Skip to main content
Orvica is currently invite-only. Join the waitlist to request access.
Helix · HIPAA

Notice of Privacy Practices

Version 1.1 · Effective 2026-06-19

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Helix is a software platform operated by Orvica LLC ("Orvica," "we," "us") that assists caregivers, patients, and licensed providers in coordinating medications, refills, appointments, and care notes. When Helix is used in a manner that involves protected health information ("PHI") of an identified individual, Orvica acts as a business associate of the covered entity (provider, prescriber, or facility) that introduced you to Helix, under Business Associate Agreements ("BAAs") executed with those covered entities. This Notice describes our practices regarding PHI received in that capacity, as required by the Health Insurance Portability and Accountability Act ("HIPAA") and 45 CFR §164.520.

1. Our obligations

We are required by law to:

  • Maintain the privacy and security of your protected health information.
  • Provide you with this Notice of our legal duties and privacy practices with respect to your PHI.
  • Abide by the terms of this Notice currently in effect.
  • Notify you in the event of a breach of your unsecured PHI (45 CFR §164.404 and §164.410).

2. How we may use and disclose your PHI

We use and disclose your PHI only as permitted by HIPAA and as agreed in our BAAs with the covered entities introducing you to the platform. Specifically:

  • Treatment: facilitating provider-to-patient and caregiver-to-provider communication (e.g., refill requests, medication reconciliation).
  • Payment: generating invoices for cash-pay services rendered by a prescriber, routed through Volt or the prescriber's billing system.
  • Health-care operations: internal quality assurance, security monitoring, de-identified product analytics. We do not aggregate PHI across covered entities.
  • As required by law: response to lawful subpoena, court order, or government request, with notice to the affected covered entity when permitted.

3. Uses and disclosures that require your authorization

Beyond the above, we will obtain your written authorization before using or disclosing your PHI for any of the following:

  • Marketing purposes (we do not currently market to PHI subjects).
  • Sale of PHI (we do not sell PHI under any circumstances).
  • Disclosure of psychotherapy notes (Helix does not currently store psychotherapy notes).

You may revoke your authorization in writing at any time, except where we have already acted in reliance on it.

4. Your rights regarding PHI

Under HIPAA you have the right to:

  • Inspect and copy your PHI maintained by Helix (45 CFR §164.524). Submit a request to privacy@orvica.co; we respond within 30 days.
  • Request an amendment if you believe your PHI is inaccurate or incomplete (45 CFR §164.526).
  • Request an accounting of disclosures we have made of your PHI in the past 6 years, other than for treatment, payment, or operations (45 CFR §164.528).
  • Request restrictions on certain uses and disclosures of your PHI (45 CFR §164.522). We will accommodate reasonable requests where feasible.
  • Request confidential communications at an alternative address or phone number.
  • Choose notification channels for optional refill, appointment, and care coordination reminders where the applicable covered entity and law permit. Account-security, privacy, breach, and legally required notices may still be sent through appropriate channels.
  • Receive a paper copy of this Notice on request, even if you have agreed to receive it electronically.
  • File a complaint with Orvica (privacy@orvica.co) or with the U.S. Department of Health and Human Services Office for Civil Rights (hhs.gov/ocr). We will not retaliate against you for filing a complaint.

5. Security safeguards

We implement administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR §164.302-318), including encryption at rest (AES-256) and in transit (TLS 1.2+), role-based access control with audit logging, mandatory multi-factor authentication for staff, vendor business associate agreements where applicable, and annual security reviews. Our information security policy is publicly available at /security.

6. Communications, email, and SMS

Helix may send reminders, care-coordination notices, and account-service messages by email, SMS, in-product notification, or push notification when enabled by the applicable user or workspace. Because standard SMS and email may reveal limited contextual information, users should choose confidential communication preferences carefully. Optional SMS is governed by the Orvica SMS Terms and can be stopped by replying STOP, except for security or legally required notices.

7. AI-assisted features

Some Helix features use third-party large-language-model providers (Anthropic) for summarization, rebuttal-letter drafting, and document parsing. PHI is never sent to any LLM provider that has not countersigned a Business Associate Agreement with us. Until that BAA is in effect, AI features that would touch PHI are disabled at the platform level (controlled by the ANTHROPIC_BAA_SIGNED environment gate).

8. Changes to this Notice

We reserve the right to change the terms of this Notice. Any change will be effective for all PHI we maintain. The revised Notice will be posted on this page with a new effective date; covered entities under BAA with us will receive direct notice of material changes.

9. Contact

Privacy Officer
Orvica LLC
1655 Post Road East, Unit 2802
Westport, CT 06880
privacy@orvica.co