Closed beta · Controlled prototype environment

HIPAA alignment requires more than a BAA.

PBRx is being developed with privacy, security, controlled data handling, and contractual safeguards appropriate to protected health information.

Executed OpenAI BAAExecuted Proton BAAApproved controls

How PBRx describes its current status

PBRx is being developed as a HIPAA-aligned platform. It is currently a controlled functional prototype in closed beta—not a generally available public clinical service. This public marketing website does not accept personal health information.

The OpenAI Business Associate Agreement

PBRx uses eligible OpenAI API services under an executed Business Associate Agreement (BAA), with approved data-retention controls, to support HIPAA-compliant processing of protected health information.

The Proton Business Associate Agreement

PBRx uses Proton Mail for business email and has entered into an executed Business Associate Agreement with Proton. Proton provides encrypted email services designed to support appropriately configured handling of protected health information.

Messages within Proton are encrypted automatically. Messages sent to or received from outside email providers are not automatically end-to-end encrypted unless additional protection, such as Proton password-protected email, is used. The Proton BAA applies to covered Proton services; it does not cover the public PBRx.com website, Netlify services, unrelated systems, or make every email workflow automatically HIPAA compliant. The public website and ordinary email are not medical-record submission channels.

For more information, see Proton’s healthcare and HIPAA information and the HHS guidance on business associates.

A BAA is one safeguard, not a complete compliance program.

A BAA does not by itself make a platform or organization HIPAA compliant. Compliance also depends on appropriate administrative, physical, and technical safeguards; policies and training; access controls; risk management; incident response; vendor oversight; and correct system configuration and operation.

Service and configuration boundaries

Only services and configurations eligible under the applicable agreement should be used for workflows involving protected health information. PBRx is designed so protected information is processed through controlled backend paths rather than sent directly from a user's browser to an AI provider.

Minimum necessary and patient control

PBRx is designed around bounded uses, patient-centered authorization, and access limited to information needed for the permitted workflow. Source evidence and audit context should remain attached to generated summaries.

No public PHI submissions

Do not send health records, lab reports, diagnoses, or other sensitive information through this public website or ordinary email. Production health-data workflows require separate authenticated systems, notices, controls, and authorizations.