1. Infrastructure Standards
VeritaMed.ai is engineered for high‑fidelity healthcare environments. Our stack meets or exceeds HIPAA Security Rule requirements.
- Data at Rest: MySQL 8.0 databases with AES‑256 transparent encryption.
- Data in Transit: TLS 1.3 for all communications (API, web, and database).
- Audit Trails: Every access, transcription edit, and database query is logged via our immutable MedCare Forensic logging system.
- Infrastructure: Hosted on HIPAA‑compliant cloud providers (AWS or Azure) with 99.9% uptime targets.
- Access Control: Role‑Based Access Control (RBAC) with mandatory multi‑factor authentication (MFA) for administrative accounts.
2. Certifications & Audits
We conduct annual third‑party security audits and penetration tests. Our SOC 2 Type II report is available under NDA to enterprise customers.
3. Compliance with Virginia Law
We comply with the Virginia Consumer Data Protection Act (VCDPA) and all relevant state healthcare privacy laws. Any breach will be reported as required by state and federal law.
VeritaMed.ai, LLC – Virginia, USA
Last updated: June 10, 2026