Skip to main content

HIPAA

Veridian Health Partners processes Protected Health Information (PHI) on behalf of covered entities. Veridian operates as a Business Associate when a signed BAA is in place.
HIPAA-aligned design is not HIPAA certification. Veridian Motion is not HIPAA-certified. Compliance depends on BAAs, agency hosting, and operational practices. Current Lovable builds use synthetic data only.

Technical safeguards (built today)

  • Row-level security on every table
  • Field-level PHI encryption (AES-256-GCM where PHI)
  • Hash-chained audit log (no PHI in payload)
  • Role-based access (pt, admin, it_admin, officer, warden, bh_clinician, wellness_participant)
  • TOTP MFA for staff (enforced per deployment)
  • Brute-force login protection
  • Program entitlement / seat enforcement

PHI and sensitive data in Veridian Motion

  • Patient identifiers and enrollment records
  • Body-map selections, complaint, questionnaire responses, posture photos
  • AI triage output, clinician notes, approved exercise plans
  • Clinician-to-patient messages and Communication Record exports
  • Medical Intake profiles and red-flag markers (medical_profiles)
  • Precision Rehab sessions, routine logs, certifications (rehab_*)
  • Chess Wellness progress, assignments, academy certs (chess_*) — activity data; not a clinical assessment
  • Program entitlements / enrollments / billing snapshots (licensing metadata)
  • Legal acceptances (version + timestamp)
Minimum necessary: patients see only their data; MSK plans only after clinician approval; notes only if shared; warden / officer do not receive clinical PHI by default.

Patient rights

HIPAA rights are exercised through the covered entity / agency. Veridian supplies data to authorized agency staff to fulfill requests.

Corrections-specific note

CJIS, FedRAMP, and state corrections IT standards are separate from HIPAA — not built into Veridian Motion. The hosting agency provides CJIS/FedRAMP/GovCloud environment, MDM kiosk lockdown, network controls, and personnel screening.

Subprocessors

PHI may be processed by subprocessors including Lovable Cloud / Supabase and server-side AI providers. List available to customers on request. Messaging screener must be BAA-covered or self-hosted before real-PHI pilots.

What’s next

Data handling

Collection and retention.

Data model & privacy

Entity groups and RLS.

Security overview

Full posture.