This guide explains how Vero handles patient data, the safeguards in place, and the privacy controls available to you.
How Vero handles patient data
Regional storage
Vero applies regional data localization to primary clinical data, including encounters, notes, patient records, uploaded documents, and audio-derived transcripts:
Canadian customers: Primary clinical data is stored in Canada.
US customers: Primary clinical data is stored in the United States.
Certain supporting functions rely on third-party service providers whose infrastructure may operate in other jurisdictions. Contractual data-protection obligations are in place for these providers.
AI and patient data
Vero uses AI to help generate notes, answer clinical questions, and support documentation workflows. Patient data and sensitive health information are not used to train, develop, or improve Vero's proprietary AI models.
Patient data is protected throughout the AI pipeline. Third-party AI providers are bound by contractual data-protection obligations.
How Vero protects your data
Encryption
In transit: TLS 1.2 or higher is enforced for every connection.
At rest: Storage is encrypted using industry-standard controls, including AES-256 where applicable.
Access and account security
Clinical data access requires an authenticated session and record-level authorization. Your data is logically isolated from other users. Row-level security at the database layer limits queries to records belonging to the authenticated user or a permitted organization scope.
Vero supports email/password authentication and optional multi-factor authentication (TOTP). Sessions use modern token-based authentication controls, and authentication endpoints include protection against abuse and suspicious access patterns.
Monitoring and vulnerability management
Vero runs ongoing monitoring across the production environment, including logging, alerting, infrastructure monitoring, and security reviews. Infrastructure vulnerability scanning and remediation are continuous.
Independent verification and compliance
SOC 2 Type II
Vero has completed its SOC 2 Type II examination. Visit the Vero Trust Center for current security, compliance, governance, and trust information.
Independent penetration testing
Vero undergoes independent penetration testing. The latest assessment reported a low risk rating with no critical, high, or medium findings.
Healthcare privacy requirements
HIPAA: Vero is aligned with HIPAA Security Rule safeguards. A HIPAA-covered entity or business associate using Vero to create, receive, maintain, or transmit electronic protected health information on its behalf must have a HIPAA-compliant Business Associate Agreement in place. Review and sign the BAA in Vero before that use.
PIPEDA: Vero is built to support Canadian privacy requirements, including Canadian storage of primary clinical data and contractual controls for subprocessors.
PHIPA: Vero supports PHIPA-aligned workflows for Ontario healthcare settings, including regional data storage, access controls, encryption, retention controls, and no use of patient data to train Vero’s proprietary AI models. See PHIPA and Ontario Health Privacy.
Your privacy and security controls
Multi-factor authentication: Enable MFA from Settings → Security.
Data retention and deletion: Configure automatic deletion from Settings → Data retention for active and archived encounters and their notes. You can also delete encounters, notes, chats, uploads, or patients when they are no longer needed. See Data Management for the available options.
Account deletion and privacy requests: Request help through the in-app support chat. If you are already chatting with us, continue in the same conversation; your account-deletion request will be passed to a human support agent. You do not need to email us separately or make an additional request to speak with a person. The team will confirm any verification needed before processing the request and follow up in that conversation. A handoff does not mean a teammate is immediately available. Email [email protected] is also available if you prefer. See Contact Vero Support for how to start a support chat.
Frequently asked questions
When is a Business Associate Agreement required?
For a HIPAA-covered entity or business associate using a cloud service to process or store electronic protected health information on its behalf, a compliant BAA is required. It is not simply an optional clinic preference. Signing a BAA does not switch encryption on or certify your organization's compliance. See HHS guidance on HIPAA and cloud computing.
How do I sign or download a Business Associate Agreement?
Open Settings → Forms & documents.
Select Sign BAA and complete the agreement in Vero.
After signing, select Download signed BAA.
For help with signing, ask for a teammate in your existing support conversation, or contact Vero Support.
Can our institution request a PIA, TRA, or approval review?
Ask Vero Support to review your institution's requirements and confirm which current materials can be shared. If you are already in support, ask for a teammate in that conversation. Availability and institutional approval should be confirmed for the specific request; a document missing from the public Help Center does not establish approval or rejection.
Does using Vero certify my organization's compliance?
No. References to HIPAA, PIPEDA, or PHIPA describe the safeguards and workflows Vero supports. They are not legal advice or a certification of your organization's compliance.
Do I still need to review AI-generated notes and answers?
Yes. Vero is a clinical documentation and decision-support tool, and AI-generated output can be incomplete or inaccurate. Clinicians are professionally responsible for reviewing, verifying, and correcting every note or answer before using it for clinical care or documentation.
How do I report a privacy or security concern?
Email [email protected] with your question or concern.
