Skip to content
RxHello Logo RxHello
Menu

Security is not a feature.
It is the foundation.

As a Business Associate, we treat your Patient Health Information (PHI) with the same strict governance as your internal staff. No compromises.

Business Associate Agreement (BAA)

Before a single byte of data is transmitted, RxHello executes a comprehensive Business Associate Agreement with your pharmacy. This legally binds us to the HIPAA Security and Privacy Rules. We do not offer a non-BAA tier.

Request a sample BAA

Encryption Standards

  • In Transit: TLS 1.3 encryption for all data moving between your PMS and our servers.
  • At Rest: AES-256 encryption for any temporarily cached patient data on AWS KMS-managed keys.

Stateless Architecture

  • We query your PMS live. We do not maintain a secondary, shadow database of your patient records.
  • Chat transcripts are retained per your custom retention policy (e.g., 30 days) and then permanently purged.

The "AI Hallucination" Safeguards

Using Large Language Models (LLMs) in healthcare requires strict boundaries. RxHello utilizes a gated architecture to prevent clinical hallucinations.

1

Deterministic Intent Routing

Before generating a response, the user's input is classified. If it matches a clinical intent (e.g., "dosage", "side effect", "interaction"), the LLM is bypassed entirely and a standard escalation script is triggered.

2

Zero-Knowledge LLM Prompts

When the LLM is used for conversational pleasantries, it is not fed PHI unless strictly necessary for a specific, safe task (like confirming a refill name). Patient names are often anonymized into tokens prior to processing.

3

No 3rd Party Model Training

We utilize enterprise API endpoints with zero-data-retention agreements. Your patient data and chat logs are never used to train underlying models by OpenAI, Anthropic, or Google.