Secure by default. Transparent by design.
Othisis is designed to provide AI-powered clinical documentation and data processing as a pure data processor. We do not practice medicine, and we do not turn PHI into a product.
Othisis functions as a Business Associate, not a data owner. Your patients' PHI is owned by the Covered Entity and patient; Othisis is a tool and processor not a secondary controller and not a direct monetizer of PHI.
"We built Othisis with a simple assumption: our data protection choices may be reviewed by a regulator, a hospital privacy officer, or an attorney."
Clinicians should feel supported, not replaced. This isn't just a product choice—it's a trust choice.
We aim to collect, store, and expose only the data necessary for a specific purpose. Access to PHI is designed around least privilege and "minimum necessary," and PHI is not sent to tools or vendors without a valid purpose and documented controls.
Non-production environments use de-identified or synthetic data. This reduces risk while still allowing teams to test and improve the system safely.
We treat third parties as part of the risk surface, not an afterthought:
We keep our security posture factual and specific, focused on clinical outcomes rather than just infrastructure.
We maintain audit visibility across systems that process PHI so that access and activity can be reviewed for compliance and operational accountability.
We use role-based access control (RBAC) to limit access based on job function and the principle of least privilege.
This posture applies to PHI/ePHI processed through Othisis, including audio, transcripts, notes, PDFs, AI outputs, metadata, and logs that may contain PHI across production and non-production environments.
Othisis retains personal data only for as long as necessary to provide the service, maintain security, comply with legal obligations, and enforce our agreements. Account data is retained while your account is active. Audio recordings, transcripts, uploaded files, AI-generated notes, and related content are retained only as long as needed to operate and support the service.
If you would like your account or personal data deleted, you may submit a request by emailing support@othisismedtech.com. Once we verify your request, we will delete your account and associated personal data within 30 days, unless we are required or permitted to retain certain information for legal, regulatory, compliance, security, fraud-prevention, billing, tax, audit, backup, or dispute-resolution purposes.
If Othisis processes information on behalf of a healthcare provider or organization, certain data may be retained, returned, or deleted according to applicable law, contractual obligations, and our agreements with that organization.