Responsible health information support

Security begins with clear boundaries.

PBRx.Vet is being developed around data minimization, Veteran control, source traceability, access controls, and careful separation between the public website and protected health-information systems.

Updated September 7, 2026Prototype disclosure
This public website does not accept health records

Do not submit VA records, medical documents, personal health details, or other sensitive information through this static website.

Security principles for the intended platform

Data minimization

Collect and retain only information required for an authorized purpose, with defined handling and retention controls.

Identity and access controls

Use authenticated, authorized access with protections appropriate to patient-controlled health information.

Encryption and secure transport

Use encrypted connections and protected storage within the production architecture.

Source traceability

Keep generated explanations and summaries connected to the records and dates that support them.

Auditability and incident readiness

Maintain operational visibility, logging, response procedures, and review processes appropriate to the deployed service.

Vendor controls

Limit protected-health-information processing to eligible services covered by appropriate contractual and data-handling controls.

Current development status

The platform remains in controlled validation and security hardening. This page describes design principles and current public-site boundaries; it is not a certification, audit report, or guarantee that every future feature has completed production review.

OpenAI services

PBRx uses eligible OpenAI API services under an executed Business Associate Agreement with approved data-retention controls for authorized HIPAA-compliant processing. Only eligible services and approved configurations should be used for protected health information.