> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs-beta.getzep.com/v4/hipaa-compliance/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs-beta.getzep.com/_mcp/server. # HIPAA compliance > Guidelines for using Zep in HIPAA-compliant applications When building healthcare applications that handle protected health information (PHI), you must ensure that identifiers used within Zep do not expose PHI. > **Info** > > Zep offers Business Associate Agreements (BAAs) for Enterprise customers. [Contact our Enterprise team](https://www.getzep.com/enterprise) to learn more about HIPAA-compliant deployments. ## Identifier requirements Zep generates the UUID of every user, thread, and graph. A Zep UUID contains no personally identifiable information (PII). Your application identifiers, such as patient identifiers, stay in your own database. No Zep operation accepts them. Labels that you send to Zep must not contain PII. Labels can appear in logs, error messages, and analytics data, so PII in a label can cause accidental exposure. | Label | Requirement | | ------------------------------ | --------------------------------------------------------------------------- | | User `metadata` | Do not put email addresses, names, or patient identifiers in user metadata. | | Graph `name` and `description` | Use descriptive text that does not contain PII. | ```python # Correct: Zep generates an opaque UUID with no PII zep_user = zep_client.user.create() zep_user_uuid = zep_user.uuid_ # e.g., "550e8400-e29b-41d4-a716-446655440000" # Incorrect: the user metadata contains PII zep_client.user.create(metadata={"email": "john.doe@hospital.com"}) # Contains email zep_client.user.create(metadata={"patient_id": "patient-12345"}) # Contains medical record number ``` ## Mapping identifiers Keep a secure mapping between opaque Zep UUIDs and internal user records in your own database: ```python # Create the Zep user. Zep generates the UUID. zep_user = zep_client.user.create() # Your internal patient record links to the opaque Zep user UUID patient_record = { "internal_patient_id": "MRN-12345", "name": "Jane Doe", "zep_user_uuid": zep_user.uuid_, "zep_graph_uuid": zep_user.graph_uuid, } # Use the stored UUID when interacting with Zep zep_client.user.get(patient_record["zep_user_uuid"]) ``` > Configure an application that uses Zep with protected health information