HIPAA

What "HIPAA-aligned" means for PepProto, stated plainly — including what is not done yet.

Summary, not a contract. This page describes how PepProto is built. It is not a counsel-reviewed policy and does not replace the agreements a clinic signs before deployment — including a Business Associate Agreement. For the executed documents, contact hello@pepproto.com.

Alignment, configured per deployment

The architecture is built for HIPAA-aligned deployment. Compliance is a property of a deployment, not of software, so it is configured per clinic and covered by a Business Associate Agreement executed before protected health information is entered.

Controls in place

Role-based access across the six platform roles; database row-level security isolating every clinic and restricting patients to their own record; encryption in transit and at rest; documents held in private storage behind signed URLs; an audit log of privileged actions; immutable, versioned treatment-plan history; and recorded provider approval on anything patient-facing.

AI and PHI

AI is used to draft, never to decide. Drafts are generated from clinical data on request, are labeled as drafts everywhere they appear, and reach a patient only after a licensed provider reviews, edits and approves them. No clinical content is used to train a model provider’s systems.

Not claimed

PepProto is not certified or “HIPAA compliant” as a product, and it is not an EMR. Field-level encryption of the most sensitive PHI, SSO, and formal third-party audit are on the roadmap rather than shipped. Ask before assuming a control exists — hello@pepproto.com.

Not an EMR · AI requires provider review