For healthcare & telehealth

Encrypted video for care teams that handle protected health information

Telehealth visits, multidisciplinary case reviews and referrals — encrypted, and deployable inside your own environment so protected health information (PHI) stays within the controls you already run.

The problem

Why the usual tools don’t fit

PHI on someone else’s cloud

Consumer video tools put patient conversations and shared records on infrastructure you can’t inspect or bound to a jurisdiction.

Consent & records obligations

Clinical conversations and shared documents may need to stay auditable, access-controlled and retained under your policies — not a vendor’s defaults.

Cross-provider collaboration leaks

Case reviews and referrals across organisations are exactly where sensitive records get forwarded into unmanaged inboxes and chats.

How Ollasync helps

Confidentiality that fits your workflow

Encrypted telehealth visits

Browser-based video with no app install for patients, encrypted in transit over a media relay you can self-host.

Case rooms for records

Per-case document rooms with role and NDA gating, in-browser viewing and per-viewer watermarks for referrals and MDT reviews.

Server-blind messaging

End-to-end encrypted clinical messaging (IETF MLS / RFC 9420) — we hold no keys and can’t read the content.

PHI stays in your walls

Self-host and every byte of media, recording and document stays on infrastructure you operate and audit.

In practice

A multidisciplinary team review, contained

A hospital stands up Ollasync on-premise. Oncology, radiology and an external specialist join an encrypted case review; imaging and notes live in a role-gated case room that never leaves the hospital network. Nothing syncs to an external cloud, and the whole session is auditable.

Compliance posture

Where a HIPAA or GDPR programme fits

We give you controls, not a badge we don’t hold — and self-hosting keeps regulated data inside your own boundary.

Full compliance posture
  • We don’t sell you a certificate — we give you the technical controls a HIPAA or GDPR-health programme requires: encryption, access control, audit logging and a DPA.
  • Self-host and PHI never leaves your certified environment, so the software sits inside your existing compliance boundary rather than adding a subprocessor.
  • A data-processing agreement covering residency, retention and breach notification is available for our hosted service.
  • We hold no SOC 2 / ISO 27001 / HDS certification yet, and we tell you so — see the security page.
FAQ

Healthcare — common questions

Is Ollasync HIPAA compliant?

Compliance is a property of your deployment. Ollasync provides the encryption, access control, audit logging and DPA a HIPAA programme needs, and self-hosting keeps PHI inside your own audited environment. We do not currently hold a formal certification and we say so plainly.

Can patients join without installing anything?

Yes. Patients join encrypted telehealth visits from any modern browser — no download, no account required for guests who are invited to a room.

Where is patient data stored?

On our EU-hosted service, in the EU (Frankfurt). If you self-host, patient data stays entirely on your infrastructure, in the jurisdiction and network you choose — including fully air-gapped.

Bring healthcare conversations in-house.

See it on your own infrastructure. Tell us your environment and requirements, and we’ll size a proof of concept with you.

Book a demo See self-hosting