FAQs
What We Get Asked The Most
You have questions, we have answers! Don't see your question listed below, or want more details? Reach out and a real human who's worked in a practice (not AI) will get back to you.
HIPAA (Health Insurance Portability and Accountability Act) sets federal rules for protecting patient health information. For a software platform, compliance means putting administrative, physical, and technical safeguards in place to keep patient data secure across storage, handling, and transmission.
Yes. As a platform that handles Protected Health Information (PHI) on behalf of your practice, we are a Business Associate under HIPAA. We sign BAAs with every customer.
All patient data transmitted through the Arrellio platform is encrypted in transit and at rest.
SOC 2 Type II is an independent audit that verifies not only if a company's security and operational controls are designed correctly, but if they are actually working and maintained over an extended period of time. It's a significantly higher bar than SOC 2 Type I, which only verifies controls exist at a single point in time.
SOC 2 Type II audits cover a defined period (typically 12 months) and are renewed annually. Arrellio maintains continuous compliance and undergoes regular re-audits to ensure our certification stays current.
ISO 27001 is the international standard for Information Security Management Systems (ISMS). It requires organizations to systematically identify security risks and implement controls to manage them - and to continuously improve those controls over time. It's one of the most rigorous and globally recognized certifications a software company can hold.
Yes. As of the publication of this page, Arrellio is the only optometry software platform holding an ISO 27001 certification.
ISO 27001 certification includes annual surveillance audits and a full recertification audit every three years. Arrellio maintains continuous compliance between audits through its internal Information Security Management System.

