HIPAA compliance
When building healthcare applications that handle protected health information (PHI), you must ensure that identifiers used within Zep do not expose PHI.
Zep offers Business Associate Agreements (BAAs) for Enterprise customers. Contact our Enterprise team to learn more about HIPAA-compliant deployments.
Identifier requirements
Zep generates the UUID of every user, thread, and graph. A Zep UUID contains no personally identifiable information (PII). Your application identifiers, such as patient identifiers, stay in your own database. No Zep operation accepts them.
Labels that you send to Zep must not contain PII. Labels can appear in logs, error messages, and analytics data, so PII in a label can cause accidental exposure.
Mapping identifiers
Keep a secure mapping between opaque Zep UUIDs and internal user records in your own database: