Our status, stated plainly.
SampliFi is a proof of concept. This page says what is in place today, what is planned, and how patient information is handled.
| Area | Today | Planned |
|---|---|---|
| HIPAA | Program design stage | Roles defined per contract, authorization templates and a risk analysis |
| State consumer-health-data laws | Not collecting consumer health data | A homepage policy link and state-specific terms |
| De-identification | Design only | An Expert Determination, before production data |
| SOC 2 | No report | A Type 1 report is planned before production data |
| HITRUST | Not pursued | If customers require it |
| HIPAA Security Rule update | Still a proposed rule | Multi-factor sign-in, encryption and an asset inventory |
What reaches a manufacturer.
- Every order, in aggregate
- Counts, rates and closed-status reasons; days from order to close and to shipment; product, strength and payer type, by month. Groups under 11 are hidden.
- Prescribers, identified
- NPI, name, city, state and ZIP from the order, with new prescriptions and what happened to them, per prescriber. Prescriber-level reporting is for brand and program teams, not field-rep targeting.
- Patient-level detail, with authorization
- Order-level rows and lookup by patient ID or order number, only for patients whose authorization is on file, only for named program-operations roles, and never for sales teams.
- Never shown to a manufacturer
- Identified order-level rows (patient ID, order number, exact dates) for patients without an authorization, and anything that could tie a journey token back to a person.
What the record holds.
The partner pharmacy’s order feed has 28 fields about each order: dates, status, product and quantity, the prescriber, the pharmacy, payer type and fill type. SampliFi adds its own consent record (authorized or not, date, version, revoked date), and the manufacturer supplies its consignment records.
What it doesn’t contain
- Patient name, date of birth, age, sex, address or contact details
- Diagnosis
- The date a prescription was written
- Delivery or receipt dates, carriers and lot numbers
- Rx numbers, fill numbers and days’ supply
How patient information is handled.
How journeys are shown
On this site, a patient’s journey is shown with a random token in place of any ID, dates generalized to the month and days counted from the order. Groups under 11 are hidden. De-identified journeys assume an Expert Determination, planned before production data.
This website
samplifi.org loads its fonts and scripts from SampliFi’s own servers. Page visits are logged by our own server.
Questions from your legal or privacy team?
Send them to us and we’ll answer them in writing.
