Security and data handling
PsychRX is a restricted staff education and office-support system. This page describes the current operating boundary, not a certification or legal opinion.
Where information goes
- Account sessions, conversations, preferences, and office notes are stored on private PsychRX infrastructure.
- Assistant processing stays within the private PsychRX environment unless web search is deliberately enabled.
- If web search is enabled, the search query is sent to external search providers and selected public pages are retrieved.
What PsychRX is not
- It is not an electronic health record or a designated medical-record repository.
- It does not independently diagnose, prescribe, authorize treatment, or replace licensed clinical judgment.
- It is not an emergency system. Follow office emergency procedures and contact the responsible clinician.
Authorized use
- Use only an individually authorized account. Do not share passwords or leave an authenticated device unattended.
- Use placeholders and de-identified clinical facts for drafts, teaching, and knowledge questions.
- Verify medication, diagnostic, legal, regulatory, and clinical decisions against authoritative sources and office policy.
- Enable web search only for de-identified questions that are appropriate to send to public search providers.
Storage and retention
Conversation history and explicit preferences persist until deleted or removed under an adopted retention policy. Signing out or allowing a login session to expire does not delete saved conversations. Authorized administrators may access system records for security, maintenance, recovery, and incident response.
Security incidents
Stop using PsychRX and notify the practice owner or designated security contact immediately if patient-identifying information is entered, an account or device may be compromised, information appears under the wrong account, or unexpected disclosure or system behavior occurs.
HIPAA readiness requires administrative, physical, and technical safeguards, a documented risk analysis, workforce policies and training, incident and breach procedures, contingency planning, and appropriate agreements with any service provider that handles protected health information. Local hosting reduces third-party processing but does not, by itself, establish compliance.