PrepQ publishes its security posture, safeguards, service providers, and policies here so healthcare practices can evaluate the platform with clear, useful information before a single patient message is sent.
Control statuses are self-attested as of August 26, 2026PrepQ operates a HIPAA compliance program on HIPAA-eligible AWS infrastructure and makes a Business Associate Agreement available to every subscribing practice before any patient traffic begins.
Every answer in the content library is written by board-certified physicians, and each practice's own clinicians review and approve content before their patients receive it.
The safeguards below describe how patient data moves through PrepQ today. Statuses are self-attested and refreshed when the architecture changes.
Service providers PrepQ uses to deliver the platform. Providers that never touch patient data are marked accordingly.
There is no official government "HIPAA certification" — no company can truthfully claim one. PrepQ instead operates a HIPAA compliance program: it runs on HIPAA-eligible AWS infrastructure, encrypts data in transit and at rest, redacts identifying details before AI processing, and signs a Business Associate Agreement with every subscribing practice.
Yes. A BAA is available to every subscribing practice and is put in place before patient traffic begins. Email [email protected] to request a copy for review.
No. PrepQ delivers patient-education content that the supervising practice reviews and adopts as its own patient communications. Patients are always instructed to follow their own care team's specific guidance, and urgent-symptom messages are directed to 911 or the practice.
Patient interactions are processed and stored on HIPAA-eligible AWS infrastructure, encrypted in transit and at rest, and retained only per a defined schedule before automatic deletion. Practice routing and approved content live in Supabase. The marketing website and source code hosting never handle PHI.
Control statuses on this page are self-attested by PrepQ's founders, who operate the platform directly, and are refreshed whenever the architecture changes. Dated changes appear in the Updates section below.
Patient voice audio moved from carrier-stored recordings to an encrypted streaming pipeline — audio is processed in PrepQ's environment and no recordings persist at the telephony carrier.
The patient SMS opt-in page, with unchecked-by-default consent and full STOP/HELP disclosures, is now linked directly from the site navigation.
Retired 19 unused phone numbers across legacy carriers, reducing the attack and billing surface to a small set of actively managed lines.
PrepQ is a patient-education platform operated by PrepQ LLC, an Illinois limited liability company. PrepQ is a technology and content vendor, not a healthcare provider, and its content is education — not medical advice, diagnosis, or treatment. The subscribing practice, not the software, remains the clinical authority at all times.
If you are experiencing a medical emergency, call 911 immediately. For questions specific to your own care, contact your practice directly.
Statements on this page describe PrepQ's current architecture and practices as of the date shown above, are self-attested, and do not constitute a certification, warranty, or legal representation. Third-party names and logos are trademarks of their respective holders; their appearance here denotes a vendor relationship, not endorsement.