Trust Center

Your trust is our priority. Learn about our comprehensive approach to security, privacy, and compliance.

Our Security Commitments

We maintain the highest standards of security and compliance to protect your data and your patients’ privacy.

HIPAA Compliant

Full compliance with HIPAA Privacy and Security Rules, including regular audits and assessments.

SOC 2 Type II​

Independently verified controls for security, availability, and confidentiality.

Enterprise Encryption

256-bit AES encryption for data at rest and TLS 1.3 for data in transit.

Security Features

Data Encryption

All patient data is encrypted using industry-standard AES-256 encryption at rest and TLS 1.3 in transit. Encryption keys are managed using AWS KMS with automatic rotation.

Access Controls​

Role-based access controls (RBAC) with multi-factor authentication (MFA). Granular permissions ensure users only access data necessary for their role.

Infrastructure Security

Hosted on SOC 2 compliant cloud infrastructure with 24/7 monitoring, intrusion detection, and automated threat response.

Audit Logging

Comprehensive audit logs track all system access and data changes. Logs are encrypted, tamper-proof, and retained for compliance.

Penetration Testing

Regular third-party penetration testing and vulnerability assessments to identify and address security risks proactively.

Disaster Recovery

Automated backups with 99.999% durability. Recovery Point Objective (RPO) of 1 hour and Recovery Time Objective (RTO) of 4 hours.

Compliance & Certifications

HIPAA

Privacy & Security Rules

SOC 2 Type II

Security & Availability

HITRUST

CSF Certified

GDPR

EU Data Protection

Privacy & Data Protection

Data Minimization

We collect and process only the data necessary to provide our research services. All patient data is fully de-identified and HIPAA compliant. Patient data is never used for purposes beyond research and is never sold to third parties.

Data Residency

All data is stored in HIPAA-compliant data centers within the United States. We offer data residency options to meet regional compliance requirements.

Data Retention

We retain de-identified patient data in accordance with HIPAA requirements and research standards. Data is maintained to support longitudinal studies while respecting all privacy regulations.

Third-Party Vendors

All third-party vendors undergo rigorous security assessments. We maintain Business Associate Agreements (BAAs) with all vendors who may access protected health information.

Privacy & Data Protection

Our patient 360 data powers critical research and clinical applications across the healthcare ecosystem.

Security Whitepaper

Detailed overview of our security architecture and practices.

Download PDF

SOC 2 Report

Available under NDA for prospective customers.

Request Report

Privacy Policy

Our commitment to protecting your data and privacy.

View Policy

BAA Template

Standard Business Associate Agreement for HIPAA compliance.

Download Template

Security Datasheet

Quick reference guide to our security features.

Download PDF

Compliance Guide

Guide to using HealthTech in a compliant manner.

Download PDF

Questions About Security?

Our security team is here to answer your questions and provide additional documentation.