Trust Center

How we protect patient information.

VeriOp processes protected health information as a business associate of the practices and surgery centers that use it. This page states the commitments we make today. Detailed security documentation is available to customers and prospects during security review: email support@veriop.ai and we will provide it.

Last reviewed: September 5, 2026

HIPAA and the BAA

We are a business associate. Every account that submits patient information executes our Business Associate Agreement before it can do so, and the BAA governs our handling of that information.

For marketplace clearances, the independent licensed clinician who performs the evaluation is the covered entity, and we are that clinician's business associate.

Encryption and access

Encrypted in transit and at rest with industry-standard encryption.

Unique login per user, role-based access, and practice-level isolation: a surgeon sees only their own cases, and no practice can see another's. Multi-factor authentication is enforced on our administrative and infrastructure access.

Where data lives

United States only, on HIPAA-eligible cloud infrastructure covered by a Business Associate Agreement. No patient information is stored or accessed outside the United States.

How AI handles patient data

AI analysis runs inside our own HIPAA-covered cloud environment, under a Business Associate Agreement. Patient information is never sent directly to an AI model developer and is not retained by the AI service. No patient information trains any model, ever.

De-identified information, created under the HIPAA Safe Harbor method, may be used to improve the product and for our published validation study.

Subprocessors

Every third party that can touch patient information is bound by a written agreement at least as protective as our own BAA. The current list is provided to customers and prospects on request.

Request it →

Incidents and breach notice

We notify affected customers in writing without unreasonable delay and no later than 10 business days after discovery of a breach of unsecured patient information, well inside HIPAA's 60-day ceiling, so a covered entity can still meet its own notification deadlines.

Found a vulnerability? Email security@veriop.ai. We will acknowledge within two business days and will not pursue researchers acting in good faith who give us reasonable time to fix an issue and do not access, alter, or retain patient information.

Getting your data out

A practice owner can export every record their practice has created at any time, in a machine-readable format, from Settings. No request, no fee, no waiting.

Records are your patients' chart documents, so we retain them rather than deleting them on a timer.

Return or destruction

On a practice owner's written direction, we permanently destroy the patient information we hold for that practice within 30 days and certify the destruction in writing. There is a 7-day grace period first, and we tell you to export before the clock runs.

De-identified information contains no patient information and is not affected.

Retention

We retain records while an account is active and after termination, under the same BAA protections, because assessments and anesthesia records form part of the patient's medical record and your practice has its own retention duties.

We do not delete on a fixed schedule and we do not decide when your records go away. You do, in writing, at any time.

Attestations and independent review

VeriOp runs on enterprise cloud infrastructure whose SOC 1, SOC 2, SOC 3, ISO 27001, and HITRUST attestations cover the data centers and services that store and process patient information, under a signed Business Associate Agreement. Our own controls at the application layer are documented in our Information Security Policy.

We complete customer security questionnaires and provide our policy set, BAA, subprocessor list, and incident-response procedure during evaluation. We name certifications only when we hold them; if your center requires a specific attestation as a condition of contracting, raise it with us early and we will scope it together.

Security review, questionnaires, and documents

Send us your security questionnaire and we will complete it. We can provide the executed BAA, our subprocessor list, our incident-response and breach-notification procedure, and a written description of our controls. Email support@veriop.ai with "security review" in the subject.

Clinical decision support for licensed providers. Not a substitute for clinical judgment. VeriOp AI, LLC · 9841 SW 130th Street, Miami, FL 33176