Compliance & security

How Vyro protects PHI once an engagement begins.

This page explains what happens after a signed agreement — not what to send through this public website. For inquiries here, keep the conversation at the business level.

Start a business-level conversation

Before access starts

A signed BAA comes first, not after.

Vyro signs a Business Associate Agreement with every client before any protected health information is accessed, consistent with HIPAA's requirements for business associates. Here is what that agreement actually pins down.

01

Permitted uses

Exactly what PHI may be accessed, by whom, and for which parts of the revenue-cycle work — nothing broader.

02

Required safeguards

The administrative, physical, and technical controls we are obligated to maintain for the duration of the engagement.

03

Breach notification

Our obligation to identify, escalate, and notify you within a defined timeframe, plus each party's responsibilities if it happens.

What's in place once PHI access starts.

These are Vyro's standing operational commitments for any engagement involving protected health information.

01

Encryption

Data is encrypted in transit and at rest across the systems used to access client information.

02

Access controls

Access is role-based and limited to staff assigned to a given engagement, reviewed on a regular basis.

03

Device & network policy

Client work is performed on managed devices over VPN-gated connections. Personal devices are not used for PHI-adjacent work.

04

Staff screening

Staff complete background screening and sign confidentiality agreements before being assigned to client work.

05

Offboarding

Access to client systems, portals, and credentials is revoked immediately when a staff member's assignment or employment ends.

06

Incident response

A documented process governs how a suspected incident is identified, escalated, and reported to the client within the timeframe set by the BAA.

Where the work happens

Offshore access, disclosed plainly.

Vyro's operations team includes staff located outside the United States. Once a client agreement and BAA are in place, PHI may be accessed by trained team members working from secure, access-controlled environments outside the US, under the same confidentiality, encryption, and access-control commitments described above. Practices that need PHI to stay US-only, or that require written notice of offshore access for their own compliance program, should raise this during onboarding — Vyro documents and honors client-specific data-residency requirements in the signed agreement.

Independent assurance

What we carry, and what we won't claim yet.

Compliance pages are easy to inflate. Here is the honest position, and we'll update this page when it changes.

  1. InsuranceVyro carries errors & omissions and cyber liability insurance covering its operations.
  2. SOC 2A SOC 2 Type II examination is on Vyro's roadmap. Until that report is complete, we do not claim SOC 2 certification.
  3. Website policiesSee our privacy policy for how this public site handles visitor information, and our website terms for how the site may be used.

Before you reach out

Keep the public site business-only.

Do not send patient names, medical records, insurance IDs, or claim files through this website, the audit form, or ordinary email — this is a public site, not a secure channel. Once a signed agreement and BAA are in place, Vyro provides an approved secure process for PHI, governed by the safeguards above.

Start with a business-level audit request

Questions we get

Compliance questions practices ask before signing.

Short answers now make the diligence conversation faster later.

Request a free audit
Do you sign a BAA before any work begins?

Yes. A signed BAA is in place before PHI access starts, not after.

Is any of our data accessed outside the US?

Vyro's operations team includes offshore staff working under the safeguards described above. If your practice requires PHI to stay US-only, tell us during onboarding and we'll document that requirement in the agreement.

What happens if there's a security incident?

We follow a documented escalation process and notify affected clients within the timeframe set by the BAA.

Are you SOC 2 certified?

Not yet. SOC 2 Type II is on our roadmap. We won't claim certification until the examination is complete.

Have a compliance question before you sign?

Talk to the team