HIPAA Compliance
Veridose AI is built from the ground up to support HIPAA compliance. As a platform used by licensed pharmacies — which are Covered Entities under HIPAA — we operate as a Business Associate and are committed to protecting all Protected Health Information (PHI) processed through our platform.
Business Associate Agreement (BAA)
A BAA is required before processing PHI through Veridose. We provide a standard BAA to all pharmacy customers. Request yours before going live.
Request a BAA →Our Role Under HIPAA
Under the Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act, pharmacies are Covered Entities required to protect the PHI they create, receive, maintain, or transmit. When you use Veridose to process medication check data, prescription information, or patient inputs, we act as your Business Associate.
As your Business Associate, we are contractually and legally required to:
- Use and disclose PHI only as permitted by your BAA and HIPAA
- Implement appropriate safeguards to prevent unauthorized use or disclosure
- Report any PHI breach to you within the time frames required by HIPAA
- Ensure our sub-processors are similarly bound by appropriate agreements
- Return or destroy PHI upon termination of the BAA
Technical Safeguards
Encryption in Transit
All data transmitted between your browser and Veridose servers is encrypted using TLS 1.2 or higher. We enforce HTTPS-only connections.
Encryption at Rest
All stored PHI is encrypted at rest using AES-256. Database backups are also encrypted using the same standard.
Voice Audio Deletion
Audio recorded during voice-input sessions is transmitted to our transcription processor and deleted immediately. No voice recordings are ever stored on Veridose servers.
Access Controls
Staff access is controlled by PIN-based authentication tied to individual license IDs and roles. Each staff member receives a unique credential set.
Audit Logging
All medication checks and PHI access events are logged with timestamps, user IDs, and action types. Logs are retained per HIPAA requirements.
Session Security
Sessions are managed via secure, short-lived tokens. Automatic session expiration is enforced to prevent unauthorized access on shared devices.
Administrative Safeguards
- Veridose designates a Privacy Officer and Security Officer responsible for HIPAA compliance
- All Veridose personnel with access to PHI complete HIPAA training
- Access to production systems is restricted to authorized personnel using multi-factor authentication
- We conduct annual risk assessments in accordance with the HIPAA Security Rule
- Security incidents are assessed and reported according to the Breach Notification Rule
Physical Safeguards
Veridose infrastructure is hosted on cloud providers (Amazon Web Services and Supabase) that maintain SOC 2 Type II and ISO 27001 certifications. Physical access to data center facilities is strictly controlled by our infrastructure providers, who also operate under HIPAA-compliant terms.
PHI We Process
The following types of PHI may be processed through Veridose as part of providing the Service:
- Patient medication lists and prescription information (entered or spoken by pharmacy staff)
- Drug interaction check inputs and results
- Case notes and check history logs
- Staff-entered patient identifiers (name, date of birth) when associated with a check
We do not require collection of Social Security numbers, financial data, or insurance information as part of the core platform.
Sub-Processors
We use the following sub-processors who may have access to PHI in the course of providing the Service. Each is bound by appropriate data processing agreements:
- Supabase (via AWS) — Database and authentication infrastructure
- OpenAI — AI model processing (zero data retention API agreement in place)
- Resend — Transactional email delivery (no PHI transmitted)
Breach Notification
In the event of a breach involving unsecured PHI, Veridose will notify affected Covered Entity customers without unreasonable delay and within 60 days of discovering the breach, as required by 45 CFR § 164.410. Our notification will include the information required by the Breach Notification Rule.
Patient Rights
As a Business Associate, we support Covered Entities in meeting their obligations regarding patient rights under HIPAA. If you receive a patient request for access, amendment, or accounting of disclosures related to PHI held by Veridose, contact us at privacy@veridose.io and we will cooperate promptly.
Contact
For HIPAA compliance inquiries, BAA requests, or to report a security concern:
Veridose AI, Inc.
Privacy & Compliance: privacy@veridose.io
General: hello@veridose.io