What this policy covers.
This Privacy Policy describes how ORAYA Health, Inc. ("ORAYA," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the ORAYA platform, including:
- the ORAYA clinical platform used by healthcare providers and their staff;
- the MyORAYA patient application and patient portal;
- our websites at
orayasolutions.comand related subdomains; and - the email, SMS/text, and mobile push notifications we send in connection with those services
(collectively, the "Services").
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
- Quick summary of our text messaging practices
- Our role: health data, HIPAA, and your provider
- Information we collect
- How we use information
- Communications overview
- Text messaging (SMS) program
- How we share information
- Security
- Cookies and tracking
- Your choices and rights
- Data retention
- Children's privacy
- Where information is processed
- Changes to this policy
- Contact us
Our text messaging practices, stated up front.
These are the points people most want answered directly, so we state them here. They are repeated in full detail in Section 6.
We never share your number for marketing
We do not sell, rent, lease, trade, or share your mobile phone number, or your consent to receive text messages, with any third party or affiliate for their own marketing or promotional purposes. Mobile information is never shared with third parties for marketing purposes. The only parties that receive your mobile number are the communications vendors that transmit messages on our behalf, and only so that they can deliver the message you asked for.
Message frequency varies
ORAYA texts are transactional and event-driven, not recurring marketing campaigns. Most messages are sent only in direct response to something you do (for example, requesting a sign-in code). Typical volume is fewer than 10 messages per month.
Message and data rates may apply
Your mobile carrier's standard messaging and data charges apply to messages you send to and receive from ORAYA. ORAYA does not charge you for text messages.
You can stop messages at any time
Reply STOP to any ORAYA text message to opt out, or HELP for assistance. See Section 6.5.
Health data, HIPAA, and your provider.
Most of the health information in the Services (your medical record, visit notes, lab results, medications, allergies, and similar clinical data) belongs to and is controlled by the healthcare provider or clinic that treats you (the "Provider"). ORAYA processes that information as a Business Associate of the Provider under the Health Insurance Portability and Accountability Act ("HIPAA") and under a written Business Associate Agreement.
What this means in practice:
- Your Provider's Notice of Privacy Practices governs your Protected Health Information ("PHI"). ORAYA uses and discloses PHI only as permitted by that agreement and by law, to provide the Services to your Provider, and for no independent purpose of our own.
- We do not sell PHI. We do not use PHI for advertising, and we do not use PHI to train general-purpose or third-party artificial intelligence models.
- Requests to access, amend, or delete your medical record should go to your Provider, who is the record's custodian. We will assist your Provider in responding. See Section 10.
This Privacy Policy governs information ORAYA handles in its own capacity (for example, account credentials, device identifiers, contact details used for authentication, application logs, and website analytics) and describes the notification channels through which we reach you.
What we collect, and where it comes from.
3.1 Information you provide
| Category | Examples |
|---|---|
| Account and identity | Name, date of birth, email address, mobile phone number, and identifiers used to match you to your medical record |
| Authentication | Passwords, one-time passcodes ("OTP"), account recovery answers, security settings |
| Contact preferences | The email address and mobile number you designate for notifications, and changes you make to them |
| Content you submit | Messages you send through the app, appointment requests, record requests, self-reported medications, allergies, symptoms, and intake responses |
| Support communications | Information you provide when you contact us for support |
3.2 Information from your provider
Your Provider's electronic health record system supplies the clinical information shown in MyORAYA: visits, medications, allergies, immunizations, lab and imaging results, documents, and scheduling data.
3.3 Information collected automatically
- Device and app data: device model, operating system version, app version, language, and mobile push notification tokens.
- Usage and diagnostic data: feature interactions, screen views, crash reports, and performance metrics.
- Log data: IP address, timestamps, request identifiers, and security events such as sign-in attempts and device registrations.
- Cookies and similar technologies on our websites and web portal, for session management, security, and limited analytics. See Section 9.
Six purposes, and nothing beyond them.
We use information to:
- Provide the Services: authenticate you, connect your app account to the correct patient record, and display your health information.
- Send transactional notifications: verification codes, security notices, appointment updates, and reminders (see Sections 5–7).
- Secure the Services: detect and prevent fraud, account takeover, abuse, and unauthorized access; maintain audit trails required by HIPAA.
- Support you: respond to questions and troubleshoot issues.
- Improve and maintain the Services: diagnose errors, monitor performance, and develop features, using de-identified or aggregated data wherever possible.
- Comply with law: meet legal, regulatory, and public-health obligations.
Three channels, all transactional.
ORAYA communicates with you over three channels. All three exist to operate your account and your care, not to market to you.
| Channel | Used for | Provider |
|---|---|---|
| Verification codes, security notices, account and connection notices, invitations to connect your record | Amazon Simple Email Service (AWS) | |
| SMS / text | One-time passcodes and account-security alerts only | Twilio |
| Mobile push | Appointment confirmations, changes, cancellations, 24-hour appointment reminders, new document available, record-connection notices | Expo push notification service (Apple APNs / Google FCM) |
You choose which contact points we use by setting your email address and mobile number in the app, and by allowing or denying push notifications in your device settings.
Authentication and account-security messages only.
6.1 Program description and consent
The ORAYA/MyORAYA text messaging program sends authentication and account-security messages only: one-time passcodes and alerts about changes to the credentials protecting your account. The registered use case is Two-Factor Authentication (2FA). We do not send marketing, promotional, care, or general account notification text messages.
Consent is collected directly by ORAYA, from you, the account holder. You opt in by entering your own mobile number yourself, either in the MyORAYA app or at an ORAYA patient check-in kiosk, checking the consent box displayed with the number field (unchecked by default), and completing one-time passcode verification of that number. Checking the box is optional: you can complete check-in and use the Services without it. No one else can enroll a number on your behalf, and we never enroll a number obtained from any other source. Consent to receive texts is not a condition of receiving medical care or of using the Services; you may instead use email for verification and notices.
6.2 The messages we send
| Message | When it is sent |
|---|---|
| Sign-in verification code | Each time you request a code to sign in |
| Contact-change verification code | When you add or change an email address or mobile number |
| Contact-change notice | To your previous contact point, when your email or mobile number is changed |
| Account recovery notice | When your account is recovered on a new device and prior sessions are signed out |
Verification codes are sent only in response to an action you take. Notice messages are security tripwires: they are sent once, when the triggering event occurs, so that you learn promptly if someone else acted on your account.
Text messages are deliberately kept short and free of clinical detail. They do not contain diagnoses, test results, medications, or other Protected Health Information beyond the fact that you have a MyORAYA account.
6.3 Message frequency
Message frequency varies and depends on how you use the Services. ORAYA texts are event-driven rather than scheduled: you receive one message per sign-in code you request, one per contact change you make, and one per qualifying security event. There is no recurring campaign and no fixed monthly send.
For a typical user, this is fewer than 10 messages per month. Users who sign in frequently on new devices may receive more; users who sign in with a saved device or use email verification may receive none.
6.4 Message and data rates
Message and data rates may apply. Messages you receive from or send to ORAYA are subject to your wireless carrier's standard text messaging and data rates under your plan. ORAYA does not charge a fee for text messages. Check with your carrier if you are unsure of your plan's charges.
Carriers are not liable for delayed or undelivered messages. Message delivery is subject to your carrier's network availability, and we cannot guarantee that every message will be delivered.
Supported carriers include the major U.S. wireless carriers; carrier support may change without notice.
6.5 Opting out and getting help
- To stop messages: reply STOP to any ORAYA text message. You will receive a single confirmation that you have been unsubscribed, after which we will send no further texts to that number.
- To resume messages: reply START to the same number, or re-verify your mobile number in the MyORAYA app.
- For help: reply HELP to any ORAYA text message, or contact us at info@orayasolutions.com or 332-323-0287.
6.6 Non-sharing of mobile information
No mobile information (including your mobile phone number, your consent to receive text messages, or your opt-in status) will be sold, rented, leased, shared, or otherwise transferred to any third party or affiliate for that party's own marketing or promotional purposes. Mobile information is not shared with third parties for marketing purposes under any circumstances.
The only disclosures of your mobile number that we make are:
- To our communications vendor (Twilio) and the underlying wireless carriers, strictly as necessary to transmit and deliver the messages you have asked to receive. These vendors act as service providers, are contractually bound to use the information only to provide that service, and may not use it for their own purposes.
- To your Provider, as part of your patient contact record, in ORAYA's role as their Business Associate.
- As required by law, as described in Section 7.4.
Text message originator opt-in data and consent are never shared with any third party for any purpose other than delivering the message.
Safeguards designed to meet the HIPAA Security Rule.
ORAYA maintains administrative, physical, and technical safeguards, including:
- encryption of data in transit (TLS) and at rest;
- field-level encryption of especially sensitive identifiers;
- multi-factor and one-time-passcode authentication;
- role-based access controls and row-level security in our data layer;
- immutable audit logging of access to patient records;
- redaction of contact details, message bodies, and one-time codes from application logs; and
- security review, dependency scanning, and secret scanning in our development pipeline.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at info@orayasolutions.com.
9. Cookies and tracking
Our websites and web portal use cookies and similar technologies that are strictly necessary for authentication, session management, and security, plus limited first-party analytics to understand feature usage and diagnose problems.
We do not use third-party advertising cookies, and we do not permit third-party tracking on pages that display health information. We honor Global Privacy Control and similar browser-level opt-out signals where applicable law requires it. You can control cookies through your browser settings; disabling strictly necessary cookies will prevent you from signing in.
What you control, and where to exercise it.
Communication choices
- Change or remove your email address or mobile number in the MyORAYA app under account settings (changes require verification, and we notify your previous contact point).
- Reply STOP to end text messages (Section 6.5).
- Use the unsubscribe link in non-essential emails. Security and verification emails cannot be unsubscribed while your account is active, because they are required to operate the account.
- Turn off push notifications in your device's system settings, or disconnect your device in the app.
Health record rights
Your rights to access, amend, restrict, receive an accounting of disclosures of, or obtain a copy of your medical record run against your Provider under HIPAA and your Provider's Notice of Privacy Practices. Direct those requests to your Provider; ORAYA will support your Provider in fulfilling them.
State privacy rights
Depending on where you live (including California, Colorado, Connecticut, Virginia, Texas, Washington, and other states with comprehensive privacy or health-data laws), you may have rights to access, correct, delete, or port personal information we hold in our own capacity, and to appeal a denial of those rights. Information governed by HIPAA is generally exempt from these state laws, but we will honor applicable requests for the information we control. We do not discriminate against you for exercising any privacy right.
To exercise a right, contact us at info@orayasolutions.com. We will verify your identity before acting on a request and will respond within the time required by applicable law.
How long we keep information, and where it lives.
11. Data retention
We retain information for as long as needed to provide the Services and as required by our agreements with Providers and by law. Retention of medical record data is governed by your Provider's retention obligations, which commonly run seven or more years. Authentication artifacts such as one-time codes are retained only briefly. Security and HIPAA audit logs are retained for at least six years, as required by the HIPAA Security Rule. De-identified and aggregated data may be retained indefinitely.
12. Children's privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 for our own purposes. Where a Provider treats a minor patient, the minor's health information is handled under the Provider's direction and applicable law, and access is granted through the Provider to the patient or an authorized personal representative.
13. Where information is processed
The Services are operated in the United States, and information is stored and processed in U.S.-based facilities. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above. If we make material changes to how we use your information or to our messaging practices, we will provide additional notice through the Services, by email, or by other appropriate means before the change takes effect. We will not materially change our text messaging opt-in, sharing, or frequency practices without notifying you and, where required, obtaining your consent again.
Who to reach, and for what.
ORAYA Health, Inc.
- Privacy questions: info@orayasolutions.com
- General support: info@orayasolutions.com · 332-323-0287
- Security reports: info@orayasolutions.com
- Website: orayasolutions.com
For questions about your medical record, your Provider's privacy practices, or to exercise HIPAA rights, contact the clinic or provider that treats you.
Questions about your data?
Reach us at info@orayasolutions.com, or read the Terms & Conditions that go with this policy.