Encryption
- All data is encrypted in transit using TLS 1.2+
- All data is encrypted at rest on our database and storage servers
- Patient access PINs are hashed before storage
- JWT tokens are signed with a secure secret and expire after 24 hours
QR Rx is engineered to meet HIPAA from the first patient record onward. Encryption, BAA-covered infrastructure, role-based access, audit logging, and a full subprocessor disclosure live here so a procurement team can finish their review in one read.
A subprocessor is a third party we use to run the platform. We disclose every one, its function, the data classification, and BAA status. PHI = Protected Health Information; "BAA signed" means we have a Business Associate Agreement on file with that vendor; "BAA not required" means the vendor does not process PHI by architectural design (procedure-level content only, or billing-only data).
LAST UPDATED · MAY 1, 2026 · subscribe to changes
Application hosting + Postgres database
USLogo + asset storage, provider data snapshots
USTransactional email delivery (HIPAA-covered)
USSMS delivery (care plan links + reminders)
USPatient Q&A + template parsing (procedure content only, no PHI)
USCare plan translation (procedure content only, no PHI)
US / globalSubscription billing + payment processing
US / globalNeed our DPA, security questionnaire (CAIQ / SIG), or vendor-risk packet? Email trust@qrrx.io and we'll send the latest. We respond within one business day.