HIPAA Compliance Program
Administrative, technical, and contractual safeguards for protected health information.
QR Rx is designed to operate as a Business Associate to healthcare providers. Our Trust Center explains the safeguards, agreements, access controls, and service-provider boundaries that support our HIPAA compliance program.
At a Glance
Administrative, technical, and contractual safeguards for protected health information.
A Business Associate Agreement is available for provider customers before PHI is handled.
Production data is protected in transit and the database and protected storage are encrypted at rest.
Role-based access, patient verification, rate limits, and MFA-protected administrative access.
Security Controls
These controls cover provider access, patient access, infrastructure, monitoring, and incident response.
Layered safeguards protect patient and clinic information throughout the platform.
Access is limited to the right person, role, clinic, and patient plan.
Sensitive activity is recorded so clinics can understand how protected workflows are used.
Patients receive a secure recovery experience without creating another account.
Production services use healthcare-ready infrastructure and defensive controls.
A documented process guides identification, containment, communication, and follow-up.
Patient Data
Patients opening a standard care plan use the secure link delivered by their clinic, then verify their identity before protected content is shown. Patient-blank Aftercare Cards open directly because they do not expose a patient record.
Access
A secure plan link, six digit PIN, and date of birth protect standard human care plans. Veterinary plans use the owner's last name in place of date of birth.
Sessions
Verified sessions use a three day idle deadline and remain bounded by the plan's recovery window. Patients can verify again while the clinic retains the plan.
Data Lifecycle
Care-plan data is retained while the provider account is active. After account termination, the provider has 30 days to export data before active PHI is returned or destroyed under the BAA. Isolated backups age out under the backup-retention schedule.
Service Providers
The registry identifies each core service provider, its purpose, whether it is authorized for PHI, and its current agreement status.
Render
Application hosting and Postgres database infrastructure for the QR Rx application and its data plane.
AWS S3
Object storage for clinic branding, provider uploads, patient-submitted recovery photos, and provider data snapshots, using server-side encryption at rest.
Firecrawl
Public website discovery for admin-created clinic demos and branding intake.
Paubox
Transactional email delivery for care plans, recovery reminders, password resets, team invitations, and outcome digests.
Telnyx
SMS delivery for care-plan links, recovery check-ins, and unscanned-plan nudges, with delivery-receipt webhooks.
Cloudflare Turnstile
Bot-protection challenges on public forms and patient verification surfaces.
Google Sign-In
Optional OAuth identity provider for provider-portal sign-in.
Google Cloud Translation
Care-plan translation through QR Rx's HIPAA-authorized Google Cloud configuration. Requests are limited to care-plan copy and do not include patient identifiers.
Anthropic
Restricted language-model assistance for administrative tools and explicitly governed clinical AI flows. Patient-specific calls require the deployment clinical AI policy gate. The default configuration fails closed.
Stripe
Provider subscription billing, payment processing, and the customer billing portal. Patients are not billed by QR Rx.
Google Ads
Conversion measurement on public marketing and provider-acquisition pages. The tag is disabled before loading on qrrx.care and patient care-plan routes.
Sentry
Application error monitoring. Session replay, tracing, logs, request bodies, cookies, and default PII collection are disabled, and events pass through PHI and credential scrubbing before transmission.
Registry updated September 1, 2026. Review the core service-provider registry for data accessed, region, and agreement details.
Documents
Review the agreement that governs QR Rx handling of PHI for provider customers.
Review BAASee how personal information and protected health information are collected and handled.
Review Privacy PolicyReview each core service provider, its purpose, data boundary, and agreement status.
Review SubprocessorsRead the operating terms for clinics and authorized QR Rx users.
Review TermsProcurement and Compliance
Contact QR Rx at dnelson@qrrx.io for current security information, procurement materials, and compliance questions.