§ 01Compliance-first health commerce
HealthDash is the operating backbone for peptide labs, supplement brands, and wellness clinics. Inventory, ordering, and customer records — wired into HIPAA-track infrastructure from day one.
Compliance Ledger
Sample order
Verified§ 02Built for the products you sell
Peptides, compounded medications, and supplements aren't standard e-commerce SKUs. HealthDash treats them like clinical inventory: lot-tracked, state-gated, prescription-aware, and recall-ready.
Lot/batch tracking, sterile-fill metadata, expiry windows, prescriber on file, state-by-state shipping rules.
503A / 503B aware
Subscription refills, multi-strength variants, FDA disclaimers wired into product pages, ingredient sheets.
GMP-friendly
Healthie integration, intake-to-order linking, clinician-specific catalogs, encrypted notes per record.
Healthie-ready
In-clinic POS for protocols, customer chart-of-services, location-scoped inventory and reporting.
Multi-location
§ 03Capabilities
Sixteen modules out of the box. Every one of them assumes the data they touch may be PHI, and acts accordingly.
Per-lot expiry, recall paths, and chain-of-custody on every unit.
Block by state, age, or required prescription before checkout.
Pull authorizations, push fulfillment status, link orders to charts.
Field-level encryption with rotated keys; safe to store identifiers.
Refill schedules tied to authorizations, with auto-pause on expiry.
Capture compounding metadata and ship docs with every order.
Every read, write, and admin action retained six years.
Stock pooled or scoped by clinic, with location-specific reporting.
Track every subprocessor, BAA status, and renewal date in one place.
§ 04Compliance posture
We won't pretend HealthDash is HIPAA-certified — no SaaS truthfully is. What we will say: every architectural decision was made on the HIPAA-track. BAA-covered hosting, encrypted at rest and in transit, least-privilege access, and audit logs that survive a breach investigation.
Read our compliance briefDigitalOcean — BAA on file. Managed Postgres, Spaces, and Valkey assigned to a dedicated HealthDash project.
ActiveTLS in transit (sslmode=require, rediss://). Fernet keyring at the column level for PHI-bearing fields.
ActiveRBAC with org scoping; cross-tenant reads structurally impossible. MFA + automatic session timeout planned.
Phase 2Append-only log of authentication, ePHI reads/writes, and admin actions — 6-year retention.
Phase 2Annual NIST 800-30 review with documented data flows, threats, and mitigations per HIPAA §164.308.
Phase 3Documented escalation, 24–72h client notification window, post-mortems retained 6 years.
Phase 3Your brand here
Powered by HealthDash
Active subs
1,284
+8.3%
Lots in inventory
37
12 expiring
Auth refills due
146
this week
Recent activity
View all
Product · variant A
Order received
Product · variant B
Refill authorization
Product · variant C
Lot received
§ 05White-label
Run HealthDash as the engine behind your own peptide store, clinic portal, or compounding pharmacy. Your domain, your colors, your logo — our compliance, our infrastructure, our SDK.
§ 06Talk to us
Demos run with one of our solutions engineers — never a bot. We start with your products, regulators, and downstream integrations, then map a 30-day path to launch.