← Back to Home

Security

Security overview · Controls are reviewed as the service evolves
Security is a shared responsibility. This page summarizes the current design and operating expectations; it is not a certification, guarantee, or substitute for an executed agreement or customer risk assessment.

Data-minimizing architecture

Supported pharmacy reports are designed to be parsed in the authorized user's browser. Direct patient and prescriber identifiers and the local re-association map are intended to remain in browser memory. The authenticated application sends a versioned, allowlisted analytical projection with run-scoped opaque tokens to protected compute. Unexpected fields and raw-file payloads are rejected.

Client-controlled values and analytical combinations may still be sensitive or constitute PHI. Data minimization reduces exposure but does not by itself establish de-identification or HIPAA compliance.

Access and tenant controls

RxRecon Pro uses invite-only named administrator accounts. Credentials may not be shared. Authentication, active organization membership, current legal acceptance, entitlement, and monthly usage authorization are designed to be checked before protected reconciliation. Tenant identity is resolved from the authenticated account rather than trusted from a browser-supplied organization claim.

Transport, validation, and logging

Hosted traffic is served over HTTPS. Protected analytical requests require authentication and strict schema validation. Application and infrastructure logging should contain operational metadata rather than pharmacy report contents, patient identifiers, raw request bodies, or analytical rows. Support requests must use synthetic or appropriately de-identified examples.

Customer responsibilities

Each pharmacy remains responsible for endpoint security, supported browsers, authorized workforce access, source-system controls, credential protection, minimum-necessary use, and promptly reporting suspected compromise. Do not submit PHI through Request Access, Stripe checkout, ordinary email, or any channel not expressly approved for PHI.

Report a security concern

Report suspected vulnerabilities, unauthorized access, or account compromise to ADMIN@RXRECONPRO.COM. Include the affected URL, date and time, and steps to reproduce, but do not include PHI, credentials, pharmacy reports, exploit code that accesses another party's data, or other sensitive records.