How Vaultus protects patient information. Vaultus operates as a HIPAA Business Associate and signs a Business Associate Agreement with each provider.
Vaultus does not store raw clinical note text. Notes are processed in the moment and hashed at every persistence boundary, and an automated guard rejects persisting note, SOAP, or free-text content. Nothing to leak, because nothing is kept.
Data is encrypted in transit (TLS 1.2/1.3) and at rest (SQLCipher AES, 256,000-iteration key derivation), with access controls, authentication, and one-way pseudonymization of provider identity.
When you process real patient information through Vaultus, Vaultus is your Business Associate under HIPAA. You review and accept our Business Associate Agreement during account creation. It sets out how PHI is protected, breach-notification commitments, and the de-identification terms.
Vaultus reports any non-permitted use or disclosure, security incident, or breach of unsecured PHI of which it becomes aware, and will notify affected providers without unreasonable delay and no later than 15 calendar days after discovery, consistent with 45 CFR 164.410.
The safety logic is deterministic and rules-based, and cites national clinical guidelines. Vaultus does not use machine learning or generative AI to produce safety observations, does not make clinical decisions, and never writes into or modifies your note.
Vaultus maintains a current subprocessor register and holds a signed Business Associate Agreement with its infrastructure subprocessor, DigitalOcean.
This page summarizes practices described in our Business Associate Agreement, Terms of Service, and Privacy Policy. The BAA is the governing document for PHI and states the current status of individual safeguards. Vaultus does not claim any third-party security certification.
← Back to home