1Executive Summary
CUBE OneCare is an enterprise healthcare platform designed with security as a foundational architectural principle, not an afterthought. The standard platform is HIPAA-aligned by architecture and processes no Protected Health Information (PHI) by default; PHI and PII processing across jurisdictions is available to clients under a Business Associate Agreement executed directly with CUBE, scoped and contracted per client, and is subject to strict adherence to HIPAA, GDPR, and industry security standards.
This whitepaper documents our multi-layered security architecture, encryption standards, access control mechanisms, incident response procedures, and compliance evidence. All controls described herein are actively monitored and maintained as audit-ready. No third-party certification audit has been performed; the independent pre-audit of 25 February 2026 was a readiness evaluation, not a certification.
The six-month informational validity of this pre-evaluation ended 2026-08-25. The finding stands as of its assessment date, the evidence it reviewed continues to be maintained, and re-assessment is part of the ongoing programme.
Encryption at Rest
AES-256-GCM
Encryption in Transit
TLS 1.3
Key Management
Encryption keys are managed by the hosting platform's secret store; no customer-managed KMS rotation schedule is in place today
Auth Protocol
OAuth 2.0 + PKCE
Session Timeout
15 min idle
MFA
TOTP + WebAuthn
2Security Architecture Overview
The platform employs a defense-in-depth strategy with security controls at every layer of the technology stack.
Application Layer
Infrastructure Layer
Data Layer
Access Control Layer
3Data Protection & Encryption
| Protection | Standard | Implementation |
|---|---|---|
| Encryption at Rest | AES-256-GCM | Encryption keys are managed by the hosting platform's secret store; no customer-managed KMS rotation schedule is in place today |
| Encryption in Transit | TLS 1.3 | HTTPS enforced, HSTS headers, certificate pinning for mobile |
| Field-Level Encryption | AES-256-GCM | PHI fields encrypted before database write, decrypted on authorized read |
| Key Management | FIPS 140-2 Level 3 | Keys held in the hosting platform's secret store, never in application code |
| Backup Encryption | AES-256 | All backups encrypted with separate key hierarchy |
| Log Encryption | AES-256 | Audit logs encrypted at rest, append-only with integrity verification |
7Incident Response
Our Incident Response Plan (IRP) follows NIST SP 800-61r2 guidelines and is tested annually through tabletop exercises and simulated breach scenarios.
Detection
< 15 minAutomated monitoring with anomaly detection
Triage
< 1 hourSeverity classification and team activation
Containment
< 4 hoursThreat isolation and evidence preservation
Notification
< 24 hoursHIPAA: 60 days. GDPR: 72 hours. We target 24 hours.
9Compliance Framework Mapping
| Control | HIPAA | SOC 2 | ISO 27001 | HITRUST | GDPR |
|---|---|---|---|---|---|
| Access Control | §164.312(a) | CC6.1 | A.9 | 01.v | Art.32 |
| Audit Logging | §164.312(b) | CC7.2 | A.12.4 | 09.aa | Art.30 |
| Encryption | §164.312(a)(2)(iv) | CC6.7 | A.10 | 06.d | Art.32 |
| Incident Response | §164.308(a)(6) | CC7.4 | A.16 | 11.c | Art.33 |
| Risk Assessment | §164.308(a)(1)(ii)(A) | CC3.2 | A.8 | 03.b | Art.35 |
| Data Retention | §164.530(j) | CC6.5 | A.8.10 | 01.t | Art.5(1)(e) |
| Breach Notification | §164.404 | CC7.5 | A.16.2 | 11.a | Art.33-34 |