Compliance
HIPAA & BAA Statement
Last updated: June 2026
Porto MD takes the privacy and security of health information seriously. This statement explains how we approach the Health Insurance Portability and Accountability Act (HIPAA), Protected Health Information (PHI), and Business Associate Agreements (BAAs).
PHI is gated by default
Porto MD’s core marketplace is designed to operate using business and order information rather than patient PHI. Features that would involve real patient data are disabled by default and remain off until the required legal agreements and technical safeguards are in place.
Business Associate Agreements
Where Porto MD would create, receive, maintain, or transmit PHI on behalf of a covered entity (such as a clinic or provider), the parties enter into a Business Associate Agreement before any such PHI is handled. The BAA governs permitted uses, safeguards, breach notification, and the responsibilities of each party.
Safeguards
Our technical controls include role-based access, row-level database security that walls off each organization’s data, encryption of data in transit, private storage for documents, and audit logging of activity across the platform. A platform-level control keeps PHI features off until compliance is confirmed.
Suppliers and pharmacies
Suppliers and pharmacies receive only the information necessary to fulfill their assigned orders. They never see another organization’s data, pricing, margins, or commissions.
Not legal advice
This statement describes our approach and is not legal advice or a substitute for a signed BAA. Clinics and providers should consult their own compliance counsel. To request a BAA, email compliance@portomd.com.