HIPAA Privacy Notice

Last Updated: June 25, 2026

This HIPAA Privacy Notice applies only to customers and organizations using Vevisto AI in connection with healthcare services subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended.

Vevisto AI is operated by VevistoAI LLC and provides AI-powered software that can be configured for healthcare and many other industries. This notice applies only when our platform is used to process Protected Health Information (“PHI”) on behalf of healthcare organizations.

Our Role

Vevisto AI provides technology that assists healthcare organizations with administrative workflows, patient communication, scheduling, document management, AI-powered assistance, and practice management.

Healthcare organizations remain responsible for:

  • Patient care
  • Medical decisions
  • Clinical documentation
  • Regulatory compliance
  • Determining what information is stored within the platform

Where applicable, Vevisto AI may act as a service provider supporting covered entities or business associates, depending on the contractual relationship between the parties.

Protected Health Information (PHI)

Depending on how a healthcare organization configures the platform, Vevisto AI may process information including:

  • Patient names
  • Contact information
  • Appointment schedules
  • Patient Intake Forms
  • Insurance information
  • Uploaded documents
  • Communications between patients and providers
  • Administrative records
  • AI-assisted conversations
  • Other healthcare-related information provided by the customer
  • Healthcare organizations determine what information is collected and stored.

Privacy & Confidentiality

Protecting patient privacy is a core principle of our platform.

We are committed to implementing reasonable administrative, technical, and organizational safeguards designed to help healthcare organizations protect PHI processed through Vevisto AI.

Only authorized users should have access to patient information based on their assigned roles and permissions.

Security Measures

Vevisto AI is designed with security features that may include:

  • Encrypted communications
  • Secure authentication
  • Identity verification
  • One-Time Passcodes (OTP)
  • Role-based access controls
  • Audit logging
  • Session management
  • Infrastructure monitoring
  • Backup procedures
  • Continuous security improvements
  • Security practices evolve as technology and industry standards continue to develop.

AI in Healthcare

Artificial intelligence within Vevisto AI is intended to support administrative workflows—not replace licensed healthcare professionals.

AI may assist with:

  • Appointment scheduling
  • Patient communication
  • Intake processing
  • Administrative questions
  • Workflow automation
  • Internal knowledge retrieval
  • The AI does not provide medical diagnoses, prescribe treatment, or replace clinical judgment.
  • Healthcare providers remain responsible for reviewing information and making all medical decisions.

Minimum Necessary Access

Healthcare organizations are encouraged to configure user permissions so individuals have access only to the information necessary to perform their job responsibilities.

Vevisto AI supports role-based access controls to help organizations implement this principle.

Business Associate Agreements (BAAs)

Where required by law or contract, VevistoAI LLC may enter into a Business Associate Agreement (BAA) with eligible healthcare organizations.

Healthcare organizations are responsible for determining whether a BAA is required for their use of the platform.

Patient Rights

Patients should direct requests regarding:

  • Access to medical records
  • Corrections to health information
  • Restrictions on disclosures
  • Copies of healthcare records
  • Privacy complaints
  • to their healthcare provider.

Healthcare providers remain responsible for responding to these requests in accordance with applicable law.

Data Retention

Healthcare organizations control the information they choose to retain within Vevisto AI.

Retention periods may vary depending on:

  • Customer configuration
  • Legal obligations
  • Regulatory requirements
  • Contractual agreements

Security Incidents

If Vevisto AI becomes aware of a security incident affecting customer information, we will investigate the matter promptly and take appropriate action consistent with our contractual obligations and applicable law.

Where required, affected customers will be notified so they can fulfill any legal notification responsibilities.

Healthcare Organization Responsibilities

Organizations using Vevisto AI are responsible for:

  • Verifying patient identity before disclosing protected information.
  • Managing user permissions.
  • Protecting account credentials.
  • Training staff on privacy and security practices.
  • Obtaining patient consent where required.
  • Complying with HIPAA and other applicable laws.

Vevisto AI provides tools that support these responsibilities but does not replace an organization’s own compliance program.

Additional Information

Healthcare organizations should also review our:

  • Privacy Policy
  • Terms of Service
  • Responsible AI Policy
  • Security & Trust
  • SMS Terms & Conditions

These documents work together to explain how Vevisto AI protects information and supports secure, responsible use of the platform.

Contact Us

If you have questions regarding this HIPAA Privacy Notice, please contact:

VevistoAI LLC

Address

15030 Ventura Blvd

Sherman Oaks, CA 91403

California, USA

At Vevisto AI, we recognize that trust is essential in healthcare. We are committed to continuously improving our platform to help healthcare organizations deliver secure, efficient, and patient-focused services while supporting responsible handling of protected health information.