Security & HIPAA

Built for regulated facilities from day one.

VynMed was designed for skilled nursing and other HIPAA-covered environments. That means encryption, least-privilege access, tamper-evident records, and an audit trail your compliance team can actually defend.

Data protection

How we protect resident and patient data

Encrypted in transit & at rest

TLS 1.2+ for every network call, verified on the device against pinned AWS root certificates. Evidence images and audit records are encrypted at rest in our managed cloud with AWS KMS keys. The short-range Bluetooth link used for device setup and offline pickup is a different question, and it has its own section below.

Tamper-evident audit log

Every test, sign-off, and override is written to an append-only log tied to the operator identity and the device clock, so nothing can be quietly altered after the fact.

Least-privilege access

Role-based access for techs, nurses, and administrators. No shared accounts, no "one master password" per cart, and every session is attributable.

Device link

What the Bluetooth link does, and what it does not do

The VynScan uses Bluetooth for three jobs, all of them short and all of them within a few feet of the device. Setup, where the app hands a new device the facility Wi-Fi credentials and a single-use pairing secret. Starting a test on a device standing in front of you when the network path to it is down, which sends a start command and no resident information. And offline pickup, where a device that captured tests while the network was down hands those records to the app to carry up. Bluetooth is never the route to our cloud: it reaches only as far as the phone in the room, and the upload from there takes the network path described above.

On that link the device is cryptographically authenticated, and the payload is not separately encrypted. Both halves of that sentence matter, so both are stated here rather than left to inference.

The authentication is real and it fails closed. Before the app pulls a single record off a VynScan, it fetches that device's public key from our cloud, where it was recorded when the facility claimed the device, and stops if the unit in front of it presents a different key. An X25519 exchange then establishes a per-connection session key, and every block the device sends carries an HMAC-SHA256 tag and a response counter computed under that key. A block that has been altered, replayed or reordered fails verification and nothing is uploaded. A substituted or impersonating device cannot push false records into a facility's history.

What that does not do is conceal the contents from a Bluetooth receiver in range while a setup or a pickup is actually in progress. We do not count the short usable range of the device radio as a security control. What we do rely on is that each of those jobs is a brief, deliberate action a staff member takes with the device in hand, that the pairing secret is single-use, and that captured evidence is encrypted at rest from the moment it reaches our cloud. The device firmware implements an AES-256 payload-encryption path for this link; the shipping app does not negotiate it, so it is not in effect today and it is not claimed here.

HIPAA

HIPAA alignment

Administrative safeguards

Security policies, workforce training, a sanction policy, and an incident response plan, being documented to 45 CFR § 164.308 ahead of first deployment.

Physical safeguards

Device hardening, facility access procedures, and workstation controls for on-site hardware per § 164.310.

Technical safeguards

Unique user IDs, automatic logoff, audit controls, and integrity controls per § 164.312, built into the product rather than bolted on.

Business Associate Agreement

We sign a BAA with every covered entity before handling PHI. Our downstream subprocessors are contractually bound to the same standards.

Minimum necessary

We don't collect what we don't need

VynMed is designed around the HIPAA "minimum necessary" principle. The device handles the smallest amount of PHI required to produce a defensible record, and nothing beyond that. We do not sell, share, or otherwise use resident data for advertising, model training, or secondary research.

Deidentified operational metrics (how many tests, uptime, error rates) help us keep your facility running. Anything tied to an individual stays inside your environment unless you explicitly export it.

Incident response

If something goes wrong

We maintain a documented incident response plan with defined severity levels, notification timelines, and post-incident review. Security-relevant incidents involving PHI are communicated to affected covered entities well inside the HIPAA breach notification window so your compliance officer can act before any regulator calls.

Suspect something? Email contact@vynmed.com with "Security" in the subject line and we'll get a human on it.

Want the full security packet?

We'll send our architecture overview, data flow diagram, subprocessor list, and a draft BAA. It is the same bundle our design partners use for vendor review.

Request the packet