Encryption in transit & at rest
TLS for data in motion and strong encryption for data at rest, across every service.
Prescr handles some of the most sensitive data there is. Here's exactly how we protect it, and an honest account of what's certified versus in progress.
TLS for data in motion and strong encryption for data at rest, across every service.
Least-privilege access so each staff member sees only what their role needs.
Every access and change to patient data is recorded and reviewable.
Choose deployment regions that match your legal and procurement needs.
AI clinical output is always reviewed and signed by a clinician before it counts.
Calls and recordings are handled with explicit consent and clear retention rules.
"Aligned" and "ready" mean we are built to the standard's requirements. We will only say "certified" once independently audited. Here's the honest picture.
Built to HIPAA's safeguards for US-facing deployments. BAA available on request.
Data-subject rights, DPA support, deletion/export workflows and EU-region hosting for clients in scope.
Business Associate Agreement and Data Processing Addendum available for qualified customers.
Standards-based integration patterns for EHR, scheduling, billing and patient-app workflows.
We use "aligned" and "ready" language deliberately. We only claim independent certification after the relevant audit or certification is complete.
We provide the agreements and references procurement and security reviewers ask for, so an evaluation doesn't stall.
Our standard DPA covering processing, sub-processors and residency. Read the DPA →
BAA available for HIPAA-covered entities on request.
Clear policies on what we store, why, and for how long. Privacy policy →
We'll walk your team through our controls and provide the documentation you need to sign off.