HIPAA compliant, SOC 2 audited, and private AI.
Counter handles prescriptions and patient contact details, so the safeguards are built into the software.
SOC 2
Our security controls are independently audited.
HIPAA compliant
We sign a BAA with every pharmacy before any patient data moves.
Private AI
The models that rank your queue work for your pharmacy only.- Each pharmacy’s data is isolated and never pooled with other pharmacies’ data.
- Your patients’ data is never used to train models for anyone else.
- Patient data reaches an outside AI provider only under a BAA, and only when it’s configured for your account.
How we handle pharmacy data.
- What Counter reads
- Patients and their contact consent, prescriptions, fills with their adjudicated amounts, and acquisition cost. Nothing outside what ranking and outreach need.
- Agreements
- We sign a business associate agreement with every pharmacy before any patient data moves.
- Isolation
- Each pharmacy’s data is kept separate and is never pooled with other pharmacies’ data.
- AI models
- Your patients’ data is never used to train models for anyone else. It reaches an outside AI provider only under a BAA, and only when that’s configured for your account.
- Encryption
- Data is encrypted in transit and at rest.
- Patient messages
- Consent is checked per channel before each send. Messages are capped at one a day and three a week, held outside 8 a.m. to 8 p.m. store time, and leave out drug names unless the patient opted in. STOP is honored immediately, and each message records the consent it relied on.
- Your data, your call
- You can export your pharmacy’s data or have it deleted at any time.