Security, HIPAA & data handling
You are handing us work that touches patient records and practice money. These are the commitments we make about how that is handled, and the questions we expect you to ask us on the call.
We execute a Business Associate Agreement before any protected health information is accessed. It defines what we may touch, for what purpose, and what happens when the engagement ends.
Week one is observation. Write access is granted per workflow, only once your team has seen the work and agreed to it. Bank and payment processor access stays read-only permanently.
Pepper gets the narrowest access each job requires. Scheduling work does not need the ledger; reconciliation does not need clinical notes.
We work with the minimum information needed to complete a task, and we do not move PHI out of your systems into places it does not need to go.
Industry-standard encryption throughout, with credentials held in a secrets manager rather than shared with people, and access revocable by you at any time.
Your patient data and your playbook are not used to train models that serve anyone else. What Pepper learns about your practice stays with your practice.
Oversight
What was accessed, what was changed, what was sent, who approved it and when — exportable, and yours.
You set which categories of work can proceed on their own and which wait for a person. The default is to wait.
Clinical questions, distressed patients, denials, refunds and anything unusual stop and come to your team.
Pepper does not diagnose, triage or advise. It handles logistics, and says so to patients when asked.
Your playbook, logs and records export on request, at any point, without a negotiation.
Access revoked, data returned or destroyed per the BAA, and a handover document for whoever takes the work back.
Ask us these
If a vendor cannot answer these plainly, that is information. We will answer them in writing, and our security documentation and current certification status are shared on request under NDA.
Where is PHI stored and processed, and which subprocessors touch it?
Which model providers are used, and under what data terms?
How is access granted, reviewed and revoked — and by whom on your side?
What is the breach notification process and timeline?
What happens to our data and playbook if we leave?
Our security documentation, subprocessor list and current certification status, shared under NDA.
Thank you — we will email the pack and an NDA within one business day.