Four planes that no request gets to skip.
Home infusion touches protected health information at every hand-off. VeinFusion enforces isolation in one place — the API — so there is no client, no app version, and no integration that can route around it.
One path to the data.
Clients never reach the database. Every web portal and native app goes through the same API, which is where authorization is decided and where the audit entry is written. A second path would mean a second place to get it wrong.
| Identity | Google Identity Platform; role claims minted server-side, never client-set |
|---|---|
| Data path | All reads and writes through the API — no direct database access from any client |
| Transport | TLS throughout; API and portals served over HTTPS only |
| Audit | Append-only log with actor, role, action, resource, and a PHI flag |
| Staff access | VeinFusion staff access is itself logged, and reading the log is logged |
Masking is the default state, not a setting.
A patient's name, address, and phone number are not part of what the nurse network browses. They unmask to exactly one nurse, at the moment that nurse takes responsibility for the visit.
Messaging and calling run through the platform in both directions, so neither party ends up holding the other's personal number after the visit is over.
What a nurse sees before confirming
| Location | ZIP-3 area, never the street address |
|---|---|
| Patient | No name, no contact details, no identifiers |
| Clinical | Visit type and duration — enough to judge fit |
| Money | The payout for the visit, stated up front |
What we do not claim.
Trust pages are where products quietly imply certifications they do not hold. Here is the honest position.
Certifications
Where VeinFusion holds a formal attestation, it will be named here with its report date. Until then, this page describes controls, not certificates — and you should read it that way.
Business associate agreements
VeinFusion handles protected health information on behalf of pharmacy customers. BAA terms are part of onboarding — ask us for the current agreement.
Sub-processors
The vendors that process data on our behalf are listed publicly, and the list changes when the vendors do.
See sub-processorsSend us your security questionnaire.
We would rather answer a long one early than a short one after you have already integrated.
Contact security