Skip to content
RxChange
How it works Keeping it safe What it costs
Sign in

Privacy Policy

Effective 18 August 2026

This policy explains what RxChange collects, why, who it is shared with, and how long it is kept. It describes the software as actually built, not as a category.

Our role

For information about your staff — names, work email addresses, sign-in records — we act as a controller. For information you enter about your pharmacy operations and your patients, we act as a processor, and under HIPAA as a Business Associate, acting on your documented instructions. See HIPAA & BAA.

What we collect

Account information

Name, work email address, assigned role, assigned pharmacy, a hash of your password (never the password itself), your registered passkeys and authenticator secret, and hashed single-use recovery codes.

Inventory information

Everything contained in the unused-inventory report your pharmacy system exports: NDC, drug name, strength, dosage form, DEA schedule, quantity on hand, last cost paid, and any lot, expiry, or last-dispensed information the report includes. Columns we do not recognise are kept as-is and shown on the item page rather than discarded.

This information concerns stock. It does not identify a patient.

Transfer records

The medication, quantity, date, reason, the pharmacies involved, the requesting user, the supervising pharmacist or employee, and any DEA Form 222 or CSOS number.

A patient name may optionally be recorded. That field is protected health information. It is encrypted before it is stored, it is never included in any email we send, and every occasion on which it is decrypted and displayed is written to the audit log.

Security and audit records

Sign-in successes and failures, multi-factor challenges, imports, transfers, exports, administrative changes, and PHI access. Records include the acting user, a timestamp, and the network address of the request.

Failed sign-in attempts are recorded against a keyed hash of the email address rather than the address itself, so the throttling records cannot be mined for a list of valid accounts.

Technical logs

Request method, path, response status, duration, and network address. Logs are configured to redact credentials, tokens, and patient fields.

Cookies

RxChange sets only strictly necessary cookies. There are no analytics, advertising, or tracking cookies, and no consent banner because there is nothing to consent to.

CookiePurposeLifetime
__Host-rxc_sid Keeps you signed in. An opaque random value; only its hash is stored server-side. Up to 12 hours, and 30 minutes of inactivity
__Host-rxc_csrf Protects forms against cross-site request forgery. Session
rxc_flash Carries a one-off confirmation message across a redirect. 60 seconds

No third-party tracking

There is no analytics platform, no advertising pixel, no session recording, and no social media widget. Web fonts are served from our own domain rather than a font CDN, so no outside party receives a request when your staff open a page.

Who we share it with

We do not sell personal information or PHI, and we do not use it to train models.

We use these subprocessors:

ProviderWhat forWhat reaches them
Cloudflare Encrypted connection between your browser and our server, plus filtering of malicious traffic Network address and request metadata in transit. Pages are not cached.
Brevo Sending invitations and transfer notifications Recipient address and message content. Patient names are deliberately excluded from all email.
Backblaze B2 Off-site backup storage Backups encrypted before they leave our server. The key is not stored with them.

We also disclose information where legally required, and to professional advisers under confidentiality. If we are ever compelled to disclose customer data we will tell you unless prohibited from doing so.

How it is protected

  • Encrypted in transit using current TLS.
  • Patient names encrypted at rest with AES-256-GCM; the key is held outside the database and is not included in backups.
  • Passwords hashed with Argon2id, and checked against known breach corpora at the point they are chosen.
  • Multi-factor authentication mandatory for every account.
  • Each pharmacy group’s data isolated in the application and independently by the database, so a query that fails to scope itself returns nothing rather than another group’s records.
  • An append-only audit log the application cannot alter or delete at runtime.
  • Encrypted off-site backups, restore-tested rather than assumed.

How long it is kept

DataRetention
InventoryReplaced entirely each time a report loads; no stock history is kept
Import recordsRetained for the life of the account
Transfer records, including any patient nameRetained for the life of the account, or as your BAA and record-keeping obligations require
Audit logRetained for the life of the account
Sign-in attempt records30 days
Expired sessions7 days
Backups14 daily, 8 weekly, 12 monthly

On termination we delete customer data within 90 days unless the law or your BAA requires otherwise. Encrypted backups age out on the cycle above.

Your rights

Depending on where you are, you may have rights to access, correct, delete, or port personal information, to object to or restrict processing, and to complain to a supervisory authority.

Where we process information on behalf of a pharmacy group, requests about that information should go to the group, which decides how it is used. We will help them respond. For information we hold about you directly, write to [email protected].

Patients: contact the pharmacy that dispenses your prescriptions. We hold no relationship with you directly and cannot verify your identity.

Children

RxChange is a workplace tool that is not directed at children, and we do not knowingly collect information from them. A patient name recorded on a transfer may relate to a minor; it is handled as PHI regardless of age.

Where data is held

Data is stored in the United States. Where information is transferred internationally we use lawful transfer mechanisms.

Breach notification

If personal information or PHI is compromised we will notify affected customers without undue delay, and within the timeframes required by your BAA and by applicable law, including the HIPAA Breach Notification Rule.

Changes

We will post changes here and update the effective date. Material changes will be notified to your administrators by email.

Contact

4TressCyber LLC
8633 S Sandy Pkwy, Sandy, UT 84070
Privacy: [email protected]
Security: [email protected]

RxChange

One list of what every one of your pharmacies has on the shelf.

Product

How it works Keeping it safe What it costs Sign in

Legal

Terms of Service Privacy Policy HIPAA & BAA Accessibility

Contact

[email protected] Report a vulnerability

© 2026 4TressCyber LLC. All rights reserved.

RxChange is inventory software. It is not a pharmacy, and it does not provide medical, pharmaceutical, or legal advice.