Security
Security
Vida Verified Last updated: July 13, 2026
Our Commitment to Security
Vida Verified is a product of Medavida, Inc. ("Vida Verified," "Medavida," "we," "us," or "our"). Protecting the identity, professional credential, and organizational information entrusted to us is central to how we operate.
We use administrative, technical, organizational, and physical safeguards designed to protect our systems and the information processed through the Vida Verified platform. Our security program is informed by the sensitivity of the information we process, the risks associated with healthcare credential verification, and applicable legal and contractual requirements.
No system can be guaranteed to be completely secure. We continually evaluate our safeguards and update our practices as our platform, technology, and risk environment evolve.
1. Data Encryption
We use encryption and secure communication protocols designed to protect information transmitted to and from the Vida Verified platform.
Our safeguards include:
- Encryption of data in transit using Transport Layer Security
- Encryption of sensitive data at rest using industry-standard encryption methods
- Secure handling of identity, credential, account, and verification information
- Protection of encryption keys and system credentials through access controls and secure configuration practices
- Use of trusted service providers that maintain appropriate security safeguards
Users should access Vida Verified only through supported browsers and secure networks.
2. Infrastructure Security
Vida Verified is hosted using cloud infrastructure designed to provide physical, environmental, network, and operational safeguards.
Our infrastructure-security practices may include:
- Network controls designed to restrict unauthorized access
- Segregation of development, testing, and production environments
- Firewalls and other network-security measures
- Restricted administrative and production-system access
- Multi-factor authentication for authorized personnel with access to sensitive systems
- Logging and monitoring of critical infrastructure and system activity
- Secure configuration, maintenance, and patch-management procedures
- Backup and recovery measures designed to support service continuity and data resilience
Access to production systems is limited to authorized personnel who require access to perform their job responsibilities.
3. Identity and Access Management
We apply role-based and least-privilege access principles to systems and information.
Our identity and access-management practices are designed to ensure that:
- Personnel receive only the access reasonably necessary for their assigned responsibilities
- Access to sensitive systems requires appropriate authentication
- Multi-factor authentication is used for designated administrative and sensitive-system access
- Access permissions are reviewed and adjusted as responsibilities change
- Access is removed when it is no longer required
- Credentials may not be shared among users or personnel
- Administrative activity may be logged and reviewed
Organizational customers are responsible for managing their authorized users and promptly removing access for individuals who no longer require it.
4. Application Security
We incorporate security considerations into the development, testing, deployment, and maintenance of the Vida Verified platform.
Our application-security practices may include:
- Source-code review and change-management procedures
- Testing before material changes are released into production
- Dependency and software-package management
- Vulnerability identification and remediation processes
- Secure development and deployment practices
- Separation of development and production access
- Authentication and authorization controls
- Input validation and protections designed to reduce common application-security risks
- Review of material third-party integrations and service providers
We may perform automated vulnerability scanning, security assessments, and other testing based on the nature and risk of the applicable systems.
5. Data Minimization and Handling
Vida Verified is designed to collect and process information reasonably necessary to provide identity, professional credential, eligibility, monitoring, compliance, and verification services.
Depending on the Service, the information processed may include:
- Account and contact information
- National Provider Identifier information
- Professional and state-license information
- Drug Enforcement Administration registration information
- Social Security number or other identity-verification information
- Practice, organizational, and medical-director information
- Sanctions, exclusions, disciplinary actions, and public-record information
- Verification results, timestamps, monitoring alerts, and status changes
We apply controls designed to:
- Limit the collection of unnecessary information
- Restrict access to sensitive verification data
- Use information only for authorized purposes
- Limit disclosure to approved personnel, systems, service providers, and requesting parties
- Retain information only for as long as reasonably necessary or legally required
- Securely delete, anonymize, or isolate information when it is no longer required
Our retention practices may vary based on the type of information, the applicable Service, contractual requirements, and legal or regulatory obligations. Additional details are available in the Vida Verified Privacy Policy.
6. Credential Verification and Monitoring
Vida Verified obtains verification information from government agencies, licensing boards, federal registries, credentialing databases, public records, and approved third-party data providers.
Our Services may verify or monitor:
- National Provider Identifier records
- Professional and state licenses
- Drug Enforcement Administration registrations
- Identity information
- Sanctions and exclusions
- Disciplinary or adverse credential events
- Credential expirations, restrictions, suspensions, and status changes
- Provider relationships with healthcare practices and other organizations
Certain credential information may be checked periodically or nightly, depending on the data source, subscription, technical availability, and applicable Service.
Vida Verified does not control government, licensing-board, registry, or third-party databases. A source may experience delays, outages, inaccuracies, or reporting gaps. Users remain responsible for maintaining valid credentials and reporting material changes when required.
7. Payment Security
Subscription and service payments may be processed through third-party payment processors.
Vida Verified does not intend to store complete payment-card numbers within its application environment. Payment information is transmitted to and processed by authorized payment providers in accordance with their security and compliance obligations.
Users should not submit complete payment-card information through customer-support messages, email, or other unsecured communication channels.
8. Vendor and Third-Party Risk
We use service providers to support functions such as cloud hosting, identity verification, credential verification, payment processing, communications, analytics, security, and customer support.
Our vendor-management practices may include:
- Evaluating the nature and sensitivity of information a provider will process
- Reviewing relevant security, privacy, and compliance information
- Using contractual confidentiality and data-protection provisions
- Limiting provider access to information reasonably necessary to perform authorized services
- Reassessing material providers based on risk and business needs
Third-party systems remain subject to their own security practices, availability, and operational controls.
9. Logging, Monitoring, and Threat Detection
We maintain logging and monitoring capabilities designed to identify suspicious behavior, unauthorized access, system errors, and other potentially harmful activity.
Depending on the system and risk involved, these practices may include:
- Monitoring authentication and access activity
- Recording critical administrative actions
- Reviewing unusual or anomalous system activity
- Monitoring the availability and performance of critical services
- Investigating suspected unauthorized access or misuse
- Maintaining records to support security investigations and incident response
Monitoring information is accessible only to authorized personnel and service providers with a legitimate operational or security need.
10. Incident Response
We maintain an incident-response process designed to identify, investigate, contain, remediate, and recover from security incidents.
Our response process may include:
- Initial assessment and classification
- Containment of affected systems or accounts
- Investigation and evidence preservation
- Remediation of identified vulnerabilities
- Recovery and restoration of affected services
- Documentation and post-incident review
- Notification to affected individuals, customers, regulators, or other parties where required by law or contract
The timing and content of any notification will depend on the facts of the incident and applicable legal and contractual requirements.
Suspected security incidents involving a Vida Verified account should be reported promptly to security@medavida.com.
11. Business Continuity and Recovery
We maintain operational and technical measures designed to support the continued availability and recovery of our Services.
These measures may include:
- Data-backup procedures
- Service and infrastructure redundancy
- Recovery planning for critical systems
- Monitoring of system availability
- Procedures for responding to significant outages
- Periodic review of recovery dependencies and responsibilities
Service availability may still be affected by maintenance, third-party outages, cyberattacks, natural disasters, government actions, internet failures, or other circumstances outside our reasonable control.
12. Workforce Security
Personnel with access to Vida Verified systems or sensitive information are expected to follow applicable security and confidentiality requirements.
Our workforce-security practices may include:
- Confidentiality and acceptable-use obligations
- Security and privacy awareness training
- Role-based access authorization
- Multi-factor authentication for designated systems
- Procedures for reporting suspected incidents
- Access changes when job responsibilities change
- Prompt access revocation following separation or termination
- Disciplinary measures for unauthorized access or misuse
Access to sensitive information is restricted to personnel with a legitimate business need.
13. Compliance Program
Vida Verified's security and compliance practices are designed to support applicable privacy, healthcare, payment, contractual, and data-protection requirements.
Our compliance program may consider frameworks and requirements applicable to our Services, including:
- Health Insurance Portability and Accountability Act requirements where Vida Verified acts as a business associate or otherwise processes protected health information
- Payment Card Industry Data Security Standard responsibilities applicable to our payment environment
- Applicable federal and state privacy and data-breach notification laws
- Contractual security and confidentiality requirements
- Security-control frameworks used to guide the ongoing development of our information-security program
- Service Organization Control readiness and assurance activities, as applicable to our stage of development
The presence of a compliance program does not mean that Vida Verified holds a particular certification unless that certification is expressly identified as current and completed on this page.
We will update this section when additional independent audits, reports, or certifications have been completed and are appropriate for public disclosure.
14. Responsible Security Disclosure
We welcome good-faith reports from security researchers and others who believe they have identified a potential vulnerability in the Vida Verified platform.
Reports should be sent to security@medavida.com and should include:
- A clear description of the potential vulnerability
- The affected page, endpoint, feature, or system
- Steps reasonably necessary to reproduce the issue
- Relevant screenshots, logs, or supporting information
- Your contact information so we can follow up
When conducting security research, you must:
- Act in good faith
- Avoid accessing, modifying, downloading, deleting, or disclosing user information
- Avoid disrupting the Services or degrading system performance
- Avoid social engineering, phishing, physical testing, denial-of-service testing, or testing of third-party systems
- Use only accounts and data you own or are authorized to use
- Stop testing and notify us immediately if you encounter personal, confidential, or sensitive information
- Allow us reasonable time to investigate and address the issue before making it public
- Comply with applicable law
Submitting a report does not create an entitlement to payment. Vida Verified does not currently represent that it operates a public bug-bounty program.
We will review good-faith reports and communicate with researchers when reasonably appropriate. We cannot guarantee a particular response time or resolution.
15. Your Role in Security
Security is a shared responsibility. You can help protect your Vida Verified account by:
- Using a strong, unique password
- Enabling multi-factor authentication when available
- Keeping authentication codes and login credentials confidential
- Not reusing passwords from other services
- Limiting account access to authorized users
- Removing users who no longer require access
- Keeping your browser, device, and operating system updated
- Avoiding access through unsecured or public networks
- Reviewing account activity and verification information regularly
- Reporting suspicious activity, unexpected credential changes, or unauthorized access promptly
- Confirming that you are accessing the official Vida Verified website before entering sensitive information
Vida Verified will never ask you to provide your password by email.
16. Security Limitations
Although we use safeguards designed to protect information and systems, no security program can eliminate all risk.
Internet transmissions, cloud infrastructure, software, third-party services, government databases, licensing-board systems, and user devices may experience vulnerabilities, outages, or unauthorized activity.
Users should maintain appropriate internal controls and should not rely on Vida Verified as their sole security, compliance, credential-management, or fraud-prevention measure.
17. Changes to This Security Page
We may update this Security page as our technology, Services, controls, and compliance program evolve.
The "Last updated" date will identify the most recent revision. Material updates may also be communicated through the Vida Verified platform or other appropriate channels.
18. Contact the Security Team
Questions about our security practices or reports of suspicious activity may be directed to:
Medavida, Inc. Vida Verified Security Team Atlanta, Georgia, United States Email: security@medavida.com Website: www.vidaverified.com