OptioSurgical is built for the data sensitivity of healthcare environments. We treat customer data — implant records, charge sheets, contract pricing, vendor relationships — with the care those workflows demand.

HIPAA

OptioSurgical operates in alignment with HIPAA’s security and privacy rules. We sign Business Associate Agreements (BAAs) with covered entity customers prior to handling protected health information.

BAA available on request — contact sales@optiosurgical.com.

SOC 2

[Update with current posture: SOC 2 Type 1 / Type 2 status, audit firm, completion date or roadmap.]

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database backups are encrypted with the same standard.

Access controls

  • Role-based access controls (RBAC) — facility administrators, managers, vendor reps, and read-only auditor roles.
  • Single sign-on (SSO) supported for enterprise customers.
  • Multi-factor authentication required for administrator accounts.
  • Vendor rep access is scoped to the facility or facilities they’re assigned to.

Audit logs

Every record creation, modification, and access is logged. Logs are retained per customer agreement and are available to facility administrators on request.

Data retention

Customer data is retained for the duration of the active subscription plus a transition window for return or migration. On request, customer data can be exported in standard formats.

Vendor and sub-processor management

[List hosting provider (AWS / Azure / GCP) and any sub-processors handling customer data, with their role and security certifications.]

Integration security

Integrations with EHR/MMIS systems (including Envi) use authenticated, encrypted connections. We support VPN, IP allowlisting, mutual TLS, and OAuth 2.0. Integration credentials are never stored in plaintext.

Reporting a security issue

Email security@optiosurgical.com. We respond to security reports within one business day.

Schedule a security review

Procurement and IT teams: we are happy to walk through architecture, controls, and our compliance posture. Schedule a security call →