Permitted uses
Exactly what PHI may be accessed, by whom, and for which parts of the revenue-cycle work — nothing broader.
Compliance & security
This page explains what happens after a signed agreement — not what to send through this public website. For inquiries here, keep the conversation at the business level.
Start a business-level conversationBefore access starts
Vyro signs a Business Associate Agreement with every client before any protected health information is accessed, consistent with HIPAA's requirements for business associates. Here is what that agreement actually pins down.
Exactly what PHI may be accessed, by whom, and for which parts of the revenue-cycle work — nothing broader.
The administrative, physical, and technical controls we are obligated to maintain for the duration of the engagement.
Our obligation to identify, escalate, and notify you within a defined timeframe, plus each party's responsibilities if it happens.
Safeguards
02 / 05
These are Vyro's standing operational commitments for any engagement involving protected health information.
Data is encrypted in transit and at rest across the systems used to access client information.
Access is role-based and limited to staff assigned to a given engagement, reviewed on a regular basis.
Client work is performed on managed devices over VPN-gated connections. Personal devices are not used for PHI-adjacent work.
Staff complete background screening and sign confidentiality agreements before being assigned to client work.
Access to client systems, portals, and credentials is revoked immediately when a staff member's assignment or employment ends.
A documented process governs how a suspected incident is identified, escalated, and reported to the client within the timeframe set by the BAA.
Where the work happens
Vyro's operations team includes staff located outside the United States. Once a client agreement and BAA are in place, PHI may be accessed by trained team members working from secure, access-controlled environments outside the US, under the same confidentiality, encryption, and access-control commitments described above. Practices that need PHI to stay US-only, or that require written notice of offshore access for their own compliance program, should raise this during onboarding — Vyro documents and honors client-specific data-residency requirements in the signed agreement.
Independent assurance
Compliance pages are easy to inflate. Here is the honest position, and we'll update this page when it changes.
Before you reach out
Do not send patient names, medical records, insurance IDs, or claim files through this website, the audit form, or ordinary email — this is a public site, not a secure channel. Once a signed agreement and BAA are in place, Vyro provides an approved secure process for PHI, governed by the safeguards above.
Start with a business-level audit requestQuestions we get
Short answers now make the diligence conversation faster later.
Request a free auditYes. A signed BAA is in place before PHI access starts, not after.
Vyro's operations team includes offshore staff working under the safeguards described above. If your practice requires PHI to stay US-only, tell us during onboarding and we'll document that requirement in the agreement.
We follow a documented escalation process and notify affected clients within the timeframe set by the BAA.
Not yet. SOC 2 Type II is on our roadmap. We won't claim certification until the examination is complete.