Security, HIPAA & AI

Last updated July 26, 2026 · RxAuto is a product of AccelRx · New York, NY

Three questions come up every time: where does the data go, are you HIPAA compliant, and are you using AI on my prescriptions? Here are the direct answers.

Where the data goes

Nowhere. RxAuto installs on one Windows workstation inside your pharmacy and talks to your pharmacy management system over your own network, exactly as a staff member sitting at that machine would. Reading the incoming prescription, deciding what to type, and typing it all happen on that workstation. There is no cloud round-trip in the dispensing path, and we never receive a copy of your database.

The only outbound connections are license validation, software updates, and a limited per-prescription accuracy record — described field by field in our Privacy Policy. Patient names, dates of birth, addresses and contact details never leave your building. What does leave — your internal patient number, the prescription number, the fill date, the drug and the directions — is protected health information, which is exactly why we sign a BAA rather than claiming we handle none.

Our HIPAA position

RxAuto processes protected health information on your behalf, which makes us a Business Associate under HIPAA. We sign a Business Associate Agreement with every pharmacy — you can read our standard BAA in full before you ask for a copy. Sign it before you process live prescriptions. If your pharmacy has its own BAA form, send it and we will sign yours.

Be sceptical of any vendor claiming to be "HIPAA certified" — no such certification exists. What matters is the architecture and the agreement. Ours minimizes exposure by design: the identifying fields never transit, free-text directions are redacted twice before storage, and access to what we do hold is limited to the people who support your installation.

  • Encryption in transit (TLS) and at rest for everything we store.
  • Patient identifiers excluded at the source, not filtered after the fact.
  • Directions text redacted on the workstation and again server-side.
  • License keys and admin credentials held in a managed secret store, never in the product’s source.
  • Access to telemetry limited to named administrators.

We are a small company and we would rather tell you what we do not have than imply otherwise: we do not currently hold a SOC 2 report or HITRUST certification. If your organization requires one, tell us and we will be straight with you about timelines.

Are you using AI on my prescriptions?

Mostly no, and never without your say-so. The great majority of what RxAuto types comes from deterministic logic trained on your own twelve months of dispensing history — your drug file, the way your store writes directions, your pricing. That is not a language model; it is your own data, replayed.

There is one optional feature that uses a language model: when a prescriber writes directions in an unusual form, RxAuto can ask a model to propose your house-style translation. It is off unless you enable it. When enabled, only redacted directions and drug information are sent — never patient identifiers — processing runs under a Business Associate Agreement with our cloud provider, and the suggestion still lands in the held queue for a pharmacist. Turning it off does not stop RxAuto working.

What happens when it gets something wrong

It will, occasionally — every data-entry method does, including hand typing. That is why every prescription RxAuto enters is placed in your review queue in an unverified state, and why our Terms of Service put verification squarely with your pharmacist. Anything RxAuto is not confident about — an ambiguous patient match, a drug not in your history — it leaves blank for staff rather than guessing.

Each prescription is written as an all-or-nothing transaction: if a step fails, nothing is written at all, so you never get a half-entered script. And when your pharmacist corrects something, that correction is what teaches your store's installation.

If you stop using it

Uninstall the software and transmission stops. Everything RxAuto typed stays in your pharmacy management system — it is your data, in your system, in the same format as anything typed by hand. There is no lock-in and nothing to export.

Reporting a security concern

If you believe you have found a vulnerability or a privacy problem, email support@rxauto.ai or call (917) 780-9525. We will acknowledge within one business day. Please do not include protected health information in your report.

Questions about this document, security, or a Business Associate Agreement? Email support@rxauto.ai or call (917) 780-9525. We answer compliance questions in writing.