Legal · Privacy
Last updated April 2026
Velora EDI ("Velora," "we," "us," or "our") is committed to protecting the privacy and security of the information we process on behalf of our clients and their members. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our AI-powered EDI clearinghouse platform and related services (collectively, the "Service"). By accessing or using the Service, you agree to the terms of this Privacy Policy.
In the course of providing EDI clearinghouse services, we receive and process Protected Health Information as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This includes, but is not limited to: enrollment data, member demographic information (names, dates of birth, Social Security Numbers), health plan identifiers, group numbers, carrier information, and benefit election data transmitted via ANSI X12 834 transactions.
We collect information you provide when creating an account, including your name, email address, company name, and billing information. We also automatically collect usage data such as API call logs, IP addresses, browser type, access timestamps, pages viewed, and system performance metrics.
We collect device identifiers, operating system information, and other technical data necessary to maintain the security and performance of the Service.
We use the information we collect for the following purposes:
Velora EDI operates as a Business Associate under HIPAA. We process PHI solely as directed by our clients (Covered Entities or their Business Associates) and in accordance with executed Business Associate Agreements (BAAs). We maintain a comprehensive HIPAA compliance program that includes:
We implement industry-leading security measures to protect all data processed through our Service:
We retain PHI and transaction records for a minimum of seven (7) years from the date of the transaction, in compliance with HIPAA record retention requirements and applicable state and federal regulations. Upon expiration of the retention period, data is securely destroyed using NIST 800-88 compliant methods.
Account and usage data is retained for the duration of your active account and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
We do not sell, rent, or trade your information. We disclose information only in the following circumstances:
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
With respect to PHI, individual rights are governed by HIPAA and should be directed to the applicable Covered Entity (your employer or plan sponsor). We will cooperate with Covered Entities to fulfill individual rights requests related to PHI.
We use strictly necessary cookies and similar technologies to operate the Service, maintain session state, and authenticate users. We do not use third-party advertising cookies or tracking pixels. Analytics cookies, if used, process only aggregated, de-identified data. You may configure your browser to refuse cookies, though this may limit your ability to use certain features of the Service.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on our website with an updated "Last updated" date and, where required, by providing direct notice via email. Your continued use of the Service after such changes constitutes acceptance of the revised policy.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Velora EDI — Privacy Office
Email: privacy@veloraedi.com
Web: https://veloraedi.com
For HIPAA-related inquiries, including breach notifications or requests related to PHI, please contact our HIPAA Privacy Officer at the address above.