Trust Center

    Security and privacy, clearly documented.

    QR Rx is designed to operate as a Business Associate to healthcare providers. Our Trust Center explains the safeguards, agreements, access controls, and service-provider boundaries that support our HIPAA compliance program.

    At a Glance

    The essentials for a clinic review.

    HIPAA Compliance Program

    Administrative, technical, and contractual safeguards for protected health information.

    Customer BAA Available

    A Business Associate Agreement is available for provider customers before PHI is handled.

    Encrypted

    Production data is protected in transit and the database and protected storage are encrypted at rest.

    Access Controlled

    Role-based access, patient verification, rate limits, and MFA-protected administrative access.

    Security Controls

    Protection across the full care-plan lifecycle.

    These controls cover provider access, patient access, infrastructure, monitoring, and incident response.

    Data Protection

    Layered safeguards protect patient and clinic information throughout the platform.

    • TLS protects customer-facing production traffic
    • The production database and protected object storage use encryption at rest
    • Patient PINs are encrypted with a separate keyed lookup hash for verification

    Identity and Access

    Access is limited to the right person, role, clinic, and patient plan.

    • Owner, practitioner, admin, and staff permissions are role based
    • Administrative access is protected by MFA and authenticated sessions
    • Standard human care plans use a secure link, six digit PIN, and date of birth verification

    Audit and Monitoring

    Sensitive activity is recorded so clinics can understand how protected workflows are used.

    • Security-relevant and PHI access events are recorded in audit trails
    • Delivery activity and suppression states are logged
    • Legal acceptances include a timestamp and supporting request metadata

    Patient Privacy

    Patients receive a secure recovery experience without creating another account.

    • Patient sessions are time limited and bounded by the recovery timeline
    • QR Rx does not sell patient data
    • Patient-specific external clinical AI remains disabled unless the deployment policy requirement is satisfied

    Infrastructure and Reliability

    Production services use healthcare-ready infrastructure and defensive controls.

    • Render and protected AWS storage operate under signed BAAs
    • Rate limits protect login and patient verification workflows
    • Selected public forms use Cloudflare Turnstile bot protection

    Incident Response

    A documented process guides identification, containment, communication, and follow-up.

    • Security events follow a documented triage and response process
    • Affected customers are notified under the BAA and applicable law
    • Client error reports are scrubbed before storage

    Patient Data

    Secure access without another patient account.

    Patients opening a standard care plan use the secure link delivered by their clinic, then verify their identity before protected content is shown. Patient-blank Aftercare Cards open directly because they do not expose a patient record.

    Access

    A secure plan link, six digit PIN, and date of birth protect standard human care plans. Veterinary plans use the owner's last name in place of date of birth.

    Sessions

    Verified sessions use a three day idle deadline and remain bounded by the plan's recovery window. Patients can verify again while the clinic retains the plan.

    Data Lifecycle

    Care-plan data is retained while the provider account is active. After account termination, the provider has 30 days to export data before active PHI is returned or destroyed under the BAA. Isolated backups age out under the backup-retention schedule.

    Service Providers

    Clear data boundaries at every layer.

    The registry identifies each core service provider, its purpose, whether it is authorized for PHI, and its current agreement status.

    View Core Registry

    Infrastructure

    • Render

      PHI AuthorizedBAA Signed

      Application hosting and Postgres database infrastructure for the QR Rx application and its data plane.

    • AWS S3

      PHI AuthorizedBAA Signed

      Object storage for clinic branding, provider uploads, patient-submitted recovery photos, and provider data snapshots, using server-side encryption at rest.

    • Firecrawl

      No PHI AccessNo PHI BAA

      Public website discovery for admin-created clinic demos and branding intake.

    Communications

    • Paubox

      PHI AuthorizedBAA Signed

      Transactional email delivery for care plans, recovery reminders, password resets, team invitations, and outcome digests.

    • Telnyx

      PHI AuthorizedHIPAA Terms

      SMS delivery for care-plan links, recovery check-ins, and unscanned-plan nudges, with delivery-receipt webhooks.

    Identity / Security

    • Cloudflare Turnstile

      No PHI AccessNo PHI BAA

      Bot-protection challenges on public forms and patient verification surfaces.

    • Google Sign-In

      No PHI AccessNo PHI BAA

      Optional OAuth identity provider for provider-portal sign-in.

    AI / Translation

    • Google Cloud Translation

      PHI AuthorizedBAA Signed

      Care-plan translation through QR Rx's HIPAA-authorized Google Cloud configuration. Requests are limited to care-plan copy and do not include patient identifiers.

    • Anthropic

      No PHI AccessNo PHI BAA

      Restricted language-model assistance for administrative tools and explicitly governed clinical AI flows. Patient-specific calls require the deployment clinical AI policy gate. The default configuration fails closed.

    Billing

    • Stripe

      No PHI AccessNo PHI BAA

      Provider subscription billing, payment processing, and the customer billing portal. Patients are not billed by QR Rx.

    Reliability / Measurement

    • Google Ads

      No PHI AccessNo PHI BAA

      Conversion measurement on public marketing and provider-acquisition pages. The tag is disabled before loading on qrrx.care and patient care-plan routes.

    • Sentry

      No PHI AccessNo PHI BAA

      Application error monitoring. Session replay, tracing, logs, request bodies, cookies, and default PII collection are disabled, and events pass through PHI and credential scrubbing before transmission.

    Registry updated September 1, 2026. Review the core service-provider registry for data accessed, region, and agreement details.

    Documents

    Everything your review team needs.

    Procurement and Compliance

    Need a security questionnaire or vendor-risk packet?

    Contact QR Rx at dnelson@qrrx.io for current security information, procurement materials, and compliance questions.