Do not submit VA records, medical documents, personal health details, or other sensitive information through this static website.
Security principles for the intended platform
Data minimization
Collect and retain only information required for an authorized purpose, with defined handling and retention controls.
Identity and access controls
Use authenticated, authorized access with protections appropriate to patient-controlled health information.
Encryption and secure transport
Use encrypted connections and protected storage within the production architecture.
Source traceability
Keep generated explanations and summaries connected to the records and dates that support them.
Auditability and incident readiness
Maintain operational visibility, logging, response procedures, and review processes appropriate to the deployed service.
Vendor controls
Limit protected-health-information processing to eligible services covered by appropriate contractual and data-handling controls.
Current development status
The platform remains in controlled validation and security hardening. This page describes design principles and current public-site boundaries; it is not a certification, audit report, or guarantee that every future feature has completed production review.
OpenAI services
PBRx uses eligible OpenAI API services under an executed Business Associate Agreement with approved data-retention controls for authorized HIPAA-compliant processing. Only eligible services and approved configurations should be used for protected health information.