HealthTap maintains a Service Organization Control Type 2 (SOC 2) Type 2 certification. This means that our controls and systems for non-financial matters including security, availability, processing integrity, confidentiality, and privacy are audited and certified by an American Institute of Certified Public Accountants (AICPA)-accredited firm on a yearly basis. This SOC 2 Type 2 also measures our compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
We conduct penetration testing by third-party, independent firms that specialize in this service. We continuously improve our software development and engineering efforts based on the results of these tests. Additionally, Privacy Shield, General Data Protection Regulation 2016/679 (GDPR), and the upcoming California Consumer Privacy Act (CCPA) help shape our standards and policies.
Visit our Standards and Trust page to learn more.