Skip to content
RxHello Logo RxHello
Menu

Privacy Policy

Last Updated: October 1, 2023

1. Information We Collect

We collect information required to operate the RxHello platform securely. This includes:

  • Pharmacy Data: Account information, integration credentials, and billing details.
  • Patient Data (PHI): We process patient names, phone numbers, date of birth, and medication history strictly as directed by the Pharmacy Management System (PMS) and governed by the Business Associate Agreement (BAA).

2. How We Use Information

We use the collected information solely to provide the contracted services:

  • To authenticate patients via SMS 2FA.
  • To query the PMS for refill status or adherence data.
  • To route clinical questions to the appropriate pharmacist queue.

We do not sell data. We do not use PHI to train third-party foundation LLM models.

3. Data Retention

RxHello operates primarily on a stateless architecture regarding PHI. We query the PMS live. Chat transcripts are retained temporarily based on the pharmacy's configured retention policy (typically 30 days) to allow for continuity of care and auditing, after which they are permanently purged from our systems.

4. Security Measures

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Access to production environments is strictly limited to authorized personnel and requires multi-factor authentication and VPN access.