Back to Home

Security & Compliance Statement

1. Infrastructure Standards

VeritaMed.ai is engineered for high‑fidelity healthcare environments. Our stack meets or exceeds HIPAA Security Rule requirements.

  • Data at Rest: MySQL 8.0 databases with AES‑256 transparent encryption.
  • Data in Transit: TLS 1.3 for all communications (API, web, and database).
  • Audit Trails: Every access, transcription edit, and database query is logged via our immutable MedCare Forensic logging system.
  • Infrastructure: Hosted on HIPAA‑compliant cloud providers (AWS or Azure) with 99.9% uptime targets.
  • Access Control: Role‑Based Access Control (RBAC) with mandatory multi‑factor authentication (MFA) for administrative accounts.

2. Certifications & Audits

We conduct annual third‑party security audits and penetration tests. Our SOC 2 Type II report is available under NDA to enterprise customers.

3. Compliance with Virginia Law

We comply with the Virginia Consumer Data Protection Act (VCDPA) and all relevant state healthcare privacy laws. Any breach will be reported as required by state and federal law.

VeritaMed.ai, LLC – Virginia, USA

Last updated: June 10, 2026