Compliance and security

Built as a HIPAA Business Associate from day one.

We are a HIPAA Business Associate under federal law. That means we sign a Business Associate Agreement, or BAA, with every prescriber we work with, and we follow the same rules as the hospital or pharmacy that sees the patient.

Pre-production posture. No live patient records have flowed yet. First live prescriber engagement in 2026.

What that actually means

Plain words for the rules we follow.

What is a Business Associate?

A Business Associate is a company that handles patient health information for a doctor or clinic. The law that defines it is 45 CFR § 160.103. Because we process clinical data for prescribers, we are one.

What is a BAA?

A Business Associate Agreement, or BAA, is a written contract that spells out how we protect patient data and what we must do if something goes wrong. The law that requires it is 45 CFR § 164.504(e). We sign one with every prescriber.

What patient data touches Scriptura?

We only see the clinical data a prescriber needs to write a peptide protocol. No patient names, addresses, or medical record numbers ever reach Scriptura.

How the data is split

The patient identifier stays with the prescriber.

Here is the path the data takes, left to right. The patient name and the clinical data never sit in the same place inside our systems.

Step 1

Patient wearable and EHR

Holds the patient name, date of birth, and address. EHR is short for electronic health record, the chart the prescriber keeps.

Step 2

Boundary tokenizer

Kepler on the wearable side and the prescriber EHR connector on the clinical side swap the patient identifier for a random 128-bit token. A token is a stand-in code with no name attached.

Step 3

Scriptura

Sees only the token plus the clinical fields needed to compute the recommendation. We hold no way to turn the token back into a name.

Step 4

Back to the prescriber

The recommendation returns to the prescriber, who re-links the token to the patient on their own side.

Why do it this way? It narrows what a breach could expose. If Scriptura's systems were ever compromised, the attacker would see anonymized clinical fields with no way to tie them back to a person.

Our subprocessors

Every subprocessor sits under a signed BAA.

A subprocessor is any outside vendor that could touch protected health information on our behalf. The whole stack runs on AWS under the standard AWS BAA, available through AWS Artifact at no extra cost, and uses HIPAA-eligible services only. Here is the full list.

VendorFunctionBAA statusNotes
AWS: ECS, ECR, RDS, S3, Bedrock, SES, CloudTrail, KMS, CognitoPrimary hosting and compute, database, storage, AI inference, email, audit logging, secrets, and sign-inBAA in place via AWS ArtifactHIPAA-eligible services only, per the AWS Artifact list
CloudflareDNS and edge for the marketing site onlyNo BAA (non-PHI surface)Protected health information traffic uses end-to-end TLS direct to AWS with gray-cloud DNS, so it never passes through the Cloudflare proxy
Google WorkspaceCorporate email and DriveBAA in placeDrive holds only de-identified analytic exports or synthetic data, never live patient records
Kepler Technologies LLCWearable data integration partnerBAA in negotiation (NDA out 2026-06-16)No live patient data will flow to Kepler until the BAA is countersigned
Anthropic Claude via AWS BedrockProtocol recommendation inferenceCovered under the AWS BAACustomer data is not used for training
Where we are

The runway to first live prescription.

We are pre-production. Some things are done, and some are still on the runway. Here is the honest list.

  • Signed AWS BAA in placeDone
  • Standard operating procedures for incident response drafted. The full tabletop test has not been run yet.Drafted, on the runway
  • Designated Security Official letterOn the runway
  • Formal HIPAA risk analysis documentOn the runway
  • Kepler BAA countersignedIn negotiation
  • Cyber insurance policy boundOn the runway
  • First live prescriber engagement, planned for 2026 after the runway items above closePlanned for 2026
What we do not claim

We only claim what is true today.

We do not claim SOC 2, HITRUST, or any third-party certification. Those are earned, not asserted, and we are pre-production.

What we do claim: HIPAA Business Associate posture, a tokenization-at-boundary architecture, and an AWS native subprocessor stack that is BAA-covered end to end.

Have your compliance team send us their questionnaire. We answer plainly.

Legal contact: reach our team through the demo request form and we will route your compliance questions to the right person.

HIPAA compliance and security | Scriptura Health | Scriptura Health