Security
Data-minimizing architecture
Supported pharmacy reports are designed to be parsed in the authorized user's browser. Direct patient and prescriber identifiers and the local re-association map are intended to remain in browser memory. The authenticated application sends a versioned, allowlisted analytical projection with run-scoped opaque tokens to protected compute. Unexpected fields and raw-file payloads are rejected.
Client-controlled values and analytical combinations may still be sensitive or constitute PHI. Data minimization reduces exposure but does not by itself establish de-identification or HIPAA compliance.
Access and tenant controls
RxRecon Pro uses invite-only named administrator accounts. Credentials may not be shared. Authentication, active organization membership, current legal acceptance, entitlement, and monthly usage authorization are designed to be checked before protected reconciliation. Tenant identity is resolved from the authenticated account rather than trusted from a browser-supplied organization claim.
Transport, validation, and logging
Hosted traffic is served over HTTPS. Protected analytical requests require authentication and strict schema validation. Application and infrastructure logging should contain operational metadata rather than pharmacy report contents, patient identifiers, raw request bodies, or analytical rows. Support requests must use synthetic or appropriately de-identified examples.
Customer responsibilities
Each pharmacy remains responsible for endpoint security, supported browsers, authorized workforce access, source-system controls, credential protection, minimum-necessary use, and promptly reporting suspected compromise. Do not submit PHI through Request Access, Stripe checkout, ordinary email, or any channel not expressly approved for PHI.
Report a security concern
Report suspected vulnerabilities, unauthorized access, or account compromise to ADMIN@RXRECONPRO.COM. Include the affected URL, date and time, and steps to reproduce, but do not include PHI, credentials, pharmacy reports, exploit code that accesses another party's data, or other sensitive records.