PHI Data Protection
Disclaimer: The information on this page is provided for general informational purposes only and is not legal advice. It describes StemVera Health's data protection practices at a high level and does not create an attorney-client relationship or any contractual obligation. For legal questions about HIPAA or your privacy rights, please consult a qualified attorney. In the event of any conflict between this page and our HIPAA Notice of Privacy Practices or Privacy Policy, those documents control.
Effective Date: June 28, 2026
Last Updated: June 28, 2026
StemVera Health takes the protection of your Protected Health Information (PHI) seriously. This page explains, in plain language, where your health information lives, how it is safeguarded, and the controls we rely on to keep it confidential, accurate, and available only to the people who need it to care for you.
What we mean by PHI
Protected Health Information (PHI) is any information that identifies you and relates to your health, care, or payment for care. Examples include your name paired with a medical condition, medication, dosage, lab result, appointment, or clinical questionnaire response.
Two separate environments
StemVera Health operates two distinct systems, on purpose, so that PHI is kept away from our public marketing site:
-
Marketing website (this site, stemvera.com). This site contains educational content, product information, and general lead contact forms (name, email, phone, state, area of interest, message). No PHI is stored here. No clinical intake, health history, or medical questionnaires are collected on this site.
-
Clinical care platform (separate, HIPAA-compliant environment). All appointment scheduling, patient intake, health questionnaires, clinical messaging, prescriptions, and medical records are handled inside a dedicated HIPAA-compliant clinical environment hosted on Google Cloud, operating under a signed Business Associate Agreement (BAA). When you click Get Started, Book, or any appointment link, you are handed off to that separate, secured system.
HIPAA-compliant infrastructure
Our clinical environment is designed to meet HIPAA's Security Rule requirements, including:
- Business Associate Agreements (BAAs) with every vendor that may touch PHI, including our cloud hosting provider, database provider, and any third-party services used to deliver care.
- Encryption in transit using TLS 1.2 or higher for all connections between your device, our systems, and our clinicians.
- Encryption at rest for all databases, backups, and file storage that contain PHI, using industry-standard AES-256 encryption.
- Isolated infrastructure so that PHI never traverses or is stored on the public marketing site's systems.
Access controls
Access to PHI is limited to the minimum necessary to provide your care:
- Role-based access. Clinicians, pharmacy staff, and support agents only see the records required for their specific role.
- Individual accounts. Every workforce member has a unique login. Shared accounts are prohibited.
- Multi-factor authentication (MFA) is required for all workforce accounts that can access PHI.
- Audit logging. Every access, view, edit, and export of PHI is logged and retained so we can investigate any suspected misuse.
- Automatic session timeouts on clinical systems to reduce the risk of unattended sessions.
Workforce training and accountability
Every employee and contractor with potential access to PHI completes HIPAA privacy and security training at onboarding and annually thereafter. Workforce members sign confidentiality agreements, and violations of our privacy policies are grounds for disciplinary action, up to and including termination and referral to authorities.
Data minimization
We collect only the health information necessary to evaluate, prescribe, and monitor your care. We do not sell PHI. We do not use PHI for advertising or marketing without your written authorization, and we do not share PHI with third parties except as permitted or required under HIPAA and described in our HIPAA Notice of Privacy Practices.
Backups, availability, and integrity
- Encrypted backups are performed on a regular schedule and stored in geographically separate, access-controlled locations.
- Integrity monitoring helps detect unauthorized changes to records.
- Disaster recovery procedures are tested so that your records remain available to your care team when you need them.
Incident response and breach notification
We maintain a documented incident response plan. If we discover a breach of unsecured PHI, we will notify affected individuals, the U.S. Department of Health and Human Services, and (where required) the media, in accordance with the HIPAA Breach Notification Rule and applicable state laws.
Your rights
You have the right to access, amend, and request an accounting of disclosures of your PHI, to request confidential communications, and to file a complaint if you believe your privacy rights have been violated. Full details are in our HIPAA Notice of Privacy Practices.
Questions or concerns
If you have questions about how your PHI is protected, or if you would like to report a suspected privacy or security concern, please contact our Privacy Officer:
StemVera Health, Privacy Officer
Phone: 888-902-4781
Email: info@stemvera.com
Mail: 1500 N Grant St #7131, Denver, CO 80203