Security & Compliance

Compliance is architecture,
not paperwork

1SyncRx was built inside a working compounding pharmacy, where HIPAA is a Tuesday, not a checkbox. Here is exactly how the platform protects every prescription it carries.

Encrypted
In transit and at rest
Role-based
Access by responsibility
Two-factor
Code to mobile or email
NPI-verified
Against the national registry

01 · HIPAA architecture

Protection in every layer a prescription touches

Encryption, access control and session discipline are not settings someone has to switch on. They are how the platform works, for every pharmacy and every prescriber, from the first sign-in.

Encrypted in transit and at rest
Every screen, every record, every message between prescriber and pharmacy.
Roles decide what each person sees
A technician, a pharmacist and an owner each get their own view. Nothing more.
Sessions guard themselves
Two-factor sign-in, automatic idle logout, lockout after failed attempts. A workstation left open in a busy clinic signs itself out.
Pharmacy admin workspace
Pharmacy Admin workspace using synthetic operational data
Original 1SyncRx product interface.

02 · The digital BAA

The BAA is a gate, not an attachment

The Business Associate Agreement is signed electronically during onboarding, and the platform enforces it. No one has to remember.

1

Presented during onboarding

The BAA appears right inside the NPI-first onboarding flow, ready to sign on screen.

2

Signed and recorded

Signature, signer and timestamp are stored with the pharmacy’s record, retrievable any day an auditor asks.

3

Unsigned means view-only

A pharmacy without a signed BAA cannot go live or handle prescriptions. The platform enforces the rule itself.

Where the data lives

Hosting
United States only
Jurisdiction
US law, end to end
Tenancy
One portal per pharmacy, fully isolated
Identity
NPI-verified via the national registry

03 · US hosting & identity

Patient data never leaves US jurisdiction

All storage and processing run on US-based infrastructure. Each pharmacy’s portal, catalog and records are its own tenant; no data is shared between pharmacies, ever.

And before anyone touches the platform, their identity is checked against the national NPI registry: pharmacies and prescribers alike.

04 · Audit trail

Who did what, when: one query, not a filing cabinet

Every action on the platform is logged with its actor and timestamp: sign-ins, edits, verifications, fills, shipments. Records are never deleted; prescriptions are placed on hold, and fill history stays intact in the pharmacy’s own RX series.

Acceptance of Terms and Privacy recorded at first sign-in
Prescriptions never deleted, only placed on hold
Clean transfer-out records when a patient moves pharmacies
Audit log · live
09:41:12Prescriber signed and sent prescription RX-20481
09:41:15System delivered RX-20481 to the participating pharmacy intake queue
10:02:37Pharmacist verified RX-20481
13:15:04Pharmacy team member marked RX-20481 filled; tracking attached
13:15:04System notified prescriber and updated order timeline
16:48:59Pharmacy team member signed in with two-factor code
Illustrative interface example. Confirm available event coverage and retention during evaluation.

Bring your compliance questions to the demo

Twenty minutes, the live platform, and every answer on screen instead of in a PDF.