Security & privacy

You are holding medical records. We built for that.

Every file in this system is somebody’s service history and medical evidence — the most sensitive paperwork most people will ever hand to a stranger. This page is exactly how it is protected, in plain terms, written so you can forward it to your malpractice carrier without translating it first.

Six things we do

How your clients’ records are protected.

  • Encrypted in transit and at rest

    Everything moving between your browser and the platform is encrypted with TLS. Everything sitting on disk — records, uploads, signed forms — is encrypted at rest, and so are the backups.

  • SSNs encrypted separately and masked

    Social Security numbers are encrypted at the field level, on top of the encryption protecting the rest of the record, and they display masked — •••-••-4417 — by default. Revealing one is a deliberate action, and it is written to the audit log with the name of whoever did it.

  • Role-based access controls

    Every person on your team has a role, and roles decide what they can open, change and export. Two-factor authentication is available for every account, and removing someone ends their access to firm files.

  • Audit logs of sensitive actions

    Views, changes, exports, document downloads and SSN reveals are written to a log with a person, an action and a timestamp. If you are ever asked who saw what and when, the answer exists.

  • SOC 2 certified infrastructure

    The platform runs on SOC 2 certified infrastructure — managed hosting and storage with independently audited controls — with encrypted backups and a recovery process that has been tested rather than assumed.

  • HIPAA-aware practices

    The product is built around the medical evidence these files carry: minimum-necessary access, retention rules, masked identifiers and documented handling of protected information.

How access works

You decide who can open which file.

Access is not a global switch. It is a decision the firm makes, per person and per file, and the system holds you to it.

  1. Owners and admins hold the keysThe firm owner decides who joins the team and what each role is allowed to do. Nobody at VA Claim Net adds people to your account.
  2. Staff see the files you assignA paralegal opens the clients and claims they are working, not the whole cabinet. Change the assignment and their view changes with it.
  3. Sensitive fields are a separate decisionIdentifiers stay masked until someone deliberately reveals them, and that reveal is logged with a name, a record and a time.
  4. Removal is immediateTake someone off the team and their access to firm files ends. Their history stays in the audit log, which is exactly where it belongs.

Team & permissions

Whitfield & Associates · 5 people · 2 representative seats

2FA on for all
PersonRoleCan open
Dale R. WhitfieldOwner · RepAll firm files
Nina O. VasquezRepAll firm files
Dana R. KimStaffAssigned files · 34 clients
Trey AlsopStaffAssigned files · 12 clients
Marisol VaneIntake onlyNew intakes, no documents

Audit log · today

  • Dana R. Kim revealed SSN onMarcus D. Whitfield4:12 p.m.
  • Dale R. Whitfield exported claim report1:58 p.m.
  • Trey Alsop downloaded DD-214 fromTommy V.11:07 a.m.

Your data

It is your practice’s data. We just hold it carefully.

  • Export any timeClients, claims and documents come back out in standard formats — during the trial, mid-subscription, or on your way out the door.
  • Deletion on requestAsk us to delete your firm’s data and we do it, subject to the retention your own records obligations require.
  • We do not sell your dataNot to data brokers, not to lead vendors, not to anyone. Your client list is not a product we have.
  • No ads, everNobody advertises to your veterans inside their portal, and nothing in their file feeds a marketing profile.

Built for the files you are actually holding.

Start the trial and look at it yourself — the audit log is on from your first login.

Sold only to VA-accredited representatives, agents and attorneys.