Skip to main content
Security

How we handle patient data

Short, specific, and written to be read by whoever fills in your security questionnaire. If something here is not clear enough to answer a question on that form, tell us and we will fix the page.

Last reviewed 29 August 2026

We sign a Business Associate Agreement

Before any work starts with a clinic, we sign a BAA. It sets out what we may handle, what we may not, and what happens if something goes wrong.

We describe what we do, not what we are certified as. There is no body that certifies a company as HIPAA compliant, so we do not use the phrase. What we can tell you is which safeguards are in place, and this page is where we write them down.

Patient data stays in your systems

Patient records live where they already live — in your booking and practice systems. We do not copy them into ours.

VisionOne stores aggregate numbers: how many leads arrived from a channel, how many calls were answered, how many appointments were booked, what that is estimated to be worth. Counts and totals, not people. If our database were opened tomorrow, there would be no patient records in it to read.

Marketing systems never receive patient data

Ad platforms and marketing tools get campaign data. They never receive patient identity, appointment details or anything that would indicate a person is a patient of yours.

We also do not put advertising or remarketing pixels on this page, on our contact form, or anywhere a visit could reveal a healthcare relationship. That is a deliberate choice, and it is the one most easily broken by accident, so we check it.

Subprocessors, disclosed by name

Any third party involved in delivering your work is disclosed by name on request, along with what it is used for. Ask and we will send the current list — we would rather you had it before you sign than discover it afterwards.

Controls in place

Data is encrypted in transit and at rest. Access is role-based — people get the access their job needs and no more. Access to client systems is logged.

If your questionnaire asks about a control that is not listed here, ask us directly. We will tell you whether we have it, rather than answering with something adjacent.

Where the work is done

Our engineering and support teams work from India. We are telling you this here rather than leaving you to discover it later, because it appears on nearly every healthcare security questionnaire.

The controls above do not change by location. Everyone working on your account is bound by the same obligations that flow down from the BAA. Access stays role-based and logged wherever the person sits. And the point in section two applies to every one of them: there are no patient records in our systems to access.

Asking us a security question

Send the questionnaire, or just the question. A person who knows the answer will reply — typically within one business day.

Email hello@visiondigitallab.com or use the contact form.