This Breach Response Plan outlines the procedures VeritaMed.ai follows in the event of a suspected security incident involving Protected Health Information (PHI), in compliance with the HIPAA Breach Notification Rule (45 CFR § 164.400–414).
All security events are logged in our immutable MedCare Audit Logs. Suspicious activity triggers an immediate alert to our security team.
The affected cloud instance or server node is isolated from the network. Access credentials are revoked, and temporary failover systems are activated if necessary.
A forensic investigation determines the scope of unauthorized access, the PHI involved, and the cause of the breach. All findings are documented.
Affected Covered Entities (healthcare providers) are notified within 72 hours of breach discovery. The notification includes: a description of the breach, types of PHI involved, steps taken to mitigate harm, and contact information for further inquiries. If required by law, the HHS and media will also be notified.
After the incident, we harden access controls, rotate all API keys and credentials, and conduct a post‑incident security audit. Any vulnerabilities are patched within 48 hours.
All breach response activities are documented and retained for at least six years. The incident is reviewed quarterly to improve security measures.
VeritaMed.ai, LLC – Virginia, USA
Last updated: June 10, 2026