Skip to content
Vital Dispatch — Care in Motion

Security

Built to HIPAA requirements, in plain English.

Here is exactly what protects patient data in Vital Dispatch and where each safeguard lives. No certifications we do not hold, no vague promises.

  • Your own database, with a BAA

    Each client runs on a dedicated, encrypted database on a plan that supports a Business Associate Agreement. Your patient data is not pooled with anyone else's, and we sign a BAA with you.

  • MFA and passkeys for every staff login

    Staff sign in with a password plus a second factor, or a passkey. Sessions time out and can be reviewed by the owner.

  • Role-based access, enforced in the database

    Admin, dispatch, nurse, reviewer and medical-director roles each see only what their job needs. The rules live in the database itself (row-level security), not just in the app's screens.

  • Append-only, signed records

    A signed chart note, consent or treatment record cannot be edited or deleted. Corrections are addenda, and the review chain (reviewer, owner, medical director) is recorded the same way.

  • Audit trail

    Who viewed or changed a patient record, and when, is logged automatically. The log is append-only.

  • No PHI in notifications

    Push notifications and texts say only who needs you and where to tap. Patient names and clinical details stay inside the app.

  • Encrypted storage for photos and documents

    Photos and documents live in private, encrypted storage and are served through short-lived links. There is no public bucket.

  • Credential lockout

    A nurse whose license or required credential has lapsed loses access to patient records until it is current.

Roles

Minimum necessary, enforced in the database

Access rules are row-level security policies in the database. A screen cannot show a record the role is not allowed to read, and an API call cannot fetch it either.

RoleSees
Admin / ownerEverything for their units: staff, services, consents, QuickBooks, chart approval.
DispatchBoard, calendar, patients and visits. No chart approval.
NurseAssigned visits and patient records while credentials are current; writes only on assigned visits.
ReviewerCharts awaiting review; signs off, never edits.
Medical directorOnly charts sent for the 10% sample. No booking or calendar access.

What we say and what we do not

We say Vital Dispatch is built to HIPAA requirements and that we sign a Business Associate Agreement with every client. We do not say “HIPAA certified”, because there is no such certification, and we do not claim third-party attestations we have not completed.

HIPAA compliance is a property of your business, not of any single piece of software. Vital Dispatch supplies the technical safeguards described above; your policies, training and risk analysis complete the picture. We are happy to walk your compliance officer through the details.

Where the data lives

Each client runs on a dedicated, encrypted Postgres database and private encrypted file storage hosted in the United States on a plan that supports a BAA. The web application runs on Vercel. Push notifications are self-hosted (VAPID) so no third-party notification service ever handles patient data.

Questions

Ask for our subprocessor list or a walkthrough of any control at jvyverman@jvcosolutions.com, or book a demo.

Walk your compliance officer through it.

We will show the audit trail, the review chain and the access rules live, on a demo database.