HIPAA & Business Associate Agreement
Effective 18 August 2026
A pharmacy is a covered entity. When RxChange processes protected health information on your behalf, we are a Business Associate. This page sets out what that means here in practice.
How little PHI is involved
Almost nothing RxChange handles is PHI. Inventory records describe stock — NDC, drug name, quantity, cost — and identify no patient.
There is exactly one field that can contain PHI: the optional patient name on a Tag for Transfer request, recorded when a transfer is made to fill a specific prescription. That is the whole PHI surface, and the design keeps it that way deliberately.
What happens to that field
- Encrypted before storage with AES-256-GCM. The key lives outside the database, is delivered to the application by file rather than environment variable, and is deliberately excluded from backups — so a stolen backup does not yield patient names.
- Never sent by email. The notification to the holding pharmacy carries drug, strength, and quantity so a technician can pull the stock, then says a patient name was recorded and to sign in to see it. This is also what keeps our email provider outside the scope of PHI processing.
- Every view is logged. Decrypting and displaying the name writes an audit entry naming the user, the transfer, and the time.
- Never in application logs. The logger redacts patient fields.
- Optional. Leave it blank and no PHI enters the system at all.
Before you enter PHI
A Business Associate Agreement must be signed first. Request one at [email protected]. Where the BAA and our Terms of Service conflict, the BAA governs.
Safeguards
Administrative, physical, and technical safeguards in place include:
- Unique named accounts with mandatory multi-factor authentication; no shared logins.
- Role-based access, with store staff restricted to a single pharmacy.
- Automatic session expiry after inactivity, and immediate revocation when an account is disabled.
- Encryption in transit and at rest for PHI.
- An append-only audit log the application cannot rewrite at runtime.
- Tenant isolation enforced independently by the database, so one pharmacy group cannot reach another’s records.
- Encrypted, restore-tested off-site backups.
Subprocessors
Our subprocessors are listed in the Privacy Policy. Because patient names are excluded from email and excluded from backup encryption keys, the subprocessor with access to decrypted PHI is none in ordinary operation. We will give notice before engaging any subprocessor that would change that.
Breach notification
We will report any use or disclosure not permitted by the BAA, and any security incident or breach of unsecured PHI, without unreasonable delay and within the timeframes the BAA and the HIPAA Breach Notification Rule require.
Patient requests
Patients should contact their pharmacy. As a Business Associate we do not respond directly to individuals, but we will help the covered entity meet access, amendment, accounting, and restriction obligations.
Return or destruction
On termination we return or destroy PHI as the BAA directs. Where destruction is infeasible for data held in encrypted backups, protections continue until those backups age out.
Contact
4TressCyber LLC
8633 S Sandy Pkwy, Sandy, UT 84070
[email protected]