HIPAA and Security Posture
A factual description of how Orisan Sage handles protected health information, and the safeguards behind the platform.
Last updated: August 2026
Where PHI Fits — and Where It Does Not
Orisan Sage is a drug information reference. Its core function — looking up drug data, FDA label text, and interaction information for a set of medications — operates on drug identifiers, not patient records. A medication list entered without patient identifiers is not protected health information (PHI), and most Sage lookups do not require any.
Some workflows can bring PHI into scope — for example, if your organization submits queries that include patient identifiers through the API. We designed the platform so that organizations can use it without transmitting PHI, and we ask customers not to send PHI unless a Business Associate Agreement is in place with us.
Safeguards
HIPAA-eligible infrastructure
Orisan Sage runs on AWS in the us-east-1 region, selected specifically because the managed services we build on — including the AI services behind interaction analysis — are HIPAA-eligible there.
Encryption in transit and at rest
All traffic to Orisan Sage is encrypted with TLS. Data stored by the platform is encrypted at rest using AWS-managed encryption.
Authenticated access
Application access requires authentication through Amazon Cognito. Accounts are provisioned by your organization or by our team — there is no self-serve signup.
Least-privilege access controls
Internal components and personnel operate under least-privilege permissions: each service and each person gets only the access required for its function.
Business Associate Agreements
If your organization is a covered entity or business associate and your intended use of Orisan Sage would involve PHI, contact us before onboarding. We will review the workflow with you and discuss executing a Business Associate Agreement where one is required.
What We Do Not Claim
There is no such thing as a “HIPAA certification” — no government body certifies products as HIPAA compliant, and we will never describe Orisan Sage that way. HIPAA obligations attach to how an organization handles PHI, not to a product label. What we can describe, and have described above, is our posture: HIPAA-eligible infrastructure, specific technical safeguards, and BAA availability for workflows that need one. Orisan Sage informs clinical decisions; it does not make them, and it is not FDA-reviewed software.
Questions
Security or compliance questions from your privacy, security, or procurement team are welcome — reach us through the contact form and we will route them to the right people.