Who we are
Parora is a product of PARORA LLC, a Michigan company. You can reach a person here:
PARORA LLC1030 Dunleavy Drive
Highland, MI 48356
joe@parora.com
Our role
Parora provides software to healthcare practices. We do not treat patients, we do not decide what anyone owes, and we do not hold the medical record.
Under HIPAA, the practice is the covered entity and Parora is a Business Associate. We sign a Business Associate Agreement (BAA) with every practice before any patient information moves, and we handle that information only on the practice's instructions and only for the purposes the BAA allows.
If you are a patient, your practice — not Parora — controls your record. Parora is the software the practice uses to send you a link and take your payment.
What we handle on a practice's behalf
A practice exports an accounts-receivable aging report from its own practice management system and uploads it to Parora. That file contains only what is needed to tell a patient what they owe and to reach them:
- Patient name
- Contact information — mobile number and email address
- Balance information the practice supplies — amount owed, date of service, amount billed, amount insurance paid, adjustments, prior payments, and how long the balance has been outstanding
We never receive or store diagnosis codes, clinical notes, or treatment plans. Those stay in the practice's system. Parora relays the numbers the practice's system produced and never calculates a balance of its own.
Patients and payments
Patients never create an account with Parora. There is no portal, no password, and nothing to download. A patient opens a secure link that expires, sees what they owe and why, and pays.
Parora does not store card numbers or bank account numbers. Payments are processed by Stripe, and the money settles to the practice. Stripe handles the card and bank details under its own terms and privacy policy; Parora receives only the result — that a payment succeeded, is still processing, or failed, and why.
Messages we send
A text or email we send on a practice's behalf contains the practice name and a secure link. Nothing else — never a balance, never a patient name, never a date of service, never a clinical word. The financial detail lives behind the link, not in the message.
Our text message program, including how consent is obtained and how to stop messages, is described in the SMS program terms.
What we never do
- We do not sell practice information or patient information, to anyone, at any price.
- We do not use it for advertising, ad targeting, or building marketing profiles, and we do not share it with advertising networks.
- We do not use patient information for any purpose other than performing the service the practice hired us to perform.
- We do not contact patients on our own behalf, ever.
How information is secured
- Encryption. Information is encrypted in transit and encrypted at rest.
- Access controls. Every record belongs to one practice, and a user reaches it only through an explicit membership in that practice. One practice's data is never visible to another.
- Audit logging. Access to patient balance information is written to an append-only audit log — entries can be added but never edited or removed.
- Least privilege. Parora staff access patient information only when a practice asks us to look at something, or when it is necessary to keep the service running.
- Link pages. Payment links are signed, expire, are rate-limited, and can require a date of birth before any detail is shown.
No system is perfect, and we will not pretend otherwise. If a breach affecting a practice's information occurs, we notify that practice as the BAA requires.
What practices send us directly
When someone asks for a pilot, we collect what they type into the form: name, role, work email, phone number if given, and details about the practice such as its name, specialty, number of locations, software, and statement volume. We use it to reply and to prepare the pilot. We do not sell it or add it to an advertising audience.
This website sets no advertising or tracking cookies, and runs no third-party advertising scripts.
Keeping and deleting data
Patient balance information belongs to the practice. How long we keep it, and what happens to it when a practice stops using Parora, are set by the BAA with that practice. A practice can ask us to return or delete its data, and we will, except where a law requires a record — for example a payment record — to be kept for a period.
Audit log entries are the one exception to deletion: an append-only log is only useful if it cannot be rewritten.
What we claim — and what we do not
Our compliance claim is exactly one thing: Parora operates as a HIPAA Business Associate and signs a Business Associate Agreement with every practice.
We do not claim SOC 2, HITRUST, or any other certification, seal, or audit. If a page anywhere ever suggests otherwise, this page is the one that is correct.
Questions about your bill
If you are a patient and something about your balance looks wrong, contact your practice. The practice produced the number, holds the record, and is the only one who can change it. Parora cannot adjust a balance, apply a credit, or explain a charge on a practice's behalf.
The practice's phone number is on the payment page, and on the statement they sent you.
Changes to this policy
If this policy changes, the date at the top of the page changes with it. Practices with a signed BAA are notified of material changes directly, because the BAA — not this page — governs how we handle their patients' information.
Contact us
Questions about this policy, a data request, or anything else about privacy at Parora:
PARORA LLC1030 Dunleavy Drive
Highland, MI 48356
joe@parora.com