Polarity

Built for HIPAA.

How we protect patient data in the management software for compounding pharmacies and the provider portal for providers and clinics.

Private by construction.

Each pharmacy's data stays its own, from the database up.

  • Your own keys

    Encryption keys for each pharmacy, with rotation.

  • Walled off

    Each pharmacy's data is isolated by the database itself.

  • Two-factor, always

    Required for every role, asked again for anything sensitive.

  • Read in house

    Prescriptions are read by private AI, never an outside service.

Verified at every step.

Safeguards on every license, sign-in, chart and payment.

  • Licenses

    Each state license is verified before you can claim a case there.

  • Sign-in

    A two-factor code at sign-in, and sign-out after 15 idle minutes.

  • Audit

    Every chart you open is on the record.

  • Payments

    Payment is taken only when you approve.

How your data stays yours.

What protects patient data in each product.

Access

Management software

One account per person

Every person has their own account. At shared stations, each action is credited to the badge holder.

Two-factor before any data

Two-factor sign-in on every account before any data opens.

Roles deny by default

Raising someone's access is a request another person approves, and changing access ends that person's open sessions.

Idle sign-out

After 30 minutes by default, set by each pharmacy from 5 to 240 minutes. Station screens lock after 10 idle minutes.

A fresh code for sensitive steps

Revealing an SSN, a bulk export, emergency access, each approval decision. Nobody decides their own request.

Emergency access

It lasts one hour, needs a fresh code and a reason, and every use is recorded.

Provider portal

Two-factor sign-in

A two-factor code at sign-in, and sign-out after 15 idle minutes.

Verified licenses

Each state license is verified at the primary source. The queue shows cases only from states where your license is active and verified.

One provider per case

A claim holds the case for 30 minutes, so no one reviews it twice.

Audit and integrity

Management software

Audit entries on open

Opening a patient record, a prescription's details or a shipping address writes an audit entry. A daily check flags unusual read volume.

Who, when and from where

Each audit entry records who, when, from which device and network, and how they signed in.

Kept 7 years by default

Audit entries are kept 7 years by default, and the application cannot edit or delete them.

Legal records are never edited

Corrections are new entries that reference the original.

Controlled-substance log and print history

Both are hash chained and verified daily.

Provider portal

Audit entries on read

Reading a patient's record writes an audit entry.

Notes stay as written

Notes are never rewritten. Corrections are added as addenda.

Checks that fail closed

License, compliance and product checks run again at every approval. If anything is off, it stops.

Encryption

Management software

In transit

HTTPS only, and the services refuse to start on an unencrypted database or cache connection.

At rest, field by field

Patient names, dates of birth, addresses, insurance, allergies, conditions, medications, notes and messages are encrypted field by field with each pharmacy's own key, protected in Azure Key Vault. Databases, backups and file storage are encrypted too.

Each pharmacy's own key

Each pharmacy can rotate its own key.

Provider portal

In transit

HTTPS only, and the database accepts only encrypted connections.

Database at rest

The database is encrypted at rest.

Encrypted pharmacy handoffIn development

Isolation and hosting

Management software

Fenced at the database

Each pharmacy's data is fenced at the database. Row-level security scopes every query.

Databases closed to the internet

Databases and storage are closed to the public internet.

Microsoft Azure in US regions

Secrets are kept in Key Vault, and services use managed identities instead of stored passwords.

Provider portal

Fenced at the database

Clinic data is fenced at the database with row-level security.

Privacy in operations

Management software

Patient details out of logs

Patient details are kept out of logs and telemetry. There is no session replay or third-party analytics in the app.

Purpose-built responses

The API returns purpose-built responses, never whole records.

Patient labels print direct

Labels with patient details print only over a direct network connection or the browser.

Private AI

The model that reads prescriptions runs inside PolarityRx.

Malware scanning

Uploads through intake, e-prescriptions and attachments are scanned for malware.

Patient rights requestsIn development

Access, accounting of disclosures and amendments.

Provider portal

Consent and identity

Patient consent is captured, and identity is verified before checkout.

Payment on approval

Payment is authorized at checkout and captured only on approval.

Case messages

Patient and care team threads stay with the case.

Alerts

Management software

In-app alerts

Approval requests, expiring lots and licenses, unusual record reads and sign-ins from a new device.

Email and text notices to patientsIn development

How we work.

What each product is held to as it is built.

  • The HIPAA checklist

    In the management software, every change is checked against it: no patient details in logs or URLs, synthetic test data, access checked on the server, sensitive actions recorded in the audit trail.

  • An access rule for every endpoint

    Every endpoint has an access rule in a test matrix. A missing rule fails the build. In the management software, the matrix is also checked for each role, for signed-out callers and for sessions without the second factor.

  • Fence tests

    Tests try to reach another pharmacy's or clinic's records, and fail the build if any table holding them lacks the database fence.

  • Encryption coverage

    In the management software, a test fails the build if a patient-data field is neither encrypted nor exempted with a written reason.

  • Leak tests

    In the provider portal, tests check that patient details are redacted from logs.

  • A separate review

    In the management software, changes that touch access, patient data, money or the database get a separate review before they land.

  • Scans on every change

    In the management software, dependency vulnerability audits, container image scans and secret scanning run on every change and weekly.

  • Synthetic data only

    In the management software, only synthetic data is used outside production.

  • Findings block releases

    In the management software, security findings block a release until they are fixed.

Bring your security team.

A 30 minute demo with our team.

Book a demo