HIPAA & health-data safeguards
Does HIPAA apply to Pharmacy360?
Currently, no — and we would rather say so than imply otherwise. HIPAA applies to health care providers who transmit health information electronically in connection with specific standard insurance transactions, such as claims, eligibility checks, and coordination of benefits. Pharmacy360 does not bill insurance; our services are paid directly by you, by card. That places us outside HIPAA's definition of a covered entity.
If we ever begin billing insurance, HIPAA will apply to us, and we will update this page and our privacy policy before that change takes effect.
Which laws protect you instead
Your health information is protected by the Federal Trade Commission Act, the FTC Health Breach Notification Rule, and state consumer-health-privacy laws — including Washington's My Health My Data Act, Nevada SB 370, and Connecticut's consumer health data provisions. Several of these give you rights over your data directly; how to exercise them is set out in our privacy policy.
The safeguards we apply regardless
We hold ourselves to HIPAA-grade administrative, physical, and technical safeguards whether or not the statute compels it:
- Health information is encrypted at rest using AES-256-GCM with a dedicated key, and in transit using TLS.
- Free text is automatically redacted of direct identifiers before it is sent to any external AI model.
- Health information is kept out of our logs, enforced by an automated test that fails our build if it regresses.
- Data is segregated by organisation at the database level, staff access is role-based, and sensitive administrative actions require a second factor.
- Backups are encrypted, and card details never reach our systems — payments are handled directly by Stripe.
No system is perfectly secure, and we do not claim otherwise.
Questions
For details of our safeguards, or to exercise a right over your data, contact us.