Legal
HIPAA Posture
Effective August 2026
A summary of how VeloCare handles protected health information in production deployments. The full security packet, subprocessor register and BAA template are available on request.
1. Business associate posture
Velozent signs Business Associate Agreements with covered entities. No PHI reaches any subprocessor without a BAA in place; the subprocessor register (cloud infrastructure, AI model providers, communication channels, clearinghouse) is customer-visible and change-notified.
2. Minimum necessary, by construction
- The schema stores no diagnoses, medications, orders, results or clinical notes — clinical facts enter only as references.
- Role portals enumerate their data needs; marketing roles never see clinical adjacency.
- Sensitive views require a recorded purpose of use; break-glass access requires a reason and alerts compliance.
3. Technical safeguards
- TLS 1.2+ in transit, AES-256 at rest, secrets in vault.
- Append-only, hash-chained audit log retained ≥ 7 years, verified nightly.
- AI calls route only to BAA-covered endpoints, with PHI redaction before prompts and no training on tenant data.
4. Incident response
Breach classification uses the audit spine to scope exposure precisely; notification clocks are tracked in-product; tabletop exercises run twice yearly.
Questions about this policy? Contact us at hello@velozent.com or via our contact page.