HIPAA Compliance
Last updated: May 24, 2026
Verity Health is designed from the ground up for healthcare. We act as a Business Associate under HIPAA and meet or exceed the Privacy, Security, and Breach Notification Rules required of organizations handling Protected Health Information (PHI).
Business Associate Agreement
Verity Health executes a Business Associate Agreement (BAA) with every customer that processes PHI through our platform. The BAA is signed before any PHI is submitted and governs the permitted uses, safeguards, and breach notification obligations between the parties. Standard BAA terms are available for review during the contracting process.
Administrative Safeguards
- Designated Security Officer with documented responsibilities
- Workforce training on HIPAA, security, and privacy on hire and annually
- Role-based access controls with least-privilege defaults
- Background checks for personnel with PHI access
- Documented incident response and breach notification procedures
- Annual risk assessments and third-party penetration tests
Technical Safeguards
- Encryption in transit: TLS 1.2+ for all connections to our APIs and web interfaces
- Encryption at rest: AES-256 encryption for all stored PHI, including database backups
- Audit logging: Every access to PHI is logged with user, timestamp, action, and resource identifier
- Authentication: Multi-factor authentication available for all user accounts; SSO via SAML 2.0 for enterprise customers
- Network isolation: Production systems run in private VPCs with no public ingress except through authenticated API gateways
- Automatic session timeout: Idle sessions expire after a configurable period (default 15 minutes)
Physical Safeguards
Our infrastructure is hosted in SOC 2 Type II-certified data centers operated by major cloud providers (AWS, GCP) that maintain ISO 27001, HITRUST CSF, and HIPAA compliance certifications. Verity Health personnel never have direct physical access to production servers.
Breach Notification
In the unlikely event of a breach affecting PHI, Verity Health will notify the affected Covered Entity without unreasonable delay and no later than 60 days after discovery, as required by 45 CFR 164.410. Notifications include the nature of the breach, the data involved, and the corrective actions taken.
Audit and Certification Roadmap
- SOC 2 Type II — annual recertification
- HITRUST CSF — in progress, targeted for Q4 2026
- Annual third-party HIPAA risk assessment
Requesting a BAA or Compliance Documentation
Customers and prospective customers can request a standard BAA, our SOC 2 Type II report (under NDA), security questionnaire responses, or other compliance documentation by contacting compliance@verityhealth.in.
Questions? Contact legal@verityhealth.in