How PBRx describes its current status
PBRx is being developed as a HIPAA-aligned platform. It is currently a controlled functional prototype in closed beta—not a generally available public clinical service. This public marketing website does not accept personal health information.
The OpenAI Business Associate Agreement
PBRx uses eligible OpenAI API services under an executed Business Associate Agreement (BAA), with approved data-retention controls, to support HIPAA-compliant processing of protected health information.
The Proton Business Associate Agreement
PBRx uses Proton Mail for business email and has entered into an executed Business Associate Agreement with Proton. Proton provides encrypted email services designed to support appropriately configured handling of protected health information.
Messages within Proton are encrypted automatically. Messages sent to or received from outside email providers are not automatically end-to-end encrypted unless additional protection, such as Proton password-protected email, is used. The Proton BAA applies to covered Proton services; it does not cover the public PBRx.com website, Netlify services, unrelated systems, or make every email workflow automatically HIPAA compliant. The public website and ordinary email are not medical-record submission channels.
For more information, see Proton’s healthcare and HIPAA information and the HHS guidance on business associates.
A BAA does not by itself make a platform or organization HIPAA compliant. Compliance also depends on appropriate administrative, physical, and technical safeguards; policies and training; access controls; risk management; incident response; vendor oversight; and correct system configuration and operation.
Service and configuration boundaries
Only services and configurations eligible under the applicable agreement should be used for workflows involving protected health information. PBRx is designed so protected information is processed through controlled backend paths rather than sent directly from a user's browser to an AI provider.
Minimum necessary and patient control
PBRx is designed around bounded uses, patient-centered authorization, and access limited to information needed for the permitted workflow. Source evidence and audit context should remain attached to generated summaries.
No public PHI submissions
Do not send health records, lab reports, diagnoses, or other sensitive information through this public website or ordinary email. Production health-data workflows require separate authenticated systems, notices, controls, and authorizations.