Compliance for provider organizations
Plain language for compliance officers and counsel evaluating LastVet. If anything here is wrong, we correct it on last.vet/claims.
Provider agreement
A standard provider agreement is in drafting with outside counsel now, and the health-data regulatory posture — including what agreements are required before any PHI is exchanged — is under review with health-data counsel. We will not exchange PHI with a provider organization before the appropriate agreement is executed. If your compliance team needs to review terms before that's final, contact us and we'll share where it stands.
Consent and PHI access
Provider access is grant-based. You see only the categories a veteran has authorized, under the purpose they approved. Every access event is logged and visible to the veteran. Veterans can revoke access at any time. LastVet is a coordination layer, not an EHR or system of record. Clinical charting stays in your EHR.
Where data lives
HIPAA-eligible AWS infrastructure (us-west-2) under an executed BAA with AWS. Veteran-directed data is encrypted at rest. API access is consent-gated with row-level security.
42 CFR Part 2
Substance use disorder categories require separate explicit veteran authorization. Part 2-gated data is withheld until that authorization is on file.
SHIELD standard
LastVet is built on the SHIELD standard: Sovereign, Holistic, Integrated, Encrypted, Live, Distributed.
SOC 2
Not certified. A SOC 2 program is pending, not parked. We do not claim certification today.