Compliance Roadmap

What controls ConnectHL7 has in place today and what is in progress or planned, including SOC 2 and HIPAA alignment.

We believe in being transparent about where we are on our compliance journey. This page shows what ConnectHL7 has in place today, what we are actively working toward, and what is planned for the future.

We do not claim certifications we have not yet achieved. Where an initiative is in progress or planned, we say so plainly. This page reflects our status as of the date below and is updated as we make progress.


Our approach to compliance

ConnectHL7 aligns its security program with widely recognized frameworks relevant to healthcare SaaS:

  • SOC 2 Trust Services Criteria (Security, Availability, Confidentiality)
  • HIPAA Security Rule, where applicable to PHI
  • AWS Well-Architected Framework — Security Pillar
  • CIS Controls
  • OWASP secure development practices

We build our controls to these standards now, so that formal attestation is a validation of how we already operate rather than a scramble to prepare.


Current — in place today

These controls are operational today:

Area Status
Documented security policies established ✅ In place
Multi-factor authentication (MFA) enforced ✅ In place
Encryption in transit (TLS 1.2+) ✅ In place
Encryption at rest (AES-256) ✅ In place
Role-based, least-privilege access control ✅ In place
Centralized, tamper-resistant logging ✅ In place
Continuous infrastructure & threat monitoring ✅ In place
Automated, encrypted backups ✅ In place
Secure software development lifecycle (SDLC) ✅ In place
Infrastructure as Code ✅ In place
HIPAA Business Associate Agreements (BAAs) available ✅ In place

Near term — actively in progress

These initiatives are underway:

Initiative Status
Independent third-party penetration testing 🔄 In progress
SOC 2 Type I examination 🔄 In progress
Formalized evidence collection for audit 🔄 In progress

SOC 2 Type I evaluates whether our controls are suitably designed at a point in time.


Future — planned

These are on our roadmap:

Initiative Status
SOC 2 Type II examination 🗓️ Planned
Recurring (at least annual) penetration testing 🗓️ Planned
Expanded compliance initiatives as customer needs evolve 🗓️ Planned

SOC 2 Type II evaluates whether our controls operate effectively over a period of time — the natural next step after Type I.


HIPAA

ConnectHL7 is designed to support customers' HIPAA obligations. We apply administrative, technical, and physical safeguards consistent with the HIPAA Security Rule to the PHI we process, and we enter into Business Associate Agreements (BAAs) with customers where required. HIPAA does not involve a government "certification"; our alignment is reflected in our controls, our BAAs, and — as it matures — our SOC 2 program.


Requesting documentation

Enterprise customers conducting a security review can request additional detail under NDA, including our responses to standard security questionnaires and, as they become available, audit artifacts. Contact security@connecthl7.com.

We will update this page as milestones are reached. For the current status of any specific initiative, please reach out — we're happy to give you a straight answer.


Related: Security Overview · Infrastructure & Architecture · Security FAQ · Contact

Last updated: 1 July 2026

Have a question for a vendor review or need documentation under NDA?

Contact Security