Security & HIPAA

Your health data is
treated like health data.

HIPAA compliance, end-to-end encryption, signed Business Associate Agreements, audit logging, and a strict no-selling policy. Not because we have to — because patients deserve it.

Our compliance posture

The foundational commitments that govern how we collect, store, transmit, and protect protected health information (PHI).

H

HIPAA-Regulated Platform

PrescriberNow operates as a HIPAA Business Associate to the clinical practices on the platform. Our privacy and security practices are governed by the HIPAA Privacy and Security Rules and our Business Associate Agreements.

BAA

Signed BAAs

We execute Business Associate Agreements with every vendor or service that processes, stores, or transmits protected health information on our behalf.

Encryption Standard

All PHI is encrypted in transit using TLS 1.3 and at rest using AES-256. No unencrypted storage of health data, ever.

Technical safeguards

The HIPAA Security Rule requires covered entities to implement technical safeguards for electronic PHI. Here is how we meet each category.

Encryption in Transit

All connections between your browser and PrescriberNow servers use TLS 1.3, the current industry standard. HTTP connections are automatically upgraded to HTTPS. HSTS headers are enforced. Certificates are rotated and monitored.

Encryption at Rest

All stored PHI — intake forms, visit records, provider notes, prescription data — is encrypted at rest using AES-256. Encryption keys are managed separately from data storage. Database backups are encrypted before leaving the primary environment.

Audit Logging

Every access, read, write, and deletion event touching PHI is logged with a timestamp, user identity, and action type. Logs are retained for a minimum of six years per HIPAA requirements and are available for review in the event of a compliance audit or security investigation.

Two-Factor Authentication

All staff, provider, and administrative accounts require two-factor authentication. Single-factor login is not available for roles with PHI access. Patient accounts are offered 2FA during sign-up and prompted at suspicious login events.

Role-Based Access Controls

PHI access is limited by role. A billing staff member cannot read clinical notes. A provider cannot access intake forms for patients outside their assigned visits. Access grants are reviewed quarterly and revoked immediately upon role change or departure.

Data Minimization

We collect only the minimum PHI necessary to provide care. We do not collect demographic data for advertising profiles, we do not build behavioral data sets, and we do not retain PHI beyond the minimum HIPAA-required retention period unless required by state law.

Our commitments to you

These are not terms-of-service fine print. They are operational policies with internal accountability.

We do not sell your data. Ever.

Your name, diagnosis, medications, and visit history are never sold to advertisers, data brokers, pharmaceutical companies, insurance carriers, or any other third party. Visit fees pay our bills. That is the only revenue model.

BAAs with every PHI-handling vendor

We maintain signed, current Business Associate Agreements with Google Workspace, our cloud infrastructure provider, our e-prescribing vendor, and every other service that has access to PHI. No vendor exception.

No third-party tracking pixels on clinical pages

Marketing analytics tools (if any) are scoped only to public marketing pages. No tracking pixels, session recorders, or advertising SDKs are loaded on intake forms, visit summaries, or any page where PHI is displayed or submitted.

HIPAA-compliant e-prescribing

Prescriptions are transmitted electronically using SureScripts-compatible e-prescribing channels, which maintain their own HIPAA compliance certifications. We do not fax or email prescriptions in plain text.

Staff training and access reviews

All staff with PHI access complete HIPAA training at onboarding and annually. Access levels are reviewed quarterly. Departing team members have credentials revoked within one business day.

Breach response

What happens if something goes wrong

We maintain a written incident-response and breach-notification plan that meets or exceeds HIPAA Breach Notification Rule requirements. In the event of a breach involving unsecured PHI:

Affected individuals are notified without unreasonable delay, and no later than 60 days after discovery. The U.S. Department of Health and Human Services is notified per regulatory requirements. If the breach affects 500 or more individuals in a single state, the relevant media are also notified.

Our response timeline is as follows:

Day 1 Incident detected & contained
Day 3 Risk assessment complete
Day 14 Affected patients notified
Day 60 HHS notification deadline

Your rights

Under HIPAA, you have the right to access and receive a copy of your protected health information, request corrections to inaccurate or incomplete records, request restrictions on certain uses and disclosures, receive an accounting of disclosures, and file a complaint with the U.S. Department of Health and Human Services if you believe your rights have been violated.

To exercise any of these rights, email team@prescribernow.com with the subject line "HIPAA Rights Request." We will respond within 30 days. For more detail, see our Privacy Policy and your Patient Rights notice.

Start a HIPAA-secure visit today.

Your intake is encrypted end-to-end, reviewed by a licensed provider, and your data is never sold. Board-certified care, licensed in your state.

Start your visit