CUBE OneCare is built for procurement-ready enterprise healthcare. Our Trust Center provides transparent access to security controls, compliance artifacts, and governance documentation across 6 regulatory frameworks.
Defense-in-depth security architecture with multiple layers of protection across infrastructure, application, and data domains.
Selected PHI fields are encrypted at the application layer with AES-256-GCM. Storage-level encryption and TLS 1.3 in transit are provided by the hosting platform. Keys are held in the platform's secret store; there is no customer-managed KMS rotation schedule today.
RBAC with least-privilege, MFA enforcement, SSO integration, and session management.
Error monitoring with automated alerting, plus insert-only audit logs.
US-based cloud infrastructure, network segmentation, container isolation, and automated patching.
HIPAA
45 CFR Parts 160, 162, 164
SOC 2 Type II
Trust Services Criteria
ISO 27001:2022
93 Annex A Controls
NIST 800-53 Rev 5
Moderate Baseline
HITRUST CSF v11
Healthcare Specific
ISO 9001:2015
Quality Management
Safeguards implemented; no formal third-party certification is yet held.
How model use is bounded, reviewed and disclosed — and what it is not permitted to do
Human-in-the-Loop
All AI-generated insights require human review before action
No Autonomous Decisions
AI assists with navigation and engagement — never clinical decisions
Bias Monitoring
Continuous fairness testing across demographic groups
Full Audit Trails
Every AI interaction logged with input, output, and confidence scores
Model Boundaries
Strict scope limitations — no access to raw PHI beyond minimum necessary
See our AI Disclosure for complete details on AI boundaries and safeguards.
Where data goes from the moment it arrives to the moment it is gone
Collected only for care delivery, billing and the operation of the platform, with the purpose recorded for each field
Processed under role-based access control, with every record access written to the audit trail
US-based encrypted storage with access controls and monitoring
Retained for the period the applicable regulation requires, and no longer by default
Deleted on request or at the end of retention; the deletion is recorded in the platform audit log. No third-party deletion certificate is issued today.
We maintain a current list of subprocessors who handle data on our behalf. Each subprocessor's DPA and BAA status is recorded in the sub-processor annex and is not presumed. CUBE has signed a BAA with Stedi (clearinghouse). BAAs with the rest of our providers, including hosting, are pending and will be published in the CUBE control panel when available. Until then, OneCare does not process real PHI.
What is processed, for what purpose, and under which agreement
This summary is informational. Formal data processing details are governed by executed DPA / BAA agreements.
Security is shared. These are the parts that stay with you
User Access Management
Provision, deprovision, and manage user accounts with appropriate role assignments. Enforce MFA policies for your organization.
Data Classification
Classify and label data per your organizational policies before ingesting into CUBE OneCare. Apply appropriate handling rules.
Incident Notification
Promptly report suspected security incidents involving your user accounts or data. Maintain an internal incident response plan.
Regulatory Obligations
Maintain your own regulatory compliance obligations (e.g., HIPAA Covered Entity requirements, state privacy laws) as applicable.
Configuration Management
Review and maintain platform configuration settings, retention policies, and integration credentials on a regular basis.
For the complete shared responsibility model, see Shared Responsibility Model.
Control documentation and readiness evidence, available to enterprise customers under NDA
Compliance alignment status for HIPAA, SOC 2, ISO 27001, HITRUST CSF, GDPR, and FHIR R4 — aligned, not certified.
View detailsInformation Security Management System with 93 Annex A controls, risk treatment methodology, and an internal review cadence.
View detailsQuality Management System aligned with ISO 9001:2015 — process controls, CAPA workflow, internal audits, and management reviews.
View detailsUnified control mapping across HIPAA, SOC 2, ISO 27001, NIST 800-53, and HITRUST CSF — mapped alignment, not certification.
View detailsClear delineation of security responsibilities between CUBE OneCare and customer organizations across infrastructure, data, and compliance domains.
View detailsThree-tier governance structure (Board, CTO Council, Working Groups), policy lifecycle management, regulatory tracking, and vendor assurance program.
View detailsCUBE Assist AI governance framework — risk tiers, human-in-the-loop requirements, bias monitoring, and model lifecycle management.
View detailsNDA-protected repository of compliance artifacts including SOC 2 readiness reports and policy documents.
View detailsTransparent mapping of security controls inspired by ISO 27001:2022 Annex A — intent, implementation, and available evidence.
View detailsPrivacy and data governance summary — retention policies, deletion procedures, and data subject access request (DSAR) workflows.
View detailsTransparent path from compliance readiness to formal certification — milestones and maturity levels.
View detailsStructured catalog of compliance evidence — policy documents, audit reports, and technical controls. Access under NDA.
View detailsNDA-gated customer trust portal entry for controlled artifact access, intake workflows, and procurement coordination.
View detailsResponsible disclosure policy with safe harbor intent, scope boundaries, and security contact pathway.
View detailsOur security team is available for procurement reviews, compliance briefings, and evidence access requests. Let us help you complete your vendor assessment.
CUBE OneCare is a digital health & wellness platform, not a medical provider. Compliance controls are implemented; no formal third-party certification is yet held. This Trust Center does not constitute legal advice or a guarantee of compliance. Contact our security team for specific procurement requirements.