Compliance
Tested with: Compliance programme status as of 2026-09
Status
Section titled “Status”| Programme | Status |
|---|---|
| HIPAA Security Rule controls | Ship with secure hosting (Phase 3). BAA available on Team and Enterprise. |
| SOC 2 Type I | Within three months after the HIPAA launch |
| SOC 2 Type II | After a six-month observation window |
| External penetration test | Before the HIPAA launch and yearly after; summary available under NDA |
| HITRUST, ISO 27001 | On customer demand |
| Accessibility (WCAG 2.2 AA) | See the accessibility statement; VPAT available |
HIPAA Security Rule mapping (summary)
Section titled “HIPAA Security Rule mapping (summary)”| Safeguard | Requirement | Mechanism |
|---|---|---|
| Administrative | Risk analysis and management | Annual risk assessment; per-change threat model for anything touching HIPAA cells |
| Administrative | Workforce security and training | Background checks; annual HIPAA training with attestation before staff get HIPAA roles; quarterly access reviews |
| Administrative | Information access management | Staff RBAC; production access to HIPAA cells only via break-glass with ticket, time-boxed, recorded |
| Administrative | Contingency plan | Hourly backups + PITR, cross-region, Object Lock; quarterly DR exercise; published RTO/RPO |
| Administrative | Business associate contracts | Our BAA with you; BAAs with sub-processors (AWS); payment and email providers receive no PHI |
| Physical | Facility, workstation, device controls | Cloud provider SOC reports; MDM-managed staff devices; no PHI on workstations |
| Technical | Access control | Unique ids; emergency access = break-glass; portal sessions expire 12 h absolute / 30 min idle on HIPAA orgs; encryption at rest with per-org keys |
| Technical | Audit controls | Every control-plane, admin and break-glass action; six-year retention; hash chain + Object Lock export |
| Technical | Integrity | Backup checksums, verified restores, Object Lock, signed images |
| Technical | Person or entity authentication | MFA required for all members of HIPAA orgs; WebAuthn for staff |
| Technical | Transmission security | TLS 1.2+ at the gateway; internal mTLS; no plaintext ports |
| Breach notification | 60-day notification | Incident process with a HIPAA breach decision tree; customer contact registry; target 72 hours |
Evidence and questionnaires
Section titled “Evidence and questionnaires”Team and Enterprise customers can download the current SOC 2 report (when issued), the penetration test summary, the sub-processor list and a completed security questionnaire (CAIQ and SIG Lite) from Compliance → Documents. Evidence is collected weekly by automation (IAM listings, MFA status, policy reports, backup verification results) and feeds our compliance platform, so reports reflect the current state.