Security & compliance

Built to pass the audit.

We handle PHI the way pharmacists do: carefully, and only where it has to exist. Every deployment is HIPAA-compliant from day one, and every action an agent takes is logged and replayable.

How we handle your data

Least privilege, logged end to end.

BAA

BAA on every deployment

A Business Associate Agreement is signed before any PHI is touched.

PHI

PHI tokenized before inference

Protected health information is tokenized inside your network before it reaches a model; voice transcripts are scrubbed first.

KEY

Encrypted in transit and at rest

Standard encryption everywhere your data moves or sits.

ACL

Role-based access

Nothing is exposed by default; access is scoped by role.

EYE

Least-privilege fields

An agent sees only the fields a given task needs, no more.

LOG

Audit log on every write

Every agent decision and write is logged and replayable, so you can show the board exactly what happened.

FAQ

Security, answered.

Is PillPilot HIPAA-compliant?

Yes. Every deployment is HIPAA-compliant from day one, with a signed BAA, audit logging on every write to your pharmacy system, and encryption in transit and at rest.

Do you sign a Business Associate Agreement?

Yes. A BAA is signed on every deployment, before any PHI is touched.

How is PHI handled with AI models?

PHI is tokenized inside the pharmacy network before model inference, and voice transcripts are scrubbed before they reach a model. The agent sees only the fields a given task needs; nothing is exposed by default.

Can we review your security documentation?

Yes. Security documentation is available on request; get in touch and we'll walk your team through it.

Book a 20-minute call

Security your board can sign off on.

Book a call and we'll walk your team through how PillPilot handles PHI.