Built as a HIPAA Business Associate from day one.
We are a HIPAA Business Associate under federal law. That means we sign a Business Associate Agreement, or BAA, with every prescriber we work with, and we follow the same rules as the hospital or pharmacy that sees the patient.
Pre-production posture. No live patient records have flowed yet. First live prescriber engagement in 2026.
Plain words for the rules we follow.
What is a Business Associate?
A Business Associate is a company that handles patient health information for a doctor or clinic. The law that defines it is 45 CFR § 160.103. Because we process clinical data for prescribers, we are one.
What is a BAA?
A Business Associate Agreement, or BAA, is a written contract that spells out how we protect patient data and what we must do if something goes wrong. The law that requires it is 45 CFR § 164.504(e). We sign one with every prescriber.
What patient data touches Scriptura?
We only see the clinical data a prescriber needs to write a peptide protocol. No patient names, addresses, or medical record numbers ever reach Scriptura.
The patient identifier stays with the prescriber.
Here is the path the data takes, left to right. The patient name and the clinical data never sit in the same place inside our systems.
Patient wearable and EHR
Holds the patient name, date of birth, and address. EHR is short for electronic health record, the chart the prescriber keeps.
Boundary tokenizer
Kepler on the wearable side and the prescriber EHR connector on the clinical side swap the patient identifier for a random 128-bit token. A token is a stand-in code with no name attached.
Scriptura
Sees only the token plus the clinical fields needed to compute the recommendation. We hold no way to turn the token back into a name.
Back to the prescriber
The recommendation returns to the prescriber, who re-links the token to the patient on their own side.
Why do it this way? It narrows what a breach could expose. If Scriptura's systems were ever compromised, the attacker would see anonymized clinical fields with no way to tie them back to a person.
Every subprocessor sits under a signed BAA.
A subprocessor is any outside vendor that could touch protected health information on our behalf. The whole stack runs on AWS under the standard AWS BAA, available through AWS Artifact at no extra cost, and uses HIPAA-eligible services only. Here is the full list.
| Vendor | Function | BAA status | Notes |
|---|---|---|---|
| AWS: ECS, ECR, RDS, S3, Bedrock, SES, CloudTrail, KMS, Cognito | Primary hosting and compute, database, storage, AI inference, email, audit logging, secrets, and sign-in | BAA in place via AWS Artifact | HIPAA-eligible services only, per the AWS Artifact list |
| Cloudflare | DNS and edge for the marketing site only | No BAA (non-PHI surface) | Protected health information traffic uses end-to-end TLS direct to AWS with gray-cloud DNS, so it never passes through the Cloudflare proxy |
| Google Workspace | Corporate email and Drive | BAA in place | Drive holds only de-identified analytic exports or synthetic data, never live patient records |
| Kepler Technologies LLC | Wearable data integration partner | BAA in negotiation (NDA out 2026-06-16) | No live patient data will flow to Kepler until the BAA is countersigned |
| Anthropic Claude via AWS Bedrock | Protocol recommendation inference | Covered under the AWS BAA | Customer data is not used for training |
The runway to first live prescription.
We are pre-production. Some things are done, and some are still on the runway. Here is the honest list.
- Signed AWS BAA in placeDone
- Standard operating procedures for incident response drafted. The full tabletop test has not been run yet.Drafted, on the runway
- Designated Security Official letterOn the runway
- Formal HIPAA risk analysis documentOn the runway
- Kepler BAA countersignedIn negotiation
- Cyber insurance policy boundOn the runway
- First live prescriber engagement, planned for 2026 after the runway items above closePlanned for 2026
We only claim what is true today.
We do not claim SOC 2, HITRUST, or any third-party certification. Those are earned, not asserted, and we are pre-production.
What we do claim: HIPAA Business Associate posture, a tokenization-at-boundary architecture, and an AWS native subprocessor stack that is BAA-covered end to end.
Have your compliance team send us their questionnaire. We answer plainly.
Legal contact: reach our team through the demo request form and we will route your compliance questions to the right person.