Security Overview

Our security philosophy, shared responsibility model, security governance, and risk management approach.

ConnectHL7 provides secure interoperability between hospitals, laboratories, EHRs, and healthcare applications. Because we handle protected health information (PHI) on behalf of our customers, security is built into how we design, build, and operate the platform.

This page describes our approach at a high level. For specifics, see Encryption & Data Protection, Infrastructure & Architecture, and our Compliance Roadmap.


Security philosophy

Our approach rests on a few durable principles:

  • Secure by default. New systems start encrypted, private, and monitored. Broad access and public exposure are exceptions that require justification, not defaults.
  • Least privilege. People and systems get only the access they need to do their job — nothing more.
  • Defense in depth. We don't rely on any single control. Identity, network, application, and monitoring controls reinforce one another.
  • Assume failure. We design for detection and recovery on the assumption that any single safeguard can fail.
  • Everything as code. Our infrastructure is defined as code and our software ships through automated pipelines with built-in security checks, so our controls are consistent, versioned, and repeatable.

Shared responsibility model

Security in a cloud-native platform is a shared responsibility between Amazon Web Services (AWS), ConnectHL7, and our customers. Understanding the boundaries helps everyone protect data effectively.

Layer Responsibility Owner
Physical data centers, hardware, core cloud services Security of the cloud AWS
Platform architecture, encryption, access controls, monitoring, secure development, data handling Security in the cloud ConnectHL7
User account management on the customer side, secure handling of credentials and API keys, appropriate use of the integration, and the data customers choose to send Security of customer usage Customer

AWS operates its infrastructure under a broad set of independent certifications and attestations. ConnectHL7 builds on that foundation and is responsible for everything we deploy on top of it.


Security governance

Security at ConnectHL7 has clear, accountable ownership:

  • A designated Security Officer owns our information security program, maintains our security policies, and coordinates our response to security events.
  • Executive leadership holds ultimate accountability for security and privacy and reviews our security posture regularly.
  • We maintain a documented set of internal security policies covering access control, secure development, incident response, backup and recovery, vendor management, and more. These policies govern how our team operates day to day.

We keep our governance lightweight and practical, with clear ownership rather than bureaucracy — appropriate to a focused, security-first company.


Risk management

We manage security risk as an ongoing operating discipline:

  • We continuously monitor our AWS environment for threats and misconfiguration using native AWS security services (see Infrastructure & Architecture).
  • We maintain an internal risk register, assess risks by likelihood and impact, and assign clear ownership and treatment to each.
  • We evaluate the security of vendors and subprocessors before granting them access to systems or data, and review them on a recurring basis.
  • Significant risks are reviewed by leadership on a regular cadence.

Continuous improvement

Security is never "done." We improve continuously by:

  • Learning from every operational and security event and feeding those lessons back into our controls.
  • Reviewing our security policies at least annually and updating them as our platform and the threat landscape evolve.
  • Tracking security metrics — such as how quickly we detect and respond to issues and how promptly we remediate vulnerabilities.
  • Advancing the initiatives on our Compliance Roadmap, including independent penetration testing and SOC 2.

Customer trust

We earn trust by being transparent and by doing the fundamentals well:

  • We tell you clearly what we have in place today and what is still on our roadmap. We do not claim certifications we have not achieved.
  • We support enterprise security reviews and can provide additional documentation under NDA.
  • We commit to timely, honest communication if a security event ever affects your data, consistent with our contractual and regulatory obligations.

If you're evaluating ConnectHL7 and have questions this page doesn't answer, contact security@connecthl7.com or see our Security FAQ.


Related: Encryption & Data Protection · Infrastructure & Architecture · Compliance Roadmap · Contact

Last updated: 1 July 2026

Have a question for a vendor review or need documentation under NDA?

Contact Security