HIPAA Compliance Notice

Pi Credits is designed so that Protected Health Information (PHI) handled in the prescription-funding workflow is collected, accessed, and stored in alignment with the Health Insurance Portability and Accountability Act (HIPAA).

Role-Scoped PHI Access

PHI is visible only to clinical and case roles that require it to coordinate medication fulfillment. Referral partners, billing roles, and financial analysts operate on de-identified case and financial views and never see patient health details.

Company Isolation

Every subscribing company operates in an isolated environment. Database-level isolation with deny-by-default policies prevents any cross-company access to case or patient records.

Audit Trail

Every credit transaction and prescription event is written to a permanent, timestamped record, giving each company a complete and unalterable history of who did what and when.

Safeguards

Transport encryption (TLS) for all connections to the Platform.

Role-based access control with multi-factor authentication support.

Payment card data handled exclusively by the PCI-scoped payment processor.

PHI excluded from transactional email and system notifications.

Business Associate Arrangements

Where a subscribing company's use of the Platform makes the operator a business associate under HIPAA, a Business Associate Agreement is executed as part of enterprise onboarding. Contact your account manager through app.picredits.com to request one.