What HIPAA-aligned means here
“HIPAA-aligned” describes the direction and controls used in development. It should not be read as a blanket certification of every environment, person, workflow, vendor, or future feature. HIPAA compliance depends on how the complete system is designed, configured, operated, documented, and monitored.
The OpenAI Business Associate Agreement
PBRx uses eligible OpenAI API services under an executed Business Associate Agreement (BAA), with approved data-retention controls, to support HIPAA-compliant processing of protected health information.
A BAA defines responsibilities for permitted handling of protected health information between covered entities or business associates and a service provider. It is an important contractual safeguard, but it does not make an entire product compliant by itself.
Controls beyond the BAA
- Use only eligible services and approved configurations for protected health information
- Apply access, authentication, encryption, logging, and retention controls
- Limit information to authorized purposes and users
- Maintain policies, training, risk analysis, incident response, and vendor oversight
- Separate public informational systems from authenticated health-data systems
- Validate each production workflow before protected information is accepted
PBRx.Vet is currently a static public website for general information. Do not send or upload VA records, medical documents, or personal health information here.
Current status
PBRx remains a controlled functional prototype in closed beta. Production claims and notices will be updated as validation, deployment scope, and operating responsibilities are finalized.