Security, HIPAA & data handling

Least access. Full trail.

You are handing us work that touches patient records and practice money. These are the commitments we make about how that is handled, and the questions we expect you to ask us on the call.

A signed BAA, first

We execute a Business Associate Agreement before any protected health information is accessed. It defines what we may touch, for what purpose, and what happens when the engagement ends.

Read-only to begin

Week one is observation. Write access is granted per workflow, only once your team has seen the work and agreed to it. Bank and payment processor access stays read-only permanently.

Least privilege, by workflow

Pepper gets the narrowest access each job requires. Scheduling work does not need the ledger; reconciliation does not need clinical notes.

Minimum necessary data

We work with the minimum information needed to complete a task, and we do not move PHI out of your systems into places it does not need to go.

Encrypted, in transit and at rest

Industry-standard encryption throughout, with credentials held in a secrets manager rather than shared with people, and access revocable by you at any time.

Not used to train general models

Your patient data and your playbook are not used to train models that serve anyone else. What Pepper learns about your practice stays with your practice.

Oversight

Every action has a name on it.

Audit trail

What was accessed, what was changed, what was sent, who approved it and when — exportable, and yours.

Approval gates

You set which categories of work can proceed on their own and which wait for a person. The default is to wait.

Escalation to a human

Clinical questions, distressed patients, denials, refunds and anything unusual stop and come to your team.

No clinical advice

Pepper does not diagnose, triage or advise. It handles logistics, and says so to patients when asked.

Your data, exportable

Your playbook, logs and records export on request, at any point, without a negotiation.

Clean offboarding

Access revoked, data returned or destroyed per the BAA, and a handover document for whoever takes the work back.

Ask us these

Diligence questions we want you to ask.

If a vendor cannot answer these plainly, that is information. We will answer them in writing, and our security documentation and current certification status are shared on request under NDA.

Where is PHI stored and processed, and which subprocessors touch it?

Which model providers are used, and under what data terms?

How is access granted, reviewed and revoked — and by whom on your side?

What is the breach notification process and timeline?

What happens to our data and playbook if we leave?

Request the security pack

Our security documentation, subprocessor list and current certification status, shared under NDA.

Thank you — we will email the pack and an NDA within one business day.