Compliance Roadmap
What controls ConnectHL7 has in place today and what is in progress or planned, including SOC 2 and HIPAA alignment.
We believe in being transparent about where we are on our compliance journey. This page shows what ConnectHL7 has in place today, what we are actively working toward, and what is planned for the future.
We do not claim certifications we have not yet achieved. Where an initiative is in progress or planned, we say so plainly. This page reflects our status as of the date below and is updated as we make progress.
Our approach to compliance
ConnectHL7 aligns its security program with widely recognized frameworks relevant to healthcare SaaS:
- SOC 2 Trust Services Criteria (Security, Availability, Confidentiality)
- HIPAA Security Rule, where applicable to PHI
- AWS Well-Architected Framework — Security Pillar
- CIS Controls
- OWASP secure development practices
We build our controls to these standards now, so that formal attestation is a validation of how we already operate rather than a scramble to prepare.
Current — in place today
These controls are operational today:
| Area | Status |
|---|---|
| Documented security policies established | ✅ In place |
| Multi-factor authentication (MFA) enforced | ✅ In place |
| Encryption in transit (TLS 1.2+) | ✅ In place |
| Encryption at rest (AES-256) | ✅ In place |
| Role-based, least-privilege access control | ✅ In place |
| Centralized, tamper-resistant logging | ✅ In place |
| Continuous infrastructure & threat monitoring | ✅ In place |
| Automated, encrypted backups | ✅ In place |
| Secure software development lifecycle (SDLC) | ✅ In place |
| Infrastructure as Code | ✅ In place |
| HIPAA Business Associate Agreements (BAAs) available | ✅ In place |
Near term — actively in progress
These initiatives are underway:
| Initiative | Status |
|---|---|
| Independent third-party penetration testing | 🔄 In progress |
| SOC 2 Type I examination | 🔄 In progress |
| Formalized evidence collection for audit | 🔄 In progress |
SOC 2 Type I evaluates whether our controls are suitably designed at a point in time.
Future — planned
These are on our roadmap:
| Initiative | Status |
|---|---|
| SOC 2 Type II examination | 🗓️ Planned |
| Recurring (at least annual) penetration testing | 🗓️ Planned |
| Expanded compliance initiatives as customer needs evolve | 🗓️ Planned |
SOC 2 Type II evaluates whether our controls operate effectively over a period of time — the natural next step after Type I.
HIPAA
ConnectHL7 is designed to support customers' HIPAA obligations. We apply administrative, technical, and physical safeguards consistent with the HIPAA Security Rule to the PHI we process, and we enter into Business Associate Agreements (BAAs) with customers where required. HIPAA does not involve a government "certification"; our alignment is reflected in our controls, our BAAs, and — as it matures — our SOC 2 program.
Requesting documentation
Enterprise customers conducting a security review can request additional detail under NDA, including our responses to standard security questionnaires and, as they become available, audit artifacts. Contact security@connecthl7.com.
We will update this page as milestones are reached. For the current status of any specific initiative, please reach out — we're happy to give you a straight answer.
Related: Security Overview · Infrastructure & Architecture · Security FAQ · Contact
Last updated: 1 July 2026
Have a question for a vendor review or need documentation under NDA?
Contact Security