We built Scripta for pharmacies that handle the most sensitive data in healthcare. Security isn't a feature we added — it's the foundation we started with.
Our HIPAA compliance isn't bolted on after the fact. It's the architectural foundation that every other decision is built on top of.
Scripta runs on AWS Bedrock, Amazon's HIPAA-eligible managed AI service, with an active Business Associate Agreement on file. All AI inference happens within the BAA boundary. Data is encrypted in transit and at rest. No patient data is persisted after processing. We chose AWS Bedrock specifically because it provides HIPAA-eligible access to frontier AI models without requiring us to manage model infrastructure or compromise on compliance.
Scripta is designed so patient identifiers never leave your pharmacy's computer. Only clinical fields — drug, sig, quantity, dates — are sent to our server. Names, dates of birth, and addresses stay on your machine.
Clinical fields only — the minimum needed to process a prescription:
Patient identifiers are stripped locally before any data leaves your machine:
Every pharmacy gets isolated credentials. No shared secrets, no shared infrastructure.
Each pharmacy receives unique API credentials. Keys are rotatable, revocable, and scoped to that pharmacy's data only.
AWS IAM policies follow the principle of least privilege. Each service component can only access the resources it needs to function — nothing more.
Credentials are never shared between pharmacies, environments, or team members. Secrets are managed through AWS Secrets Manager with automatic rotation.
Every prescription Scripta touches produces a self-contained audit record — one record per Rx, designed so a compliance reviewer can see exactly what happened without any specialized tools.
Each record captures the full story of one prescription:
Patient identifiers are automatically redacted at write time — not after the fact, but before the record is created:
If a PHI field is present, it is replaced with a redacted placeholder so auditors can confirm the field existed without ever seeing the value.
Every prescription gets its own self-contained audit record — readable without specialized tools. Your compliance team can review any Rx in seconds.
Find any audit record quickly. Search by date range, drug, or outcome. Aggregate stats show clean vs. flagged fills at a glance.
Every record documents exactly which data crossed the network and which stayed local — a provable record that PHI never left your pharmacy.
Get a summary of every error Scripta caught — hourly, daily, or on your own schedule. Delivered to Microsoft Teams, Discord, email, or wherever your team already communicates. No extra logins, no dashboards to check.
We plan for the worst so our pharmacy partners don't have to. Clear timelines, no ambiguity.
Automated. Continuous monitoring via CloudWatch detects anomalies, errors, and potential security events in real time.
<1 hour. Affected services are isolated immediately. Pharmacy operations continue uninterrupted — Scripta can be disabled instantly with no side effects.
<24 hours. Affected pharmacy partners are notified with a clear description of the incident, its scope, and any actions required on their end.
<72 hours. Root cause analysis begins immediately. Preliminary findings are shared with affected partners within three business days.
<7 days. Remediation is implemented, verified, and documented. A final incident report is provided to all affected partners.
A complete list of third parties that process data on behalf of Scripta Health.
| Provider | Purpose | Data Access |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, AWS Bedrock (AI inference), CloudWatch (monitoring) | Clinical fields only — encrypted in transit and at rest, BAA active |
| AI model inference (via AWS Bedrock) | Frontier AI models for prescription processing, accessed exclusively through AWS Bedrock's managed interface | Clinical fields only — accessed within the AWS Bedrock BAA boundary, no data persisted after processing |
| GitHub | Source code management | Source code only — no customer data, no clinical data, no PHI |
We offer a Trust Packet (NDA-gated) with full architecture documentation, data flow diagrams, BAA details, and our security controls matrix. Scribe writes. Sentinel watches. You verify.
Request Trust Packet