Trust · Compliance

HIPAA compliant AI for pharmacies — what that phrase actually means.

OneDose is built to be operated under HIPAA: BAAs on every deployment, encryption in transit and at rest, identity verification before any disclosure of prescription information, minimum-necessary access, and audit logging. But no software is HIPAA compliant by itself — HIPAA regulates organisations and their business associates, not products, and there is no HIPAA certification body.

That distinction is the most useful thing on this page. A 'HIPAA compliant' badge on a product is a category error, and it invites a buyer to believe a compliance question has been answered by a purchase.

Why can no product be HIPAA compliant by itself?

HIPAA imposes obligations on organisations — covered entities such as providers and health plans, and the business associates who handle PHI on their behalf. It does not certify software. There is no HIPAA certification body, and no product can hold a HIPAA certificate because no such certificate exists.

So “HIPAA compliant software” is at best shorthand for “software that can be deployed compliantly, by an organisation meeting its obligations, under a BAA.” At worst it is marketing designed to retire a question that has not been answered.

The practical consequence is that your compliance posture is yours. A vendor can make it straightforward or impossible; a vendor cannot make it automatic, and one implying otherwise has told you how carefully they think about this.

What does HIPAA require of an AI agent handling prescriptions?

Nothing exotic — the standard obligations, applied to a channel that happens to be a phone call or a message. A Business Associate Agreement, because the vendor handles PHI on your behalf. Identity verification before disclosure, because the phone is where a wrong disclosure is easiest. Encryption in transit and at rest, covering the call audio and the transcript, both of which are PHI. Minimum necessary, so a caller asking whether a prescription is ready hears “yes, since Tuesday” and not their medication history. An audit trail, because it is the evidence if anything is ever investigated. And access controls on the vendor’s own staff, who are people with access to PHI.

The security page covers how each of those is implemented, and what to ask us for in writing.

What can we evidence today?

Each claim with its current evidentiary status, generated from our configuration rather than maintained by hand — so it cannot drift ahead of what we can actually produce on request.

  • HIPAA compliant

    BAA on every deployment

    Evidence on request
  • SOC 2 Type II

    End-to-end encryption

    Evidence on request
  • ABDM-ready · ISO 27001

    Audit log on every action

    Evidence on request
  • Regional data residency

    IN · US · EU

    Evidence on request
  • Business Associate Agreements (BAA)

    Signed as standard

    Evidence on request
  • End-to-end encryption

    In transit and at rest

    Evidence on request
  • Full audit logs

    On every agent action

    Evidence on request

If you are running a procurement process, ask for the reports and their scope. A badge is not a report, and a report covering a different system than the one you are buying is a common and entirely legal way to display a logo that means nothing to you. That advice applies to us as much as to anyone we are being compared against.

What applies outside the United States?

A different regime, with a different regulator, different residency rules and different obligations on automated processing. HIPAA is a US federal law and governs nothing elsewhere.

You will notice this page does not print a grid of regulator names per market. That is deliberate. In several of the markets we are asked about, multiple authorities have overlapping scope and are genuinely easy to confuse — and a compliance page that names the wrong authority has done more damage than a compliance page that says less. We are not going to guess in public and hope you do not check.

So: tell us your jurisdiction and we will give you a specific answer, in writing, with the regulation named. If a vendor gives you a fluent answer about your regulator without hesitating, it is worth asking them for the citation.

Is an AI agent a regulated medical device?

It depends on what it does, and it is a real question rather than a rhetorical one. Software that provides information used for a diagnostic or therapeutic decision falls under medical-device rules in several jurisdictions — in the EU, MDR Rule 11 addresses precisely this category, and the EU AI Act layers further obligations on high-risk uses.

This is one of the reasons OneDose agents collect and escalate rather than decide. An agent that triages a symptom to a conclusion or tells a patient whether to continue a medication is doing the thing those rules are written about. Keeping the clinical determination with a clinician is a safety decision first and a regulatory one second, and the two point the same way.

If you need a formal classification answer for your jurisdiction, that is a question for your regulatory counsel rather than for a vendor’s website — and we will give them whatever technical detail they need to answer it.

Frequently asked

Is OneDose HIPAA compliant for pharmacies?
OneDose is built to be operated under HIPAA in the United States: we sign Business Associate Agreements, encrypt PHI in transit and at rest, verify identity before disclosing prescription information, apply minimum-necessary access and log every agent action. No software is HIPAA compliant by itself — HIPAA regulates covered entities and their business associates, not products, and no HIPAA certification body exists.
Does HIPAA apply outside the United States?
No. HIPAA is a US federal law. Other jurisdictions have their own regimes with different regulators, different residency rules and different obligations on automated processing — so a vendor leading with "HIPAA compliant" in a market HIPAA does not govern is answering a question you did not ask.
Which regulations apply to OneDose in our country?
Ask us, and expect a specific answer rather than a page. OneDose does not publish a grid of regulator names per market, because naming the wrong authority is a worse error in a compliance-led sale than saying nothing — and several of the markets we are asked about have multiple regulators with overlapping scope that are easy to confuse.
Is an AI follow-up agent a regulated medical device?
It depends on what it does and where. Software providing information used for a diagnostic or therapeutic decision falls under medical-device rules in several jurisdictions — EU MDR Rule 11 is written about exactly this, and the EU AI Act adds obligations on top. This is why OneDose agents collect and escalate rather than decide: the clinical determination stays with a clinician. If you need a formal classification answer for your jurisdiction, that is a question for your regulatory counsel and we will give you the technical detail they need.
Do you sign a BAA?
Yes. Ask for the document during evaluation rather than at contract stage.