Built to pass the audit.
We handle PHI the way pharmacists do: carefully, and only where it has to exist. Every deployment is HIPAA-compliant from day one, and every action an agent takes is logged and replayable.
Controlled scripts are never auto-committed; each is staged for pharmacist sign-off.
Least privilege, logged end to end.
BAA on every deployment
A Business Associate Agreement is signed before any PHI is touched.
PHI tokenized before inference
Protected health information is tokenized inside your network before it reaches a model; voice transcripts are scrubbed first.
Encrypted in transit and at rest
Standard encryption everywhere your data moves or sits.
Role-based access
Nothing is exposed by default; access is scoped by role.
Least-privilege fields
An agent sees only the fields a given task needs, no more.
Audit log on every write
Every agent decision and write is logged and replayable, so you can show the board exactly what happened.
Security, answered.
Is PillPilot HIPAA-compliant?
Yes. Every deployment is HIPAA-compliant from day one, with a signed BAA, audit logging on every write to your pharmacy system, and encryption in transit and at rest.
Do you sign a Business Associate Agreement?
Yes. A BAA is signed on every deployment, before any PHI is touched.
How is PHI handled with AI models?
PHI is tokenized inside the pharmacy network before model inference, and voice transcripts are scrubbed before they reach a model. The agent sees only the fields a given task needs; nothing is exposed by default.
Can we review your security documentation?
Yes. Security documentation is available on request; get in touch and we'll walk your team through it.
Security your board can sign off on.
Book a call and we'll walk your team through how PillPilot handles PHI.