Security and compliance

Built to support your DEA and HIPAA program. Not to replace it.

Records are append-only where the regulations require it. Corrections are made by documented reversal, never deletion. Every submission attempt is logged and auditable. This page lists the safeguards behind that.

Safeguards

How clinic and patient information is protected.

Encrypted in transit and at rest

Every connection and every stored record.

Per-clinic isolation

Row-level separation between practices. One clinic can never see another's data.

Role-based access

Staff see what their role needs. Admin records and the audit log stay with admins.

Multi-factor sign-in

A second factor protects every staff account.

Audit logging

Access to and changes within clinical records are logged, and the log is append-only.

Least-privilege support

Our own personnel get access only as needed to provide support, and that access is logged too.

Ongoing monitoring

Continuous monitoring and periodic review of the security configuration.

Retention that matches the rules

Records are kept for the periods controlled-substance and REMS regulations require, and exportable at any time.

HIPAA

A Business Associate Agreement with every clinic, and with every vendor behind us.

ComplyRx operates a HIPAA compliance program with a documented risk analysis, written policies, staff training, and an incident response plan. Every service provider that handles protected health information on our behalf is under a BAA. The current list of sub-processors is published in our Privacy Policy.

DEA recordkeeping

Records built for inspection.

Controlled-substance records are append-only. A mistake is corrected with a documented reversal that leaves the original entry in place, so the record always shows what happened and what was corrected. Receipts, dispensing, physical counts, and dispositions are exportable on demand.

Use of AI

Assistance, reviewed by your staff, never trained on your data.

Some features use an AI model to help read uploaded documents or answer questions about a clinic's own data. Those requests go to a vetted provider under a BAA and under terms that prohibit using the content to train its models. Any suggestion is shown to staff for review before anything is saved. ComplyRx does not make unreviewed clinical decisions.

If something goes wrong

Incidents are handled under a written plan.

If we become aware of a security incident affecting protected health information, affected clinics are notified in accordance with HIPAA and our Business Associate Agreement. To report a security concern, write to vmathews@complyrx.ai.

What we never do

Your data is yours.

We never sell, rent, or share clinic or patient information with third parties for their own purposes.

We never use your data to train AI models, and neither may any provider we use.

We never let one clinic's information reach another clinic.

We never hold your records hostage. Export is available to you at any time.