Quality and safety

The rules we hold ourselves to.

CLIA-validated labs, a HIPAA-compliant stack with a chain-hash audit log, weekly OIG screening, Anti-Kickback Statute safe compensation, and a physician review on every flagged result.

Clean minimalist lab bench representing precision and quality

Lab quality

CLIA-validated, with hormone analytes validated per-analyte.

Your sample is processed by a CLIA-certified reference lab. Hormone markers on capillary matrix are held to a higher bar: per-analyte validation before any result clears into your trend chart.

CLIA certification

All labs that process Pep Club samples are certified under the Clinical Laboratory Improvement Amendments, the federal standard for clinical lab testing.

Reference ranges, optimal ranges, and LOINC mapping are committed to the portal before results release.

Per-analyte capillary validation

Fingerstick and upper-arm capillary collection is not automatically equivalent to a venous draw. For hormone panels, we require per-analyte capillary validation on our chosen device before an assay is released against our optimal ranges.

Analytes that cannot be validated on capillary matrix are routed to a venous alternative rather than reported with low confidence.

Privacy and security

A HIPAA-compliant stack, built for tamper-evident audit.

Every vendor that touches protected health information is covered by a Business Associate Agreement. Every PHI access is written to a chain-hashed audit log so any backfill or deletion is detectable.

Chain-hash audit log

Every read and write against protected health information is recorded to an append-only audit log. Each row hashes the row before it, so a tamper attempt anywhere in the chain surfaces the next time the chain is verified.

Verification runs on cadence internally; admins can re-verify on demand.

BAA chain and encryption

Every vendor that handles PHI on your behalf, including our database provider, identity provider, hosting provider, email relay, cache, and observability tools, is covered by a Business Associate Agreement.

Data is encrypted in transit and at rest. Database rows are isolated by Row Level Security policies.

Session hardening

Authenticated portal sessions idle-time-out automatically. Sensitive actions require recent authentication.

Audit transparency

The admin compliance log is visible internally to our compliance team. A third-party penetration test is planned ahead of full-scale launch.

Regulatory posture

Our commitments written down.

Health platforms attract special scrutiny for good reasons. Here is how we handle the rules that matter most to patients.

OIG exclusion screening

Our physician roster is cross-checked against the OIG List of Excluded Individuals and Entities (LEIE) at onboarding and again weekly, on an automated cron that runs every Sunday at 03:00 UTC.

Any match results in an immediate scheduling block pending compliance review.

Anti-Kickback Statute

Physicians working with The Pep Club are compensated on an hourly or per-consult basis. Compensation is never tied to prescription volume, product mix, or pharmacy routing.

The clinical entity (PC) and technology entity (MSO) are separately owned, with a Management Services Agreement between them.

Informed consent

Warm-base outreach from our affiliated pharmacy to eligible patients requires the specific authorization described by 45 CFR 164.508(a)(3). A generic pharmacy relationship is not enough.

Flagged-result SLA posture

When a marker is flagged, our posture is a licensed physician review within 24 hours. Escalation workflows ensure urgent findings route to a physician the same day.

SLA enforcement tooling and visible countdown timers land in the next milestone.

Regulatory posture. AI outputs surfaced in your portal are framed educationally. They do not constitute a diagnosis, a prescription, or a substitute for professional medical advice. Clinical decisions always flow through a U.S.-licensed physician.
State availability. The Pep Club operates only where our affiliated professional corporation has a licensed physician on roster and where our affiliated pharmacy holds an active license. We expand that footprint deliberately and disclose the current list at eligibility.
Your right to choose a pharmacy. Prescriptions written by a Pep Club physician may be filled at any pharmacy you choose. Our affiliated compounding pharmacy is the default because of the BAA, formulary, and shipping integration already in place.

Compliance that gets out of your way.

Every commitment on this page is enforced in code, not a PDF. We publish our posture so you can check it.

See panels and pricing