Documentation Index
Fetch the complete documentation index at: https://docs.veridianhp.com/llms.txt
Use this file to discover all available pages before exploring further.
Data handling
This page is a plain-English summary of what data Veridian collects, where it lives, how long it’s kept, and how it gets deleted.What we collect
| Category | Source | Purpose |
|---|---|---|
| Practice account info | Dashboard | Authentication, support, billing. |
| API keys (fingerprint only) | Generated by Veridian | Authentication and audit. |
| Invoice identifiers, amounts | Practice API calls | Payment processing. |
| Patient first and last name | Practice API calls | Render Bridge, send receipt. |
| Bank connection (via partner) | Patient through Bridge | Initiate ACH transfer. |
| Webhook delivery logs | Generated by Veridian | Reliability and replay. |
| Audit log entries | Generated by Veridian | Tamper-evident record of actions. |
What we never collect
- Diagnosis or procedure codes
- Clinical notes or treatment information
- Raw bank credentials (these stay with our bank-connection partner)
- Card numbers (Veridian is ACH-first)
Where data lives
All Veridian production data is hosted in the United States. Sub-processors that handle PHI on our behalf are listed in our security package, available to practices on request.Retention
| Data | Default retention |
|---|---|
| Active session records | Until terminal state. |
| Settled payment records | 7 years (financial record requirements). |
| Audit log entries | 7 years (tamper-evident). |
| Webhook delivery logs | 90 days. |
| Dashboard session/login logs | 1 year. |
| Revoked API keys (fingerprint) | Indefinite for audit reconstruction. |
Deletion
When a practice ends its Veridian relationship:- Live API keys and webhook endpoints are revoked.
- PHI fields are deleted on the schedule defined in the BAA (typically within 60 days of termination unless the practice requests an export first).
- Financial records required by law are retained for the statutory period in encrypted, access-controlled storage.
- Audit log entries remain for tamper-evidence, but PHI within them is minimized — we record that an action occurred, not the patient detail.
Export
Practices can export their own data at any time from the dashboard or via API. Exports include sessions, payments, webhook history, and audit log for the practice.What’s next
HIPAA
Our role as a Business Associate.
Incident response
What happens if something goes wrong.
