Privacy

What auro collects from a practice and its patients, why it is collected, where it lives, who can see it and what can be switched off. The binding text is published at sign-up. This page says plainly what the software does.

What auro collects, and why

On the patient’s side: the chart, the visits and their recordings and transcripts, the notes and care plans, what the patient logs, the eligibility answers Lana brings back, the claims and the remittances, and the messages between the patient and the practice. On the practice’s side: the people who work there and the role each of them holds, the settings, the catalogue and the billing account.

Each of those exists because a screen or a claim needs it. auro does not collect a field to see what it might be useful for later, and it does not buy or sell information about a patient or a practice to anyone.

Protected health information, and the business associate agreement

Everything in a patient’s record is protected health information: the chart, the logs, the recordings, the transcripts, the claims and the messages. auro is a business associate of the practice, and the business associate agreement is signed when the practice signs up, before a single record exists.

It covers every product, every user and every sub-processor listed further down this page. The full agreement is published at sign-up; this page says what it does, not what it says.

Where the data lives, and how it is held

Data is hosted in the United States. It is encrypted with AES-256 at rest and with TLS in transit, and backups stay in the same region as the records they back up.

Nothing about a patient is copied onto a laptop to make a feature work, and no record leaves the practice’s boundary to be looked at by a human at auro without the practice asking us to look.

Retention and purge

Records are kept on the practice’s own retention schedule, because the practice, not auro, decides how long its clinical records live. Call recordings are kept for thirty days with their transcripts.

When a practice leaves auro, its records are exported to it and then purged. A patient’s deletion request goes to the practice that holds the record; when the practice tells us to delete, we delete, and the deletion itself is written to the audit log.

Who can see what

Every user is a role: owner, lead dietitian, clinician, coordinator, patient. The record shows each role only what its work needs, and the database enforces it rather than the screen, so a page cannot show what the role is not allowed to read.

Every provider signs in with multi-factor authentication. Sessions expire. The audit log records who opened which record, what they changed, what the software did on their behalf, and when, and it is append-only.

The model boundary

The model interprets; it never holds the record. It reads a visit, a call or a claim in order to draft a note, classify a code or pull a benefit out of a conversation, and the practice’s own database holds the truth that comes out of it. Identity is stripped at the boundary before the model sees anything.

No patient data is used to train a model, ours or a vendor’s, and the vendor is bound to the same by contract. One practice’s data does not shape another practice’s behaviour without that practice’s consent in writing.

Privacy choices

What a practice and a patient can actually switch. None of these needs a support ticket: each is a setting on the record, or one line in an email to privacy@theaurohealth.com.

A patient’s choices are made with the practice that holds their record, because the record is the practice’s. auro carries them out and writes the change to the audit log.