Request demo access

Our status, stated plainly.

SampliFi is a proof of concept. This page says what is in place today, what is planned, and how patient information is handled.

Status as of October 2026
AreaTodayPlanned
HIPAAProgram design stageRoles defined per contract, authorization templates and a risk analysis
State consumer-health-data lawsNot collecting consumer health dataA homepage policy link and state-specific terms
De-identificationDesign onlyAn Expert Determination, before production data
SOC 2No reportA Type 1 report is planned before production data
HITRUSTNot pursuedIf customers require it
HIPAA Security Rule updateStill a proposed ruleMulti-factor sign-in, encryption and an asset inventory

What reaches a manufacturer.

Every order, in aggregate
Counts, rates and closed-status reasons; days from order to close and to shipment; product, strength and payer type, by month. Groups under 11 are hidden.
Prescribers, identified
NPI, name, city, state and ZIP from the order, with new prescriptions and what happened to them, per prescriber. Prescriber-level reporting is for brand and program teams, not field-rep targeting.
Patient-level detail, with authorization
Order-level rows and lookup by patient ID or order number, only for patients whose authorization is on file, only for named program-operations roles, and never for sales teams.
Never shown to a manufacturer
Identified order-level rows (patient ID, order number, exact dates) for patients without an authorization, and anything that could tie a journey token back to a person.

What the record holds.

The partner pharmacy’s order feed has 28 fields about each order: dates, status, product and quantity, the prescriber, the pharmacy, payer type and fill type. SampliFi adds its own consent record (authorized or not, date, version, revoked date), and the manufacturer supplies its consignment records.

What it doesn’t contain

  • Patient name, date of birth, age, sex, address or contact details
  • Diagnosis
  • The date a prescription was written
  • Delivery or receipt dates, carriers and lot numbers
  • Rx numbers, fill numbers and days’ supply

How patient information is handled.

How journeys are shown

On this site, a patient’s journey is shown with a random token in place of any ID, dates generalized to the month and days counted from the order. Groups under 11 are hidden. De-identified journeys assume an Expert Determination, planned before production data.

Patient authorization

Patients decide whether to authorize sharing of patient-level detail. Patient-level views include only patients whose authorization is on file, and an authorization can be revoked: how to change a sharing choice.

This website

samplifi.org loads its fonts and scripts from SampliFi’s own servers. Page visits are logged by our own server.

Privacy notice (draft)

Questions from your legal or privacy team?

Send them to us and we’ll answer them in writing.