Security & privacy

Built to hold as little of your data as possible.

You handle protected health information every day — so you know the questions to ask. Here's exactly how Occlara treats your data, what we minimize, and our honest roadmap to HIPAA-grade controls. No hand-waving.

PHI-safe by design

What we do — today

PHI-light architecture

Identifiers are minimized server-side before any AI call. Reconciliation runs on CPT codes, RVUs, and dollars — not patient identity.

Encrypted in transit and at rest

Your uploads and the data derived from them are encrypted end-to-end through our infrastructure providers.

Per-tenant isolation

Every row is scoped to your account with Postgres Row-Level Security and least-privilege access. Your data is never comingled with another physician's.

Human-in-the-loop

Nothing enters reconciliation until you confirm it. Low-confidence extractions are quarantined for your review before they ever count.

You own your data

We don't sell your data, and we don't use your documents to train models. Export or delete on request.

PHI-free billing

Subscription billing never receives procedure or clinical detail — we bill a flat SaaS seat, and nothing clinical touches the payment processor.

Path to HIPAA compliance

Where we're headed — and where we are

Occlara is engineered for HIPAA-grade controls from day one, but we'll be candid: we are in private beta and are not yet operating as a HIPAA-covered system of record. Before we handle protected health information at scale, we execute Business Associate Agreements (BAAs) with the subprocessors below and enable their HIPAA controls. Until then, we keep the product deliberately PHI-light and onboard every early user by hand.

SubprocessorRoleBAA / HIPAA posture
SupabaseDatabase · auth · file storageBAA available on Team + HIPAA add-on — executed before PHI.
VercelApplication hosting · serverlessBAA available on Pro — executed before PHI.
Anthropic (Claude)Document extraction (AI)BAA available on Enterprise — executed before PHI; inputs minimized.
StripeSubscription billingNo BAA — used PHI-free by design; never receives clinical detail.
Where we are today

Private beta · hand-onboarded · numeric-first extraction with identifiers minimized before any AI call. We'll update this page as each BAA is executed and each control is turned on — so you can see the roadmap become reality, not just a promise.

Our stack

What Occlara is built on

Transparency over black boxes. These are the technologies behind the product and the role each one plays.

React · TanStack Start
Type-safe full-stack app; PHI logic stays server-side.
Supabase — Postgres + RLS
Row-Level Security enforces per-physician tenant isolation.
Vercel
Hosting and serverless functions for extraction & reconciliation.
Anthropic Claude
Structured document extraction from minimized inputs.
CMS Physician Fee Schedule
The public source of truth every earned-dollar traces to.
Scope

What Occlara is — and isn't

It is

An informational reconciliation tool that shows, in dollars, where your credited wRVUs and pay diverge from what your performed procedures should have earned against the CMS fee schedule.

It isn't

Legal, billing, or compensation advice; your employer's system of record; or a filing or appeals service. What you do with the numbers is your call.

Last updated: July 2026. This page describes our engineering approach and roadmap; it is not a compliance certification or legal advice. Formal Terms and a Privacy Policy accompany general availability.