US-Based Workforce · US Data Residency
Epic App Available Customer Login · Call (501) 830-1478
Security & Compliance

244 controls.
Tested daily.

Healthcare AI vendors talk about security in vague terms. We do not. Drata continuously monitors 244 security and infrastructure controls across our systems, code, and personnel, and updates our public security posture every day. The same report we share with auditors is open to any prospective customer to inspect.

Continuous monitoring
Drata, daily-updated
Data residency
United States only
Frameworks
SOC 2 II · HIPAA
Last updated
Today
244
Controls Monitored
Daily
Automated Testing
24/7
Continuous Coverage
US
Data Residency
Vendor due diligence

Questions to ask any healthcare AI vendor.

The strongest test of a vendor is not what they say about themselves. It is what they will commit to in writing. Here are the questions we recommend asking every vendor you evaluate, and our answers to each.

I.
Where is your data processed and stored?
Our answer
United States only. Every step.
Many healthcare AI vendors store data in international cloud regions, route it through third-party APIs hosted outside the US, or rely on offshore contracted labor. We store every chart in US infrastructure, and every person who can access PHI is based in the United States. This commitment is included in every BAA we sign.
II.
How many security controls do you continuously monitor?
Our answer
244 controls. Tested daily.
Continuous monitoring means automated daily testing across infrastructure, code repositories, identity providers, endpoints, HR systems, and policies. Our public security posture is updated every 24 hours. SOC 2 reports provide annual third-party attestation; continuous monitoring produces daily verification of the same controls on top of that, so the security posture you see is current rather than point-in-time.
III.
What compliance frameworks do you maintain?
Our answer
SOC 2 Type II. HIPAA with BAA. US data residency.
SOC 2 Type II is the floor: an independent audit of security, availability, confidentiality, and privacy controls over a period of operation. HIPAA with a Business Associate Agreement is the law. US data residency means customer data is stored only in US infrastructure, and the personnel who can access PHI work inside the United States. Ask any vendor to put all three in writing.
IV.
Can we see your real-time security posture?
Our answer
Yes. Our live report is publicly linked.
Most vendors share a static SOC 2 report from last year's audit. We publish a daily-updated security posture report direct from our continuous monitoring platform. The link is at the top of this page. The same report goes to auditors, to customers, and to anyone evaluating us.
V.
Will you share your actual policies on request?
Our answer
Yes. By name. By request.
Our policies are reviewed quarterly and approved by our security steering committee. Ask any vendor for their access control policy, data retention policy, or incident response plan. Most decline. We will send any policy, by name, under NDA when appropriate.
VI.
What is your breach notification commitment?
Our answer
Materially faster than the HIPAA floor.
HIPAA requires breach notification within 60 days. We commit to notification timelines well inside that window, with specific terms written into every BAA we sign. Ask any vendor what their contractual notification window is. If it is sixty days, that is the legal minimum, not a commitment.
Open book

The same report we share with our auditors.

Drata connects directly to our infrastructure, version control, identity provider, endpoints, and HR systems. It continuously verifies that 244 controls are in place and functioning. The report you can open from this page is the same one we share with our SOC 2 auditors, updated automatically every day.

Open live report →
Live Security Posture · Today
Controls monitored 244
Continuous test frequency Daily
Infrastructure connection Live
Identity provider connection Live
Code repository connection Live
HR system connection Live
Report freshness Updated today
What we monitor

Ten areas. Continuous coverage.

The 244 controls in our report fall into ten broad categories. Each is monitored automatically every day. Specific control implementations are documented in policies available on request; the categories below show the scope of what is covered.

I · Access & Identity
Access & Identity Management
Least-privilege access provisioning, deprovisioning within one business day of termination, role-based access control, centralized authentication, MFA, session timeouts, and unique user IDs across every system.
II · Encryption
Data Protection & Encryption
Strong cryptographic algorithms for data at rest and in transit, strong TLS ciphers, key generation and rotation procedures, secure password storage, and device encryption for all personnel endpoints.
III · Monitoring
Continuous Monitoring & Auditing
Audit logging across every production system, audit trails for privileged access and invalid access attempts, security event tracking, threat detection, and continuous control self-assessments.
IV · Cloud
Cloud Infrastructure
US-only Azure regions, network segmentation, restricted public access, web application firewall, private endpoint access to storage, zone redundancy, autoscaling, and continuous infrastructure log alerts.
V · Continuity
Business Continuity & Disaster Recovery
Documented business continuity and backup policies, backup restore testing, BCP/DR exercises, redundancy of processing, business impact analysis, and uninterruptible power supply.
VI · Change Control
Change Management & Code Quality
Documented change management policy, approval workflows for production releases, change detection, separate environments for development and production, static application security testing, and software composition analysis.
VII · Personnel
Personnel Security & Training
Background checks, code of conduct, NDAs, HIPAA awareness training, security awareness training, phishing simulations, formal onboarding and offboarding checklists, and competence records.
VIII · Vendors
Vendor & Subprocessor Management
Vendor due diligence, vendor compliance monitoring against industry frameworks, vendor register and agreements, communication of subprocessor changes, and privacy and security requirements written into third-party agreements.
IX · Privacy & PHI
Privacy & PHI Handling
Documented privacy policy, BAA execution with every covered customer, allowable use and disclosure controls, data subject rights procedures, record of processing activity, quarterly privacy compliance review.
X · Vulnerabilities
Vulnerability Management
Documented vulnerability management policy with risk-based SLAs, continuous vulnerability scanning, prompt remediation of critical and high vulnerabilities, automated security patching, and penetration testing.
Frameworks maintained

What we comply with.

Compliance frameworks are not all equal. SOC 2 Type II is the most common baseline for security, availability, and confidentiality controls. HIPAA with a Business Associate Agreement is the law for any vendor that touches PHI. US data residency is the commitment that customer data is stored only inside the United States. We maintain all three.

I.
SOC 2 Type II
Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over a period of operation.
II.
HIPAA
Full HIPAA compliance including the Privacy Rule, the Security Rule, and the Breach Notification Rule. Business Associate Agreements executed with every covered customer.
III.
US Data Residency
Customer data is stored only in US infrastructure, and every person who can access PHI is based in the United States. The commitment is contractually binding and included in every BAA.
Data residency

Your data is stored in the United States.

In an industry where vendors increasingly store healthcare data in international cloud regions and rely on offshore service providers, we make a commitment that is contractually binding and continuously monitored: every chart we process is stored only inside the United States, and every person who can access PHI works inside it.

I.
Stored in the United States.
Customer data, PHI, audit logs, backups, and archives are stored only in US infrastructure. Backups remain in-region; archives remain in-region. There are no cross-border replicas.
II.
No data retained outside the United States.
Customer data is not retained at rest outside the United States and is never used to train any foundation model. This commitment is contractually binding and included in every BAA we sign.
III.
Operated by US-based personnel.
Every employee who can access customer PHI is based in the United States, in Little Rock or Seattle. No offshoring. No third-party outsourcing of PHI access. This commitment is written into every BAA we sign.
Request a policy

Ask us for any policy by name, any time.

Our policies are documented, reviewed quarterly, and approved by our security steering committee. If you are evaluating us as a vendor and need to see a specific policy in writing, under NDA when appropriate. Most vendors decline. We do not.

Request a policy →
Subprocessors
  • Microsoft Azure
  • SmartyStreets