Security & compliance

Four planes that no request gets to skip.

Home infusion touches protected health information at every hand-off. VeinFusion enforces isolation in one place — the API — so there is no client, no app version, and no integration that can route around it.

Architecture

One path to the data.

Clients never reach the database. Every web portal and native app goes through the same API, which is where authorization is decided and where the audit entry is written. A second path would mean a second place to get it wrong.

IdentityGoogle Identity Platform; role claims minted server-side, never client-set
Data pathAll reads and writes through the API — no direct database access from any client
TransportTLS throughout; API and portals served over HTTPS only
AuditAppend-only log with actor, role, action, resource, and a PHI flag
Staff accessVeinFusion staff access is itself logged, and reading the log is logged
Patient privacy

Masking is the default state, not a setting.

A patient's name, address, and phone number are not part of what the nurse network browses. They unmask to exactly one nurse, at the moment that nurse takes responsibility for the visit.

Messaging and calling run through the platform in both directions, so neither party ends up holding the other's personal number after the visit is over.

What a nurse sees before confirming

LocationZIP-3 area, never the street address
PatientNo name, no contact details, no identifiers
ClinicalVisit type and duration — enough to judge fit
MoneyThe payout for the visit, stated up front
Being straight about it

What we do not claim.

Trust pages are where products quietly imply certifications they do not hold. Here is the honest position.

Certifications

Where VeinFusion holds a formal attestation, it will be named here with its report date. Until then, this page describes controls, not certificates — and you should read it that way.

Business associate agreements

VeinFusion handles protected health information on behalf of pharmacy customers. BAA terms are part of onboarding — ask us for the current agreement.

Sub-processors

The vendors that process data on our behalf are listed publicly, and the list changes when the vendors do.

See sub-processors

Send us your security questionnaire.

We would rather answer a long one early than a short one after you have already integrated.

Contact security