Veridoc FAQ

HIPAA-grade cross-border patient consent, with a blockchain chain of custody that any auditor, payer, or regulator can independently verify.

01

What is Veridoc and what problem does it solve?

Veridoc is an AI medical concierge for cross-border care with a blockchain-verified chain of custody for every patient consent. Paper consent is not legally defensible across jurisdictions — a Thai patient treated in Bangkok, whose records are later reviewed by a U.S. insurer or home physician, has no auditable proof that the consent was informed, in-language, and unaltered. For the broader compliance story and our network overview, see our full resource library.

02

How does notarized consent submission work end-to-end?

The patient receives a one-time consent link tied to a specific consent record. They review the form in their preferred language, sign with a cryptographically-bound e-signature (21 CFR Part 11), and at the moment of signature Veridoc computes a SHA-256 hash of the payload and appends it to a tamper-evident hash chain. From that point on, the record carries an immutable proof: the exact form version, the exact timestamp, the exact device. The intake flow is live at veridoc.health/consent.

03

What does the chain-of-custody proof show a verifier?

Anyone holding the record link can render a public audit view: the consent payload, the cryptographic hash anchoring it on the chain, the form version signed, the timestamp, and the device/IP context. The proof is independently verifiable — verifiers do not need to trust Veridoc, only the cryptography and the chain. To see exactly what a counterparty sees, render a sample record at veridoc.health/verify/<recordId>.

04

Who is allowed to verify a Veridoc consent record?

Verification is public-by-design — anyone holding the record link can render the audit view. The strength of the proof comes precisely from not depending on trusting us. In practice the verifiers fall into three groups: the patient's payer or insurer disputing a claim, regulators or licensing bodies auditing cross-border care, and the patient's home physician coordinating aftercare. Every public load is itself logged. See our partner directory for who uses Veridoc today, and the resource hub for the chain-of-custody discussion.

05

What happens when a hospital voids a previously issued consent?

Consent records on Veridoc are insert-only — once notarized, a record cannot be edited or deleted. A void is itself a new event appended to the chain: the issuing hospital issues a signed revocation referencing the original record, with clinician identity, timestamp, and reason. From that moment, any verifier sees both the original notarized consent and the revocation trail. Intake-side prevention — making voids rare — is handled on the consent flow at veridoc.health/consent; the immutability policy is discussed in our resource hub.

06

Where is patient data stored, and who can read it?

Patient identifiers live in a HIPAA-controlled environment under a signed Business Associate Agreement; the on-chain record carries a cryptographic hash of the consent, not the PHI itself. Access is role-scoped: the patient sees their own record, the treating clinician sees records for their patients, the hospital admin sees records their hospital issued, and auditors and counterparties see only what the public record link exposes. The full controls breakdown is in our HIPAA consent checklist.

07

How does a patient get a copy of their own consent record?

Every notarized consent is assigned a numeric record id at signing. The patient receives that id (and a matching audit link) at submission, so they always have a permanent reference — independent of email or hospital portal access. To render their own record in plain language (hospital, procedure, signed-at timestamp), they visit veridoc.health/r/<recordId>. For the full audit view (hash chain, device, form version) they visit veridoc.health/verify/<recordId>. The record id IS the auth token.

08

How can a hospital get onboarded as a Veridoc pilot?

Pilot onboarding begins with a signed Business Associate Agreement and a short scoping call covering your hospital's consent flows, EMR integration points, and target languages. Implementation typically completes in under a week, including a parallel-run period where digital and paper consent coexist. Start by booking a demo at veridoc.health/demo to see the platform on your own procedures, then visit veridoc.health/partners for the pilot-application flow and partner-agency terms.

Talk to the team

See Veridoc on your own procedures, partner network, and consent workflows — or scope a pilot.