Last Modified: June 5, 2025
This Privacy Statement describes how Verisma Systems, Inc. and its affiliates (collectively, “Verisma”) may collect, use, transfer, and/or store “Personal Information,” meaning information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or members of your household.
Verisma acts as a Business Associate under HIPAA and processes Personal Information and Protected Health Information (PHI) on behalf of healthcare providers, payers, and other covered entities. Patients with questions regarding their rights to access or amend PHI should follow the Notice of Privacy Practices of the applicable healthcare provider or entity.
This Privacy Statement applies to all non-marketing-related portal applications and domains that Verisma may use in conjunction with the delivery of its services, including:
Verisma’s marketing-related websites are governed by a separate Privacy Statement available at: https://verisma.com/verisma-online-privacy-statement/
By using the Services, you agree to this Privacy Statement. This Privacy Statement may be updated periodically without prior notice to reflect changes in our information practices. The date above indicates when this statement was last revised.
This Statement is not intended to create any contractual or legal rights for any third party. Verisma is not responsible for the content or privacy practices of third-party websites and encourages users to review the privacy statements of any website that collects personal information.
Verisma collects Personal Information that you voluntarily provide to us or to the covered entities we service. Types of information collected may include:
Verisma uses this information exclusively to process, track, and fulfill Release of Information requests, keep users informed about request status, administer accounts, process payments, detect fraud, and improve our Services.
From time to time, Verisma may use Personal Information to send important notices regarding changes to policies, terms, or Services. Information may also be used internally for auditing, analytics, and research purposes.
For its Services and portal applications, Verisma does not use third-party tracking technologies such as:
Microsoft Azure Analytics, which maintains HIPAA Business Associate compliance and SOC 2 Type II certification, may be used solely for internal technical support purposes. Data collected through Azure Analytics is not shared with Microsoft or any other third party.
Verisma may use artificial intelligence (AI) and machine learning technologies to assist in processing healthcare data, including:
These technologies do not replace human review. All AI processing occurs within Microsoft Azure’s HIPAA-compliant cloud infrastructure, and no Protected Health Information is used to train AI models. Every AI-generated output requires human oversight before any consequential decision is made.
Verisma maintains an internal AI and Data Governance Committee responsible for:
Verisma undergoes ongoing surveillance audits as part of its HITRUST recertification cycle and maintains HITRUST r2 certification on a standard two-year schedule.
For AI governance, HITRUST certification confirms:
Verisma is required by healthcare providers it serves to retain copies of medical records provided to requesters. These records are maintained to support quality monitoring, regulatory oversight, and other business purposes.
Access to Personal Information is restricted to authorized Verisma personnel and approved third parties who assist in providing Services and conducting business operations.
Verisma may disclose Personal Information in connection with a potential sale of the company or its assets, provided any receiving party agrees to privacy protections equal to or greater than those outlined in this Statement.
Without your express authorization, Verisma will not sell, license, transmit, or disclose Personal Information to other parties.
Verisma employs administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, disclosure, or misuse. Security practices are reviewed and updated periodically.
Verisma may collect information that cannot be directly associated with a specific individual and may use or disclose such information for any lawful purpose.
Examples include:
Users may disable cookies through their browser settings. While doing so generally will not prevent use of the Services, some features may not function properly.
Verisma does not knowingly collect or use personal information from children age 13 or younger and does not knowingly permit such individuals to use its Services except where legally permitted.
If a parent or guardian believes a child has provided information to Verisma, they should contact Verisma using the information provided below.
Verisma’s Services are not intended for use by individuals under 18 years of age without prior written permission. Limited exceptions may apply for emancipated minors or individuals otherwise authorized by law.
Verisma’s websites and Services are not directed to children under 13 years of age. Any use by individuals under 13 is prohibited unless a legally recognized exception applies and appropriate authorization has been obtained.
California residents may exercise certain rights under the California Consumer Privacy Act, including:
California residents may also request that their healthcare provider direct Verisma to delete personal information from Verisma’s databases where applicable.
If you have questions regarding this Privacy Statement, please contact:
Email:
ROIPrivacy@verisma.com
Verisma Systems, Inc.
Attn: Privacy Officer
1750 Founders Parkway
Suite 130
Alpharetta, GA 30009
866-390-7404 | © Copyright 2026 Verisma Systems, Inc.