Security
Built to HIPAA requirements, in plain English.
Here is exactly what protects patient data in Vital Dispatch and where each safeguard lives. No certifications we do not hold, no vague promises.
Your own database, with a BAA
Each client runs on a dedicated, encrypted database on a plan that supports a Business Associate Agreement. Your patient data is not pooled with anyone else's, and we sign a BAA with you.
MFA and passkeys for every staff login
Staff sign in with a password plus a second factor, or a passkey. Sessions time out and can be reviewed by the owner.
Role-based access, enforced in the database
Admin, dispatch, nurse, reviewer and medical-director roles each see only what their job needs. The rules live in the database itself (row-level security), not just in the app's screens.
Append-only, signed records
A signed chart note, consent or treatment record cannot be edited or deleted. Corrections are addenda, and the review chain (reviewer, owner, medical director) is recorded the same way.
Audit trail
Who viewed or changed a patient record, and when, is logged automatically. The log is append-only.
No PHI in notifications
Push notifications and texts say only who needs you and where to tap. Patient names and clinical details stay inside the app.
Encrypted storage for photos and documents
Photos and documents live in private, encrypted storage and are served through short-lived links. There is no public bucket.
Credential lockout
A nurse whose license or required credential has lapsed loses access to patient records until it is current.
Roles
Minimum necessary, enforced in the database
Access rules are row-level security policies in the database. A screen cannot show a record the role is not allowed to read, and an API call cannot fetch it either.
| Role | Sees |
|---|---|
| Admin / owner | Everything for their units: staff, services, consents, QuickBooks, chart approval. |
| Dispatch | Board, calendar, patients and visits. No chart approval. |
| Nurse | Assigned visits and patient records while credentials are current; writes only on assigned visits. |
| Reviewer | Charts awaiting review; signs off, never edits. |
| Medical director | Only charts sent for the 10% sample. No booking or calendar access. |
What we say and what we do not
We say Vital Dispatch is built to HIPAA requirements and that we sign a Business Associate Agreement with every client. We do not say “HIPAA certified”, because there is no such certification, and we do not claim third-party attestations we have not completed.
HIPAA compliance is a property of your business, not of any single piece of software. Vital Dispatch supplies the technical safeguards described above; your policies, training and risk analysis complete the picture. We are happy to walk your compliance officer through the details.
Where the data lives
Each client runs on a dedicated, encrypted Postgres database and private encrypted file storage hosted in the United States on a plan that supports a BAA. The web application runs on Vercel. Push notifications are self-hosted (VAPID) so no third-party notification service ever handles patient data.
Questions
Ask for our subprocessor list or a walkthrough of any control at jvyverman@jvcosolutions.com, or book a demo.
Walk your compliance officer through it.
We will show the audit trail, the review chain and the access rules live, on a demo database.