Industries · Healthcare (OrenHealth)
OrenHealth is OrenGen Worldwide's healthcare practice. We build AI systems, software and automation for the administrative work of hospitals, health systems and specialty clinics, and we decide where protected health information (PHI) is processed before we decide which tools to use.
Cloud
Self-Hosted
Hybrid
Governed
Care operations
Each runs on phones, faxes, portals and spreadsheets that were never designed to work together. In each one, AI can prepare, sort and route while staff keep the decisions.
Scheduling, rescheduling and directions calls queue up at peak hours. Consent-based voice and chat assistants can answer routine requests, book within your rules and hand everything else to staff.
Referrals arrive by fax, portal and email, often incomplete. Document extraction can read each packet, flag what is missing and route it to the right queue for review.
Prior-authorization status checks, eligibility follow-ups and denial work lists take staff hours. Automation can track status, prepare follow-ups and surface the items a person must act on.
Policies, payer rules and procedures live in dozens of documents. A retrieval assistant can answer from the approved versions and show the passage it used.
Governed architecture
Where PHI is stored and processed determines which services may touch it, which agreements must be in place and who operates the system. We settle that per workload with your privacy and security teams, at the start. We design so your data, models and workflows stay under your control, wherever they run.
Deployment model
Where PHI would be processed: in cloud services under your organization's account and configuration.
Fits when: the workload needs managed services or elastic capacity, and every service in the data path is covered by the agreements your compliance team requires.
Deployment model
Where PHI is processed: on infrastructure your organization controls. Models and retrieval run inside that boundary, so PHI does not leave it for AI processing.
Fits when: PHI must stay inside your environment, and your team or a managed operator can run the stack.
Deployment model
Where PHI would be processed: steps that touch PHI stay self-hosted; steps that use no patient identifiers can call cloud services.
Fits when: some tasks need cloud-scale models, and the line between identified and non-identified data can be enforced by the system and logged.
We don't attach HIPAA compliance labels to our services. Your privacy officer and counsel decide whether a design meets your obligations; we give them the detail to decide.
Minimum necessary. Each assistant and workflow reads only the fields its task requires; staff access follows your roles.
Encryption. Data encrypted in transit and at rest, in the environment the deployment model names.
Audit trail. A record of what the system read, what it produced and which person approved it.
Human review. Staff approve outputs before they reach a patient, a payer or the record.
Retention. Retention for prompts, outputs and logs can be set to your organization's schedule.
Consent. Patient calls and texts go only to people who have opted in. No cold outreach.
Solution stack
Each capability has its own page. For healthcare work we combine them into one governed system.
Assistants for intake, document extraction and staff knowledge. We build custom self-hosted AI environments (LLM and RAG); cloud services your organization approves are a design option. Works with leading commercial and open-source AI models.
AI Systems →Workflows that move referrals, authorizations and requests between your EHR, practice management system, fax and portals through the interfaces they provide. No rip-and-replace.
Automation & Integration →Staff portals, work queues and operational dashboards built around your records and access rules. Operational reporting only, never clinical decision support.
Software & Applications →Cloud, self-hosted or hybrid, chosen per workload by where PHI must be processed, who operates the system and what it costs to run.
Infrastructure →Access control, audit trails, human review points and AI-use policy, designed into the first release rather than added after a finding.
Governance & Security →Buy-Lingual™ AI Voice and AI Employees for consent-based patient communication: inbound calls and chats, booking and reminders for patients who have opted in.
OrenAgents →Choose your setting
Each setting buys, integrates and staffs differently. Each page explains what applies to you.
Hospitals and multi-facility health systems: access centers, referral and authorization paperwork, and staff knowledge, alongside the systems of record you already run.
Hospitals →Independent and multi-location specialty practices: front desk, recall, intake and follow-up around your practice management system.
Specialty Clinics →Revenue-cycle, patient-access and back-office teams in any setting, and the administrative workflows they run every day.
Healthcare Operations →Administrative and operational support for research and life sciences teams, with our limits stated up front.
Life Sciences →Scenarios
These are illustrative scenarios that show the kind of work we scope. They are not client engagements.
Illustrative scenario
A clinic group's phones go to voicemail after hours. A consent-based voice assistant answers, books or reschedules within the group's rules, and hands any clinical question to the on-call process the group already uses, with a transcript for staff.
Illustrative scenario
A hospital department receives referrals by fax. Extraction reads each packet, checks it against the department's required-document list and puts incomplete ones in a staff queue with the missing items named.
Illustrative scenario
Access-center staff search long payer and policy documents during calls. A self-hosted retrieval assistant answers from the approved documents and cites the passage, so staff can check it before they respond.
What we do and don't do
Our healthcare work focuses on healthcare administration. We do not provide clinical decision support, diagnosis or treatment guidance, we are not a contract research organization, and we do not replace validated clinical systems of record.
In practice: patient access, intake and referrals, revenue-cycle paperwork, staff knowledge and operational reporting.
OrenGen does not currently hold CMMC, FedRAMP, DoD Impact Level, CJIS or HITRUST authorizations, is not a 21 CFR Part 11-validated system, and does not maintain corporate personnel security clearances.
Framework status is shown on Compliance.
Compliance officer FAQ
What does your healthcare practice, OrenHealth, work on?
Our healthcare work focuses on healthcare administration. We do not provide clinical decision support, diagnosis or treatment guidance, we are not a contract research organization, and we do not replace validated clinical systems of record. In practice that means patient access, intake and referrals, revenue-cycle paperwork, staff knowledge and operational reporting.
How do you handle HIPAA?
We don't attach HIPAA compliance labels to our services. We describe the controls a design includes (minimum necessary access, encryption in transit and at rest, audit trails, human review and retention settings) so your privacy and security officers can assess them against your obligations. That determination stays with your organization and its counsel.
Will you sign a Business Associate Agreement?
Raise it at the start of your briefing. The agreements your compliance team requires should be in place in writing before any PHI is shared with us.
Where does PHI go in a deployment?
That depends on the deployment model, which is agreed with you first. Self-hosted: models and retrieval run on infrastructure your organization controls, so PHI stays inside that environment for AI processing. Cloud, as a design option: PHI would be processed in services under your organization's cloud account, and the design can list each service in the data path for your review. Hybrid, as a design option: steps that touch PHI stay self-hosted, and only steps without patient identifiers use cloud services.
Do you hold HITRUST or other security authorizations?
OrenGen does not currently hold CMMC, FedRAMP, DoD Impact Level, CJIS or HITRUST authorizations, is not a 21 CFR Part 11-validated system, and does not maintain corporate personnel security clearances. If your procurement treats one as a hard requirement, tell us at the briefing so expectations are clear from the start.
Will this replace our EHR?
No. We work around the systems of record you already run, through the interfaces your vendors provide, and we do not replace validated clinical systems of record. Which platforms and interfaces apply is agreed during scoping.
How do patient calls and texts work?
Only with consent. Voice and messaging features are built for opt-in communication with patients who have agreed to be contacted, for administrative purposes such as scheduling and reminders. We do not build cold calling or cold texting, and clinical questions go to your staff.
Who will we work with?
Our founder, Andre Mandel, personally leads sales, solution architecture and client delivery. Delivery is supported by a distributed team of contractors engaged per project. We deliver our services remotely, nationwide.
Can we see a demo?
We don't run demonstrations that involve PHI. In a Mission Brief we walk through the architecture for your workflow instead: where its data lives, which steps AI takes on and where staff review.
Mission Brief · Healthcare
We map where its data lives, which steps AI can take on, where staff review, and which deployment model keeps PHI where your policies require.