Skip to navigation

HIPAA compliance

Configure an application that uses Zep with protected health information

When building healthcare applications that handle protected health information (PHI), you must ensure that identifiers used within Zep do not expose PHI.

Zep offers Business Associate Agreements (BAAs) for Enterprise customers. Contact our Enterprise team to learn more about HIPAA-compliant deployments.

Identifier requirements

Zep generates the UUID of every user, thread, and graph. A Zep UUID contains no personally identifiable information (PII). Your application identifiers, such as patient identifiers, stay in your own database. No Zep operation accepts them.

Labels that you send to Zep must not contain PII. Labels can appear in logs, error messages, and analytics data, so PII in a label can cause accidental exposure.

LabelRequirement
User metadataDo not put email addresses, names, or patient identifiers in user metadata.
Graph name and descriptionUse descriptive text that does not contain PII.
# Correct: Zep generates an opaque UUID with no PII
zep_user = zep_client.user.create()
zep_user_uuid = zep_user.uuid_ # e.g., "550e8400-e29b-41d4-a716-446655440000"
# Incorrect: the user metadata contains PII
zep_client.user.create(metadata={"email": "[email protected]"}) # Contains email
zep_client.user.create(metadata={"patient_id": "patient-12345"}) # Contains medical record number

Mapping identifiers

Keep a secure mapping between opaque Zep UUIDs and internal user records in your own database:

# Create the Zep user. Zep generates the UUID.
zep_user = zep_client.user.create()
# Your internal patient record links to the opaque Zep user UUID
patient_record = {
"internal_patient_id": "MRN-12345",
"name": "Jane Doe",
"zep_user_uuid": zep_user.uuid_,
"zep_graph_uuid": zep_user.graph_uuid,
}
# Use the stored UUID when interacting with Zep
zep_client.user.get(patient_record["zep_user_uuid"])