PrepQ
Specialties Pricing Sign in Dashboard Schedule a Demo Sign up here
Trust Center

Your patients' information,
handled with care.

PrepQ publishes its security posture, safeguards, service providers, and policies here so healthcare practices can evaluate the platform with clear, useful information before a single patient message is sent.

Control statuses are self-attested as of August 26, 2026

Compliance

HIPAA

Self-attested program

PrepQ operates a HIPAA compliance program on HIPAA-eligible AWS infrastructure and makes a Business Associate Agreement available to every subscribing practice before any patient traffic begins.

Physician Governance

Operational

Every answer in the content library is written by board-certified physicians, and each practice's own clinicians review and approve content before their patients receive it.

Controls

The safeguards below describe how patient data moves through PrepQ today. Statuses are self-attested and refreshed when the architecture changes.

Data protection

Encryption in transit and at restPatient interactions are encrypted in transit (TLS) and at rest on AWS infrastructure.
Operational
Minimum-necessary collectionPrepQ collects only the information needed to answer each question. Usage analytics contain no PHI.
Operational
Defined retention and automatic deletionData is retained only per a defined schedule before automatic deletion.
Operational
No carrier-side voice recordingsPatient audio is streamed for processing rather than stored as recordings at the telephony carrier.
Operational

Clinical safety

PHI redaction before AI processingIdentifying details are automatically redacted from patient questions before they reach answer-generation systems, with a confidence gate on the redaction step.
Operational
Urgent-symptom escalationMessages suggesting urgent symptoms trigger an immediate instruction to call 911 or the practice rather than an AI answer.
Operational
Practice-approved answers firstResponses draw from the practice's approved library; questions outside it are referred back to the office instead of guessed at.
Operational

Access & integrity

Signed, verified webhooksInbound carrier traffic is cryptographically verified before processing; unverified requests are rejected.
Operational
Per-practice line isolationEach practice's dedicated number routes only to that practice's approved content and dashboard.
Operational
Logged and traceable interactionsEvery patient interaction is logged, timestamped, and traceable in the practice dashboard.
Operational

Subprocessors

Service providers PrepQ uses to deliver the platform. Providers that never touch patient data are marked accordingly.

AWS
Amazon Web ServicesHIPAA-eligible cloud — Lambda · Bedrock · Transcribe · Polly · Comprehend Medical · S3 / KMS · DynamoDB
Te
TelnyxPatient voice & SMS carrier
Tw
TwilioVoice & SMS carrier
Su
SupabasePractice routing & content database
VercelWebsite hostingNo PHI
Gh
GitHubSource code hostingNo PHI

Resources

FAQ

Is PrepQ HIPAA certified?

There is no official government "HIPAA certification" — no company can truthfully claim one. PrepQ instead operates a HIPAA compliance program: it runs on HIPAA-eligible AWS infrastructure, encrypts data in transit and at rest, redacts identifying details before AI processing, and signs a Business Associate Agreement with every subscribing practice.

Does PrepQ sign Business Associate Agreements?

Yes. A BAA is available to every subscribing practice and is put in place before patient traffic begins. Email [email protected] to request a copy for review.

Is PrepQ medical advice?

No. PrepQ delivers patient-education content that the supervising practice reviews and adopts as its own patient communications. Patients are always instructed to follow their own care team's specific guidance, and urgent-symptom messages are directed to 911 or the practice.

Where does patient data live?

Patient interactions are processed and stored on HIPAA-eligible AWS infrastructure, encrypted in transit and at rest, and retained only per a defined schedule before automatic deletion. Practice routing and approved content live in Supabase. The marketing website and source code hosting never handle PHI.

Are these controls continuously monitored?

Control statuses on this page are self-attested by PrepQ's founders, who operate the platform directly, and are refreshed whenever the architecture changes. Dated changes appear in the Updates section below.

Updates

Security · August 2026
Streaming media pipeline

Patient voice audio moved from carrier-stored recordings to an encrypted streaming pipeline — audio is processed in PrepQ's environment and no recordings persist at the telephony carrier.

Compliance · August 2026
SMS consent made one click from the homepage

The patient SMS opt-in page, with unchecked-by-default consent and full STOP/HELP disclosures, is now linked directly from the site navigation.

Operations · August 2026
Phone number fleet consolidated

Retired 19 unused phone numbers across legacy carriers, reducing the attack and billing surface to a small set of actively managed lines.