Security FAQ
Answers to common healthcare security, privacy, and due-diligence questions from IT teams, CISOs, and procurement.
Answers to common questions from healthcare IT teams, CISOs, security reviewers, and procurement teams. For more detail on any topic, follow the linked pages or contact security@connecthl7.com.
Data hosting & residency
Where is customer data hosted? ConnectHL7 is hosted entirely on Amazon Web Services (AWS). We operate no on-premise servers. See Infrastructure & Architecture.
What cloud provider do you use? AWS is our sole cloud provider. We build on AWS's independently attested infrastructure and are responsible for everything we deploy on top of it. See our shared responsibility model.
Can we choose the AWS region where our data is stored? Data residency options can be discussed during a security review depending on your requirements. Contact security@connecthl7.com.
Do you use any subprocessors? Yes — primarily AWS for hosting, and a limited set of vetted service providers. We assess vendors before granting access to systems or data and review them on a recurring basis. A current subprocessor list can be provided during a security review.
Encryption & data protection
Is data encrypted? Yes. All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. See Encryption & Data Protection.
Is data encrypted in transit? Yes — all connections require modern TLS (1.2 or higher). Legacy protocols and weak ciphers are not permitted.
Is data encrypted at rest? Yes — our datastores, object storage, message queues, and backups are encrypted at rest by default.
How are encryption keys managed? Keys are managed through AWS's hardware-backed key management service (AWS KMS), with tightly restricted, logged access. See key management.
How do you manage secrets? Secrets (credentials, API keys) are stored in AWS Secrets Manager, encrypted, and retrieved only at runtime. Secrets are never stored in source code, and our pipeline includes automated secret scanning.
Is our data used to train AI models or for any secondary purpose? No. We use customer data only to provide the ConnectHL7 service, consistent with our contractual and regulatory obligations.
Access control
How is access controlled? Through role-based access control (RBAC) and least-privilege principles — people and systems get only the access their role requires. See authorization.
Is MFA required? Yes. Multi-factor authentication is mandatory for all team member access to our AWS environment, source control, and business systems.
Who at ConnectHL7 can access customer data? Access to production and customer data is tightly restricted to a small number of authorized personnel, granted on a least-privilege basis, logged, and reviewed regularly.
How is access reviewed and removed? Access is reviewed on a recurring basis and removed promptly when someone changes roles or leaves. Departures trigger prompt revocation of access and credentials.
Monitoring & logging
Do you monitor your environment for threats? Yes — continuously, using Amazon GuardDuty, AWS Security Hub, Amazon Inspector, and AWS Config. See monitoring.
Do you keep audit logs? Yes. AWS CloudTrail records API and administrative activity, and Amazon CloudWatch centralizes application and infrastructure logs. Logs are retained to support investigation and auditability.
Vulnerability & secure development
Do you perform vulnerability scanning? Yes. We continuously assess our workloads and container images with Amazon Inspector, and scan dependencies and code on every change in our CI/CD pipeline.
Do you conduct penetration testing? Independent third-party penetration testing is in progress, with recurring testing planned. See our Compliance Roadmap.
How do you build software securely? All code changes are peer-reviewed and pass automated security checks (static analysis, dependency scanning, secret scanning) before deployment. Our practices follow OWASP guidance. See secure software development.
How quickly do you patch vulnerabilities? We remediate vulnerabilities on timelines prioritized by severity, with critical issues addressed most urgently.
Backups & resilience
Are backups encrypted? Yes. All backups are encrypted at rest and in transit. See Business Continuity & Disaster Recovery.
How often are backups tested? We test data restoration on a recurring basis. A backup that has never been successfully restored is not treated as reliable.
What are your recovery objectives (RPO/RTO)? We maintain internal RPO and RTO targets, with the most aggressive targets applied to core message processing and our primary data store. Specific figures can be shared under NDA during a security review.
Is the platform highly available? Yes. Workloads run across multiple AWS Availability Zones using managed, redundant services, so single-component failures do not take the service down. See high availability.
Do you have a disaster recovery plan? Yes. We maintain and regularly test a documented disaster recovery plan, including cross-region backup copies and the ability to rebuild our environment from Infrastructure as Code.
Compliance & agreements
Are you SOC 2 certified? Not yet. SOC 2 Type I is in progress and SOC 2 Type II is planned. We build our controls to SOC 2 criteria today and are candid about our status. See our Compliance Roadmap.
Are you HIPAA compliant? We are designed to support customers' HIPAA obligations, apply safeguards consistent with the HIPAA Security Rule to PHI, and sign Business Associate Agreements (BAAs) where required. HIPAA has no government "certification"; our alignment is reflected in our controls and BAAs.
Will you sign a BAA? Yes, where required for the processing of PHI. Contact privacy@connecthl7.com or sales@connecthl7.com.
Can you complete our security questionnaire? Yes. Send it to security@connecthl7.com. Many common questions are already answered on this Trust Center, which can speed up your review.
Can we get your security documentation for our review? Yes — we can provide additional documentation under NDA, including questionnaire responses and available audit artifacts. Contact security@connecthl7.com.
Incidents & reporting
How can customers report security concerns? Email security@connecthl7.com. To report a vulnerability, follow our Responsible Disclosure process.
What happens if there's a security incident affecting our data? We maintain an internal incident response process and will notify affected customers in a timely manner, consistent with our contractual and regulatory obligations (including HIPAA breach notification where applicable).
Didn't find your answer? Contact security@connecthl7.com or see the Contact page.
Last updated: 1 July 2026
Have a question for a vendor review or need documentation under NDA?
Contact Security