Transparent, real-time view of every regulatory framework CUBE OneCare is aligned with. Controls and evidence are maintained continuously, so the platform is ready for customer review and audit today. Updated as our compliance posture evolves.
Last updated: August 2026 · Questions? Contact the compliance team
CUBE is aligned with every framework on this page and certified under none of them. Alignment is a standing commitment: controls and evidence are maintained continuously, so the platform is ready for customer review and third-party audit today.
Formal certification is a separate stage, taken one framework at a time. CUBE takes up each named framework in turn — including migrating infrastructure if the certification path requires it. For ISO 27001 and ISO 9001 the independent pre-audit is already complete, which is the stage that precedes certification itself. During the current pilot phase CUBE states its posture as alignment and audit-readiness rather than certification.
CUBE is aligned with HIPAA. Processing PHI requires a Business Associate Agreement executed directly with the client. Our hosting provider's Business Associate Agreement is not yet executed, so no PHI runs on that platform until it is signed.
Health Insurance Portability and Accountability Act
All Administrative, Physical, and Technical Safeguards documented and operating. CUBE has signed a BAA with Stedi (clearinghouse). BAAs with the rest of our providers, including hosting, are pending and will be published in the CUBE control panel when available. Until then, OneCare does not process real PHI.
Updated: 2025-06-01
Service Organization Control 2 — Type II
SOC 2 control mapping and readiness evidence are maintained; external Type II reporting remains pending until formally issued.
Updated: 2025-06-01
Information Security Management System
ISO 27001 ISMS mapping and readiness evidence are maintained. An independent pre-evaluation — not a certification — was completed 25 February 2026 by CIIESOST; see the constraints and validity window below. CUBE is aligned with ISO 27001 and certified under none of its clauses; certification is approached one framework at a time.
Point-in-time independent finding dated 25 February 2026. The evidence it examined is maintained continuously, it remains available for review under NDA, and a renewed report is planned.
Updated: 2026-08-17
Quality Management System
ISO 9001 quality management system documentation is maintained. An independent pre-evaluation — not a certification — was completed 25 February 2026 by CIIESOST; see the constraints and validity window below. CUBE is aligned with ISO 9001 and certified under none of its clauses; certification is approached one framework at a time.
Point-in-time independent finding dated 25 February 2026. The evidence it examined is maintained continuously, it remains available for review under NDA, and a renewed report is planned.
Updated: 2026-08-17
Health Information Trust Alliance Common Security Framework
Healthcare-specific controls are mapped and documented across the HITRUST domains. CUBE is aligned with HITRUST CSF and certified under none of its assessment tiers on the shared platform; institutions that require certified hosting can use a dedicated deployment on HITRUST-certified infrastructure through CUBE's compliance-hardened white-label option.
Updated: 2026-08-17
General Data Protection Regulation (EU)
GDPR-aligned controls for EU/EEA data subjects. Data Protection Officer (DPO) designated. Privacy Impact Assessments conducted for all processing activities.
Updated: 2025-06-01
Fast Healthcare Interoperability Resources — Release 4
FHIR R4 native platform with 21 resource types, full CRUD + versioning, SMART on FHIR OAuth2, and Bulk Data Export. ONC §170.315(g)(10) aligned.
Updated: 2025-06-01
Compliance Disclaimer
Status labels reflect CUBE OneCare's current control mapping, internal readiness evidence, and implementation posture. “Aligned” indicates controls are mapped and supported by internal evidence where available; it does not mean a third-party certification has been issued. No certification is dated in advance; each framework is taken up in turn. For the most current information, contact the compliance team.
Audit readiness documentation, control mappings, and available security evidence can be requested under NDA through the Evidence vault.