HIPAA compliance
When building healthcare applications that handle protected health information (PHI), following proper data handling practices is essential. This guide covers the requirements for using Zep in HIPAA-compliant environments.
Understanding HIPAA compliance with Zep
The Health Insurance Portability and Accountability Act (HIPAA) sets standards for protecting sensitive patient health information. When using Zep as part of a healthcare application, you must ensure that identifiers used within the system do not expose PHI.
Zep offers Business Associate Agreements (BAAs) for Enterprise customers. A BAA is a contract that establishes the responsibilities of each party regarding PHI and is required when a covered entity works with a service provider that may access PHI.
Zep can sign BAAs for Enterprise customers. Contact our Enterprise team to learn more about HIPAA-compliant deployments and BAA options.
Identifier requirements
User IDs, thread IDs, and graph IDs in Zep must never contain personally identifiable information (PII). This requirement is critical for HIPAA compliance and good security hygiene in general.
Why this matters
Identifiers are used throughout the system for logging, debugging, and operational purposes. If these identifiers contain PII such as names, email addresses, or medical record numbers, this information could be inadvertently exposed in logs, error messages, or analytics data.
Required approach
Use opaque, randomly generated identifiers that have no inherent meaning:
Identifier requirements
Mapping identifiers
Maintain a secure mapping between your opaque Zep identifiers and your internal user records in your own database:
This approach ensures that even if Zep identifiers are logged or exposed, no PHI is compromised.
Summary
- Use opaque, randomly generated identifiers (UUIDs) for user IDs, thread IDs, and graph IDs
- Never embed PII such as names, emails, or medical record numbers in identifiers
- Maintain secure mappings between Zep identifiers and internal records in your own systems
- Contact Zep about Enterprise plans for BAA options and HIPAA-compliant deployments