Complete compliance documentation for HIPAA, SOC 2, ISO 27001, HITRUST, GDPR, and FHIR. All frameworks maintained with documented controls and evidence.
Administrative, Physical & Technical Safeguards
Trust Service Criteria
Information Security Management System
Common Security Framework
General Data Protection Regulation
HL7 FHIR R4 Interoperability
Last updated: August 2026
Our compliance posture is updated quarterly and shared proactively with enterprise customers.
Aligned with HIPAA; not certified — HIPAA has no certification scheme. PHI processing activates under a Business Associate Agreement executed per client.
Aligned and audit-ready; not attested. External Type II reporting remains pending until formally issued.
Aligned with ISO 27001; not certified. An independent pre-audit is complete and the readiness evidence is maintained continuously.
Aligned with ISO 9001; not certified. An independent pre-audit is complete and the readiness evidence is maintained continuously.
Aligned with HITRUST CSF; not certified on the shared platform. A dedicated deployment on HITRUST-certified infrastructure is available through the white-label option.
Aligned with GDPR for EU/EEA data subjects. Data Processing Addendum terms are provided through the approved contracting workflow.
Native FHIR R4 support with ONC §170.315(g)(10)-aligned APIs — an interoperability standard, not a compliance certification.
Compliance readiness package available to enterprise customers upon execution of NDA through the secure contact form. Certification is approached one framework at a time, and the readiness evidence for each framework above is maintained continuously. Open security request.
CUBE is aligned with HIPAA. Processing PHI requires a Business Associate Agreement executed directly with the client. Our hosting provider's Business Associate Agreement is not yet executed, so no PHI runs on that platform until it is signed.
Enterprise customers receive the compliance readiness package, including attestations and evidence exhibits.