Security Statement
Last updated: September 11, 2026
Your privacy, our priority
Where HIPAA applies, we follow its privacy and security requirements, along with other applicable federal and state laws.
Vytal Path is a consumer health information service. HIPAA applicability can depend on the particular relationship, service, information, and circumstances. This statement should not be read as a blanket representation that every Vytal Path activity is governed by HIPAA or as a third-party certification. Vytal Path applies applicable legal requirements where they govern and maintains a security program designed to protect consumer health information.
Account security
Passwords are not stored in plain text. Vytal Path uses salted password hashing designed to resist brute-force attacks. Login protections include rate limiting and lockout controls. Two-factor authentication is available for additional protection, and Vytal Path may require additional verification for sensitive actions, including authentication changes, connected-health actions, and data-deletion operations.
Encryption and infrastructure
Traffic between supported clients and Vytal Path is protected in transit using HTTPS/TLS. Production health and account data is stored using private cloud infrastructure with encryption controls. Current AWS architecture includes private Amazon RDS PostgreSQL database resources for structured application data and Amazon S3 for applicable uploaded documents such as lab PDFs. Access is restricted through application and cloud access controls rather than direct public database access.
Cloud and AI security
Vytal Path uses Amazon Web Services for applicable production infrastructure and Amazon Bedrock for supported AI processing. Access to cloud resources is controlled using role-based permissions and least-privilege principles. Secrets and credentials are kept out of client-side code and are managed using protected server-side configuration or secrets-management services.
Monitoring and auditability
Vytal Path maintains security and audit logging for important account, administrative, and system events. Cloud monitoring, security alerts, and audit services are used to detect and investigate suspicious or unexpected activity. Access attempts that violate authorization controls may be logged for security review.
Data protection practices
Vytal Path uses access controls, caregiver authorization checks, sensitive-action verification, encrypted transport and storage controls, protected secrets, restricted document storage, security logging, and operational monitoring. Security risks are reviewed as the architecture changes, and identified issues are addressed based on risk.
No online service can guarantee absolute security. Security controls reduce risk but cannot eliminate it.
Incident response and breach notification
Vytal Path maintains incident-response and recovery procedures. If a security incident results in unauthorized acquisition, access, use, or disclosure that triggers notification duties, Vytal Path will investigate, contain, document, and provide notifications required by applicable law. Depending on the circumstances, applicable requirements may include the FTC Health Breach Notification Rule, HIPAA breach-notification requirements where HIPAA applies, and federal or state breach-notification or consumer-health laws.
Ongoing compliance
Security and privacy compliance is an ongoing process, not a one-time technical test. Vytal Path reviews risks, policies, vendor relationships, access controls, and technical safeguards as the service changes. Where HIPAA applies to a particular Vytal Path activity or relationship, Vytal Path follows the applicable HIPAA privacy and security requirements for that activity, including required administrative, physical, and technical safeguards and appropriate agreements where required.
Vytal Path does not describe itself as "HIPAA certified." No statement on this page is a guarantee that a security incident can never occur.
Reporting security issues
If you discover a potential security issue involving Vytal Path, report it promptly using the Contact Us information so it can be investigated.
