosted on US servers, Canadian practices in Montreal. Redundant data centers, load balancing, and high-availability replicas keep the platform running.

Common Security Questions

Access is restricted to authorized personnel who need it to support the platform, and it's governed by least-privilege and minimum-necessary principles. Every access is logged and auditable, and administrative access to infrastructure runs through Google Cloud Identity and Access Management.

For Ontario practices, Oryx personnel access patient information solely as authorized agents acting on behalf of the custodian under PHIPA Section 17.

Yes. Each user is assigned a role with read, write, and delete privileges based on what their position actually requires, so your front desk team, billing staff, and clinical providers each see only what's relevant to their work. Permissions are fully customizable, and two-factor authentication with a rolling key controls access from outside the office on a per-user basis.

You can request an export at any time, or when service ends. Exports can include patient records, clinical charting, treatment history, billing information, communications, documents, images, radiographs, and DICOM files.

Structured information is delivered in CSV format. Documents and images come in their original file formats, using secure transfer methods. If you leave, Oryx does not delete your data until you have had sufficient opportunity to export it.

On Google Cloud Platform, in the region that matches your geography. United States practices are hosted in Google Cloud's U.S. regions.

Canadian practices are hosted in the northamerica-northeast1 (Montréal) region. That covers production databases, application servers, storage, search, daily backups, point-in-time recovery, and high-availability replicas. Canadian backups remain in Canada.

No. Identifiable patient information is never used to train AI or machine learning models. Where Oryx uses AI, it runs under enterprise Google Cloud Platform agreements rather than consumer AI services, and those agreements contractually prohibit customer information from being used to train Google's foundation models.

Oryx may use de-identified and anonymized information to improve models used only within Oryx products. That process follows documented de-identification standards informed by guidance from Ontario's Information and Privacy Commissioner, which remove identifiers including patient names, contact information, geographic detail, imaging metadata, and DICOM identifiers. Employees are prohibited from attempting to re-identify anonymized information, and Oryx never sells anonymized data or shares it for third-party commercial purposes.

If Oryx confirms unauthorized access to your information, your practice is notified without unreasonable delay, along with the available detail on the nature and scope of the incident and the containment actions taken.

Oryx cooperates with your own notification obligations and supports your practice in responding to privacy regulators where appropriate, including the Information and Privacy Commissioner of Ontario.

Oryx is built for high availability on Google Cloud Platform. Traffic is load balanced across multiple frontend and application instances, production databases are replicated with high-availability replicas and automated regional failover, and software is released in rolling deployments with rollback capability to limit disruption. Server health and application performance are monitored continuously.

Behind that, your data is backed up automatically every day and retained for 90 days across multiple zones or regions, with point-in-time recovery available for the past seven days.

A SOC 2 audit against the Security Trust Principles is currently in progress. Today, Oryx maintains security and privacy controls designed to support customer compliance with HIPAA, PIPEDA, and Ontario PHIPA, and reviews those controls on an ongoing basis as regulations and industry practices evolve.

Questions About How Oryx Handles Your Practice’s Data?

Book a demo and we’ll walk through Oryx’s security architecture, compliance documentation, and data practices in as much detail as you want.