When building healthcare applications that handle protected health information (PHI), you must ensure that identifiers used within Zep do not expose PHI.
Zep offers Business Associate Agreements (BAAs) for Enterprise customers. Contact our Enterprise team to learn more about HIPAA-compliant deployments.
To maintain HIPAA compliance when using Zep, user IDs, thread IDs, and graph IDs must not contain personally identifiable information (PII). Identifiers appear in logs, error messages, and analytics data, so embedding PII in them risks inadvertent exposure.
Maintain a secure mapping between opaque Zep identifiers and internal user records in your own database: