HIPAA Compliance Notice
Last updated: July 4, 2026
Pi Credits is designed so that Protected Health Information (PHI) handled in the prescription-funding workflow is collected, accessed, and stored in alignment with the Health Insurance Portability and Accountability Act (HIPAA).
Role-Scoped PHI Access
PHI is visible only to clinical and case roles that require it to coordinate medication fulfillment. Referral partners, billing roles, and financial analysts operate on de-identified case and financial views and never see patient health details.
Company Isolation
Every subscribing company operates in an isolated environment. Database-level isolation with deny-by-default policies prevents any cross-company access to case or patient records.
Audit Trail
Every credit transaction and prescription event is written to a permanent, timestamped record, giving each company a complete and unalterable history of who did what and when.
Safeguards
Transport encryption (TLS) for all connections to the Platform.
Role-based access control with multi-factor authentication support.
Payment card data handled exclusively by the PCI-scoped payment processor.
PHI excluded from transactional email and system notifications.
Business Associate Arrangements
Where a subscribing company's use of the Platform makes the operator a business associate under HIPAA, a Business Associate Agreement is executed as part of enterprise onboarding. Contact your account manager through app.picredits.com to request one.