Who it protects
CurrentHIPAA
Institutions and the data they hold
SHIELD
The person the data belongs to
LastVet standard
HIPAA was written in 1996 to protect institutions handling health data. It set the legal minimum. It was not written for sovereignty.
SHIELD was built for the people the data belongs to. It adds stronger veteran-controlled workflows where we have implemented them today.
S · H · I · E · L · D
The standard
SHIELD is LastVet's data standard for veteran-controlled health information. It exceeds HIPAA in every dimension, and every architectural decision is checked against it before it ships.
LastVet is designed to meet HIPAA requirements and add stronger veteran-controlled workflows. The rows below describe current LastVet capabilities.
CurrentRoadmapBadges show what is shipped now versus what is still in build-out.
Capabilities are built and verified in production against the VA sandbox. VA production data access is in review, not yet approved.
HIPAA
Institutions and the data they hold
SHIELD
The person the data belongs to
HIPAA
Healthcare providers and covered entities
SHIELD
The Veteran
HIPAA
Permits sale of de-identified data. Institutions monetize routinely.
SHIELD
No one. No advertising, ever. No data sale. No model training on identified data. Veterans are never charged.
HIPAA
Broad authorization at intake, often buried in paperwork
SHIELD
Granular, per-category, per-recipient, plain-language
HIPAA
Written request, processed at the institution's pace
SHIELD
Immediate. Same screen. No grace period.
HIPAA
Disclosures permitted for treatment, payment, and operations, often without the patient's awareness
SHIELD
No automatic notification, ever. The veteran chooses if and when their care team is told.
HIPAA
Patient must request audit logs in writing
SHIELD
Veteran can view logged access events in the app
HIPAA
"Right to access" - institution decides format and timeline
SHIELD
Veteran can export a portable record summary today. Structured data export is in build-out.
HIPAA
Standard PHI protections
SHIELD
SUD records are dual-gated behind a separate, explicit consent flow, handled above standard PHI requirements
HIPAA
Each institution maintains its own siloed record
SHIELD
Providers can add coordination notes when the veteran grants write access. Their clinical charting stays in their own EHR.
HIPAA
Disclosure required, but often opaque
SHIELD
Veteran sees who has access, what they accessed, and when
HIPAA
Fax, paper, manual records requests
SHIELD
A veteran-controlled record workspace that supports connected care coordination
HIPAA
Required for institutional systems
SHIELD
Encrypted at rest and in transit, with row-level security enforced at the database itself, on HIPAA-eligible infrastructure under a signed BAA
HIPAA
Compliance and liability protection
SHIELD
Veteran sovereignty and healthier outcomes
HIPAA was written in 1996, before smartphones, before patient portals, before the modern reality that healthcare data moves through dozens of systems before it reaches the person it belongs to. It set the legal minimum for protecting health information at institutions. It was never designed to give patients sovereignty. We are building to HIPAA requirements and adding stronger veteran controls where the floor is not enough.
Veterans navigate one of the most fragmented care ecosystems in the country - the VA, DoD, community providers, mental health services, peer support networks, family practitioners. Every transition creates a gap. Every gap loses information. HIPAA compliance does not solve this. Veteran sovereignty does. When the veteran owns the record, the gaps close.
Sovereign. Holistic. Integrated. Encrypted. Live. Distributed. Every architectural decision in LastVet is checked against SHIELD before it ships. If a feature doesn't make the system more sovereign, more holistic, more integrated, more encrypted, more live, or more distributed - it doesn't get built. SHIELD is not marketing. It is how we work.
LastVet is built on SHIELD. Your data, your rules.