HIPAA Compliance

HIPAA Compliance

Last Updated: August 2026

Veridose AI is built from the ground up to support HIPAA compliance. As a platform used by licensed pharmacies — which are Covered Entities under HIPAA — we operate as a Business Associate and are committed to protecting all Protected Health Information (PHI) processed through our platform.

Business Associate Agreement (BAA)

A BAA is required before processing PHI through Veridose. We provide a standard BAA to all pharmacy customers. Request yours before going live.

Request a BAA →

Our Role Under HIPAA

Under the Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act, pharmacies are Covered Entities required to protect the PHI they create, receive, maintain, or transmit. When you use Veridose to process medication check data, prescription information, or patient inputs, we act as your Business Associate.

As your Business Associate, we are contractually and legally required to:

Technical Safeguards

Encryption in Transit

All data transmitted between your browser and Veridose servers is encrypted using TLS 1.2 or higher. We enforce HTTPS-only connections.

Encryption at Rest

All stored PHI is encrypted at rest using AES-256. Database backups are also encrypted using the same standard.

Voice Audio Deletion

Audio recorded during voice-input sessions is transmitted to our transcription processor and deleted immediately. No voice recordings are ever stored on Veridose servers.

Access Controls

Staff access is controlled by PIN-based authentication tied to individual license IDs and roles. Each staff member receives a unique credential set.

Audit Logging

All medication checks and PHI access events are logged with timestamps, user IDs, and action types. Logs are retained per HIPAA requirements.

Session Security

Sessions are managed via secure, short-lived tokens. Automatic session expiration is enforced to prevent unauthorized access on shared devices.

Administrative Safeguards

Physical Safeguards

Veridose infrastructure is hosted on cloud providers (Amazon Web Services and Supabase) that maintain SOC 2 Type II and ISO 27001 certifications. Physical access to data center facilities is strictly controlled by our infrastructure providers, who also operate under HIPAA-compliant terms.

PHI We Process

The following types of PHI may be processed through Veridose as part of providing the Service:

We do not require collection of Social Security numbers, financial data, or insurance information as part of the core platform.

Sub-Processors

We use the following sub-processors who may have access to PHI in the course of providing the Service. Each is bound by appropriate data processing agreements:

Breach Notification

In the event of a breach involving unsecured PHI, Veridose will notify affected Covered Entity customers without unreasonable delay and within 60 days of discovering the breach, as required by 45 CFR § 164.410. Our notification will include the information required by the Breach Notification Rule.

Patient Rights

As a Business Associate, we support Covered Entities in meeting their obligations regarding patient rights under HIPAA. If you receive a patient request for access, amendment, or accounting of disclosures related to PHI held by Veridose, contact us at privacy@veridose.io and we will cooperate promptly.

Contact

For HIPAA compliance inquiries, BAA requests, or to report a security concern:

Veridose AI, Inc.
Privacy & Compliance: privacy@veridose.io
General: hello@veridose.io