Privacy & data handling
- ✓We never sell or share your data with any third party, including distributors, manufacturers, or your GPO.
- ✓We never use your data to train AI or machine-learning models, ours or anyone else's.
- ✓Your data is encrypted with AES-256 in transit and at rest, the same standard used across the financial system.
- ✓We use your data only to produce your analysis, and we purge it whenever you ask.
What we receive
To run an analysis, we work with the purchasing and contract data your health system already maintains, line items such as drug identifiers (NDCs), descriptions, unit prices, account or ship-to identifiers, and contract references. We also collect the contact details you provide when you request an analysis.
We do not need, request, or want protected health information or any patient-level data. If such data is present in a file you send, we will not use it and will work with you to remove it.
How we use it
Your data is used for a single purpose: to identify pricing discrepancies across your hospitals and to support recovering them on your behalf. We do not use it for advertising, profiling, resale, or any purpose unrelated to your engagement.
We do not train AI on your data
Our engine is built and improved on our own and licensed reference data, never on client data. Your files are not added to any training set, model, or shared benchmark. What you send us stays isolated to your engagement.
How we protect it
Data is encrypted with AES-256 in transit (TLS) and at rest. Access is restricted to the specific personnel working on your engagement, under role-based controls and audit logging. Transfers happen over a secure, access-controlled channel, never over unencrypted email.
Who can see it
Only the RX Parity team members assigned to your engagement. We do not share your data with distributors, manufacturers, GPOs, or any other outside party. When we negotiate on your behalf, we share only the specific findings you authorize, and never your underlying files.
Retention & deletion
We keep your data only as long as needed to deliver and support your analysis. You may request deletion at any time, and we will permanently purge your data from our systems and confirm when it is done.
HIPAA-aligned handling
Although we work with pricing and contract data rather than patient records, we handle all client information to HIPAA-aligned standards and will enter into a Business Associate Agreement where appropriate.
Your rights
You own your data. You can ask us what we hold, request a copy, or request deletion at any time. Reach us at privacy@rxparity.com.