How PBRx describes its current status
PBRx is being developed as a HIPAA-aligned platform. It is currently a controlled functional prototype in closed beta—not a generally available public clinical service. This public marketing website does not accept personal health information.
The OpenAI Business Associate Agreement
PBRx uses eligible OpenAI API services under an executed Business Associate Agreement (BAA), with approved data-retention controls, to support HIPAA-compliant processing of protected health information.
A BAA does not by itself make a platform or organization HIPAA compliant. Compliance also depends on appropriate administrative, physical, and technical safeguards; policies and training; access controls; risk management; incident response; vendor oversight; and correct system configuration and operation.
Service and configuration boundaries
Only services and configurations eligible under the applicable agreement should be used for workflows involving protected health information. PBRx is designed so protected information is processed through controlled backend paths rather than sent directly from a user's browser to an AI provider.
Minimum necessary and patient control
PBRx is designed around bounded uses, patient-centered authorization, and access limited to information needed for the permitted workflow. Source evidence and audit context should remain attached to generated summaries.
No public PHI submissions
Do not send health records, lab reports, diagnoses, or other sensitive information through this public website or ordinary email. Production health-data workflows require separate authenticated systems, notices, controls, and authorizations.