How VA Protects Your Information
VA is committed to providing the highest-quality care when you visit VA facilities and when you access care using telehealth and other online tools. A core part of this commitment is protecting sensitive health data through all measures available, including encryption, the use of secure platforms, and compliance with Health Insurance Portability and Accountability Act (HIPAA) standards.
VA’s approach to privacy and security as part of telehealth is rooted in trust and transparency — trust that your data is guarded and used appropriately and transparency concerning how your data is used.
These principles are put into practice with VA’s key security measures for telehealth.
All Veteran Data Is Encrypted
VA uses industry-standard encryption for all telehealth sessions to protect health data during transmission through the internet. This includes the use of the Secure Sockets Layer (https://), which creates a secure connection to send data.
VA Platforms Meet Modern Standards for Security
VA’s platforms store health information in a secure environment on VA’s web servers. To further protect your information and make it simple for you to access care online, VA has consolidated the log-in options to Login.gov and ID.me. With those two options, you can sign in to accounts on VA.gov, My HealtheVet, the VA: Health and Benefits app, and more. Both Login.gov and ID.me meet modern security standards and allow you to use a single secure account to access VA benefits and services. VA also undergoes regular audits to ensure that its systems comply with federal regulations for security.
VA Complies With HIPAA Privacy Rules
VA follows strict privacy policies aligned with HIPAA to ensure that access to your data is limited to authorized personnel. VA aims to provide full transparency into the ways in which your data is used and to give you options for reporting any concerning activity.
Multifactor Authentication Boosts Security
VA uses multifactor authentication to ensure that only you and any authorized personnel have access to your sensitive health data. Multifactor authentication requires an email address, password, and at least one other authentication factor, such as a cell phone that can receive a security code in a text message.
Learn more about VA’s privacy and security policies.Addressing Privacy Concerns
VA is here to address any concerns you may have about privacy when using telehealth services. Please contact the VA Privacy Service at PrivacyService@VA.gov or 202-273-5070 with any questions or concerns.
You may also submit a privacy concern by mail to the following address:
U.S. Department of Veterans Affairs
Privacy Service
810 Vermont Ave. NW (005R1A)
Washington, DC 20420
If you have witnessed or been subjected to a privacy violation, follow these steps to report a privacy complaint.