Compliance & Security

Protecting sensitive health information is foundational to everything we do. Verisma combines experienced professionals, rigorous processes, and secure technology to help healthcare organizations confidently manage health information exchange while supporting regulatory compliance.

Privacy and Security

The security and handling of protected health information (PHI) of our clients is paramount to the technology and services we provide. We are committed to complying with all applicable federal and state laws pertaining to the privacy and confidentiality of PHI and will maintain the highest safeguards to prevent unauthorized access and disclosures.

Our HITRUST-certified Verisma Release Manager™ platform has been built around stringent security protocols with optimal performance and uptime, and is designed to protect sensitive data at rest and data flowing between health systems and our infrastructure.

Data Protection

  • PHI secured in transit using TLS and SSL encryption.
  • PHI at rest encrypted using AES-256 encryption.
  • Security protocols designed to protect sensitive data exchanged between health systems and Verisma infrastructure.

Compliance-Driven Operations

Technology is only one part of a strong compliance program. Verisma supports privacy, security, and compliance through ongoing employee education, operational oversight, quality controls, and documented processes designed to help protect sensitive information throughout the release lifecycle.

Training and Compliance

As part of our commitment to providing an expert, knowledge-based release management solution, Verisma provides a web-based training program with 24/7 access to training material across multiple educational tracks.

  • Employees receive client-specific training beginning during implementation to better understand and incorporate each client’s ROI policies and procedures into the daily workflow.
  • All Verisma employees attend mandatory monthly training covering topics ranging from HIPAA to product updates and releases.
  • Ongoing education helps keep teams current on applicable federal and state regulatory requirements, including HIPAA and HITECH.