Security Built for Clinical Workflows
Only you can view your patients’ PHI. VeloNote personnel cannot. Patient information is available only within the authorized user’s active session, with HIPAA-focused security, session-only processing, access controls, audit logging, and automatic deletion of uploaded patient data.
How VeloNote Protects PHI
A brief explanation of who can access patient information, how long it is retained, and the safeguards built into VeloNote for physicians and compliance teams.
Only you can view your patients’ PHI. VeloNote personnel cannot.
Who Can Access What?
The Authorized User Can View
- uploaded patient records
- generated clinical drafts
- active patient information within their session
VeloNote Personnel Cannot View
- uploaded patient files
- generated clinical notes
- diagnoses or treatment information
- historical patient charts
- PHI in backups
VeloNote personnel may access operational information required to run the platform, such as account status, billing information, security logs, and system-level activity, but not patient PHI.
Designed Without Administrative PHI Access
VeloNote administrative accounts are not provided with access to customer PHI. There is no administrative pathway for the founder, developers, administrators, or support personnel to browse patient records or generated clinical content.
- •No founder access to PHI
- •No developer access to PHI
- •No administrator access to PHI
- •No support-staff access to PHI
- •Administrative activity is logged
- •Emergency or support actions are documented and logged
- •Backups do not contain PHI
Patient Information Is Not Persistently Retained
Patient information is processed for the active clinical workflow and is automatically deleted when the user moves to the next patient, ends the session, or closes the browser.
- Automatic deletion at the end of the active workflow
- No PHI retained in backups
- No persistent patient-record database available to VeloNote personnel
- Patient information is not used to train public AI models
No PHI in Backups / No AI Training
Backups do not contain patient PHI.
Patient information is not used to train public AI models.
Business Associate Agreements and Administrative Logging
The infrastructure used to process protected health information is covered by appropriate Business Associate Agreements.
Infrastructure & Encryption
VeloNote operates on HIPAA-eligible cloud infrastructure across AWS and Google Cloud Platform, with encryption in transit (TLS 1.2+) and at rest (AES-256). Data centers maintain SOC 2 Type II and ISO 27001 certifications.
Administrative Logging
Administrative activity is logged for security monitoring and compliance:
- •CloudTrail: AWS API calls and management events
- •CloudWatch: Application logs and performance metrics
- •VPC Flow Logs: Network traffic monitoring
- •Log file validation prevents tampering
A Deeper Look at VeloNote Security & Compliance
For physicians, compliance officers, IT teams, and healthcare organizations that want a more detailed review of VeloNote’s security architecture, HIPAA safeguards, data handling, and clinical compliance approach.
Security FAQs
Who can see the patient information I upload to VeloNote?
Only the authorized user can view the patient information and generated clinical content within their active VeloNote session. VeloNote’s founder, employees, developers, administrators, and support staff cannot access or browse that PHI.
Can Brian Lawenda or anyone working at VeloNote see my patients’ clinical information?
No. VeloNote is designed so that Brian Lawenda and VeloNote personnel cannot open, browse, or view customer PHI.
How long is patient information retained?
Patient information is automatically deleted when the user moves to the next patient, ends the session, or closes the browser.
Is PHI stored in backups?
No. VeloNote backups do not contain patient PHI.
Is patient information used to train AI?
No. Patient information is not used to train public AI models.
This page is provided for informational purposes only and does not constitute a warranty, guarantee, or expansion of liability. This overview does not modify the Terms of Service or any executed agreement.