Back to Home

Breach Response Plan

This Breach Response Plan outlines the procedures VeritaMed.ai follows in the event of a suspected security incident involving Protected Health Information (PHI), in compliance with the HIPAA Breach Notification Rule (45 CFR § 164.400–414).

1. Detection & Triage

All security events are logged in our immutable MedCare Audit Logs. Suspicious activity triggers an immediate alert to our security team.

2. Containment

The affected cloud instance or server node is isolated from the network. Access credentials are revoked, and temporary failover systems are activated if necessary.

3. Assessment & Forensic Review

A forensic investigation determines the scope of unauthorized access, the PHI involved, and the cause of the breach. All findings are documented.

4. Notification

Affected Covered Entities (healthcare providers) are notified within 72 hours of breach discovery. The notification includes: a description of the breach, types of PHI involved, steps taken to mitigate harm, and contact information for further inquiries. If required by law, the HHS and media will also be notified.

5. Remediation

After the incident, we harden access controls, rotate all API keys and credentials, and conduct a post‑incident security audit. Any vulnerabilities are patched within 48 hours.

6. Documentation & Review

All breach response activities are documented and retained for at least six years. The incident is reviewed quarterly to improve security measures.

VeritaMed.ai, LLC – Virginia, USA

Last updated: June 10, 2026