Trust center
HIPAA compliance
Effective: 2026-05-30
WeConsult Rx is a Business Associate under HIPAA. We execute a Business Associate Agreement with every customer (covered entity or business associate) before any PHI is processed on our platform.
HIPAA controls — overview
Administrative safeguards (§164.308)
- Security management process, including risk analysis and management.
- Assigned security responsibility (CISO / Security Officer).
- Workforce security: termination procedures, sanction policy.
- Information access management (role-based access).
- Security awareness training (annual + new hire).
- Security incident procedures with breach notification within BAA windows.
- Contingency plan: data backup, disaster recovery, emergency mode.
- Annual evaluation against §164.308.
Physical safeguards (§164.310)
- Facility access controls inherited from cloud infrastructure providers — SOC 2 Type II.
- Workstation use and security policy for staff devices.
- Device and media controls: encrypted laptops, secure disposal.
Technical safeguards (§164.312)
- Access control — unique user IDs, automatic logoff, encryption.
- Audit controls — append-only audit log (7-year retention).
- Integrity — tenant isolation, append-only audit, version control.
- Person or entity authentication — MFA for staff accounts.
- Transmission security — TLS 1.2+ and signed webhooks.
Safe Harbor de-identification
Before any chart data is sent to AI-assisted services, we apply the 18-identifier Safe Harbor de-identification standard (§164.514(b)(2)). De-identification events are logged.
- Names, addresses, ZIP codes more granular than first 3 digits
- All dates more specific than year (with ages 90+ aggregated)
- Phone, fax, email, SSN
- Medical record numbers (replaced with de-identified tokens)
- Account numbers, license numbers, vehicle identifiers
- Device identifiers, URLs, IP addresses
- Biometric identifiers, full-face photographs
- Any other unique identifying number / characteristic / code
Breach notification
We notify affected customers per the BAA executed with that customer. For confirmed breaches affecting unsecured PHI, notification occurs without unreasonable delay and no later than 60 days from discovery (§164.410).
Minimum necessary
Our application implements the minimum necessary standard (§164.502(b)). UI surfaces only the fields a role needs; the database only stores the fields a workflow requires; audit metadata excludes PHI by gate test.
BAA
Our standard Business Associate Agreement is available for review at /baa. We countersign within one business day.