HIPAA
What "HIPAA-aligned" means for PepProto, stated plainly — including what is not done yet.
Alignment, configured per deployment
The architecture is built for HIPAA-aligned deployment. Compliance is a property of a deployment, not of software, so it is configured per clinic and covered by a Business Associate Agreement executed before protected health information is entered.
Controls in place
Role-based access across the six platform roles; database row-level security isolating every clinic and restricting patients to their own record; encryption in transit and at rest; documents held in private storage behind signed URLs; an audit log of privileged actions; immutable, versioned treatment-plan history; and recorded provider approval on anything patient-facing.
AI and PHI
AI is used to draft, never to decide. Drafts are generated from clinical data on request, are labeled as drafts everywhere they appear, and reach a patient only after a licensed provider reviews, edits and approves them. No clinical content is used to train a model provider’s systems.
Not claimed
PepProto is not certified or “HIPAA compliant” as a product, and it is not an EMR. Field-level encryption of the most sensitive PHI, SSO, and formal third-party audit are on the roadmap rather than shipped. Ask before assuming a control exists — hello@pepproto.com.
Not an EMR · AI requires provider review