HIPAA
Veridian Health Partners processes Protected Health Information (PHI) on behalf of covered entities. Veridian operates as a Business Associate when a signed BAA is in place.Technical safeguards (built today)
- Row-level security on every table
- Field-level PHI encryption (AES-256-GCM where PHI)
- Hash-chained audit log (no PHI in payload)
- Role-based access (
pt,admin,it_admin,officer,warden,bh_clinician,wellness_participant) - TOTP MFA for staff (enforced per deployment)
- Brute-force login protection
- Program entitlement / seat enforcement
PHI and sensitive data in Veridian Motion
- Patient identifiers and enrollment records
- Body-map selections, complaint, questionnaire responses, posture photos
- AI triage output, clinician notes, approved exercise plans
- Clinician-to-patient messages and Communication Record exports
- Medical Intake profiles and red-flag markers (
medical_profiles) - Precision Rehab sessions, routine logs, certifications (
rehab_*) - Chess Wellness progress, assignments, academy certs (
chess_*) — activity data; not a clinical assessment - Program entitlements / enrollments / billing snapshots (licensing metadata)
- Legal acceptances (version + timestamp)
warden / officer do not receive
clinical PHI by default.
Patient rights
HIPAA rights are exercised through the covered entity / agency. Veridian supplies data to authorized agency staff to fulfill requests.Corrections-specific note
CJIS, FedRAMP, and state corrections IT standards are separate from HIPAA — not built into Veridian Motion. The hosting agency provides CJIS/FedRAMP/GovCloud environment, MDM kiosk lockdown, network controls, and personnel screening.Subprocessors
PHI may be processed by subprocessors including Lovable Cloud / Supabase and server-side AI providers. List available to customers on request. Messaging screener must be BAA-covered or self-hosted before real-PHI pilots.What’s next
Data handling
Collection and retention.
Data model & privacy
Entity groups and RLS.
Security overview
Full posture.
