Compliance & Trust

Built for regulated environments from day one.

InteractSafe is designed around data minimalism, conservative clinical standards, and transparent sourcing. Here's what B2B partners in healthcare need to know.

HIPAA Scope

Not a covered entity. Not in HIPAA scope.

Under HIPAA, a "covered entity" is a health plan, healthcare clearinghouse, or healthcare provider that electronically transmits health information in connection with covered transactions. InteractSafe is none of these.

More importantly, InteractSafe does not collect, store, or transmit protected health information (PHI). The interaction checker is anonymous and session-based — no names, no dates of birth, no insurance identifiers, no medication histories are stored.

This means partners who embed the InteractSafe widget are not creating a data-sharing arrangement that involves PHI, and there is no Business Associate Agreement (BAA) required on our end. That said, partners should consult their own compliance counsel regarding their broader data practices.

Bottom line: InteractSafe does not store or transmit PHI. The widget is education infrastructure, not a health record system.

Data Policy

Minimal data. Maximum transparency.

What we collect

Anonymized aggregate usage analytics (optional, partner-controlled). Standard server logs via Cloudflare (IP anonymized). No cookies beyond essential session function.

What we don't collect

No user accounts. No medication data stored at the user level. No names, emails, or identifiers from the checker tool. No third-party advertising trackers.

Contact form only

The only email we collect is from voluntary B2B contact form submissions. These are used solely to respond to partner inquiries.

Technical Infrastructure

Secure, fast, and minimal by design

🔒

HTTPS Everywhere

All pages and the widget endpoint are served over HTTPS. No unencrypted connections.

☁️

Cloudflare Hosted

All static assets and the main application are served via Cloudflare's global edge network — fast, DDoS-resistant, highly available.

📭

No Third-Party Ads

No advertising SDKs, no pixel trackers, no retargeting scripts. InteractSafe does not run advertising and does not allow advertisers to influence content.

🔁

Session-Only Interactions

Medication selections in the checker exist only for the active session. Nothing is written to storage after the tab closes.

Medical-Legal Stance

Education-only. Clearly framed.

All InteractSafe content — on the main site and in licensed deliverables — is framed explicitly as educational reference material, not medical advice. Every guide includes a clear disclaimer directing patients to consult their prescriber.

Our editorial philosophy is conservative by design: we report what the evidence shows, acknowledge where evidence is limited, and never extrapolate beyond what peer-reviewed sources support.

  • No medical advice claims in any content
  • No specific dosing recommendations
  • No "absolutely contraindicated" language — we use "high-risk, avoid without specialist approval"
  • Prescriber consultation recommended throughout
  • Composite case examples disclosed as illustrative, not clinical
Editorial Standards

Source hierarchy and review process.

1.
Primary sources only

FDA official drug labeling, NIH databases (PubMed, MedlinePlus), and peer-reviewed research. Never commercial health websites, blogs, or AI-generated content without primary source backing.

2.
Pharmacist review

Every interaction profile is reviewed for clinical accuracy and conservative safety bias by Sanford A. Orloff, RPh (ret), NPI 1518289974 — 40+ years of clinical pharmacy experience.

3.
Ongoing updates

Source dates are verified on every content update. Licensed partners receive notifications when guides are updated due to new labeling changes or research.

4.
No commercial influence

No advertiser relationships. No sponsored content. No commercial health website sourcing. InteractSafe does not allow commercial interests to influence editorial decisions.

Data Flow

What happens when a patient uses the widget

1
Patient opens partner site

The embedded widget loads from Cloudflare CDN over HTTPS. No cookies set beyond session function.

2
Patient selects substances

Selections are held in browser session memory only — not written to any database, cookie, or local storage.

3
Interaction result displayed

The pharmacist-reviewed guide for that combination is returned and displayed. No individual check is logged against an identity.

4
Optional: aggregate analytics

If the partner has opted into aggregate analytics, a count of interaction type (not identity) is incremented — e.g., "GLP-1 + cannabis: +1." No individual record is created.

No PHI ever stored

At no point does InteractSafe store, transmit, or process any information that could identify an individual or constitute protected health information.

Questions about compliance for your specific use case?

Contact us directly with your compliance questions — we'll give you a straight answer or connect you with the right resource.