Overview
NoazRX is committed to protecting the confidentiality, integrity, and availability of personal and
health-related information. This policy explains how long data is retained, how it is secured, and when it
is archived or permanently deleted, in alignment with applicable healthcare privacy requirements.
- Prescription deliveries
- Patient delivery information
- Proof of Delivery (POD)
- Chain-of-custody records
- System audit logs
Core principles
- Minimum necessary access: Only data required for operations is accessible.
- Segregation: Operational data and archival data are separated and governed independently.
- Automation: Retention and deletion are enforced by scheduled jobs, not manual actions.
- Auditability: Access, archival, and deletion events are logged.
- Security by design: Archived data is not accessible via APIs or the front end.
πΊπΈ HIPAA
United States (HIPAA)
This policy is designed to align with the HIPAA Privacy Rule and HIPAA Security Rule.
Operational retention
- Active deliveries: retained until completion
- Completed delivery operational access: 90 days
- Driver telemetry (location/status): 24β72 hours
- Temporary operational metadata: automatically purged
Archive retention (no API/UI access)
- Proof of Delivery (POD): 7 years
- Chain-of-custody records: 7 years
- Audit logs: minimum 7 years
Archiving, access controls & disposal
When operational access is no longer required, records are moved to a restricted compliance archive
that is not accessible via APIs or the front end. After legal retention periods, archived data is
permanently deleted or cryptographically destroyed. Archival and disposal actions are logged with
timestamp, reason, and policy version.
Security controls
- Role-based access and tenant scoping (pharmacy/organization boundaries)
- Audit logging for access, export, archive, and deletion events
- Separation of archival systems from operational systems
- Secure disposal and documented retention enforcement
π¨π¦ PHIPA
Canada (PHIPA)
This policy is designed to align with PHIPA and applicable pharmacy delivery record expectations.
Operational retention
- Active deliveries: retained until completion
- Completed delivery operational access: 90 days
- Driver telemetry (location/status): 24β72 hours
- Temporary operational metadata: automatically purged
Compliance archive (restricted)
- Proof of Delivery (POD): minimum 7 years
- Chain-of-custody records: minimum 7 years
- Audit logs: 7β10 years
Archiving, access controls & disposal
PHI is accessible only on a need-to-know basis and is removed from operational systems once not
required for service delivery. Archived PHI is stored in a restricted compliance archive that cannot be
accessed by drivers, pharmacies, or general platform users. When no longer required, PHI is securely
destroyed in a manner that prevents reconstruction. Disposal actions are logged and auditable.
Security controls
- Tenant and role-based separation to protect PHI access boundaries
- Audit logging to detect and investigate access events
- Restricted archival storage isolated from operational systems
- Secure disposal and documented retention enforcement
Contact
Questions about this policy or NoazRX data-handling practices?
This page describes NoazRX retention and protection practices at a high level, uses language such as
"designed to support" and "aligned with" rather than absolute guarantees, and may be updated periodically.
It is provided for general information and is not legal advice; NoazRX recommends a final review by qualified
counsel before relying on this policy in production.