Security & Compliance

Built from the ground up to protect healthcare data. Security is foundational to everything we do.

Security Controls

Encryption Everywhere

All data encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM). HL7 messages are encrypted from ingestion to delivery.

Access Control

Role-based access control (RBAC) with granular permissions. Multi-factor authentication (MFA) support for all users.

Audit Logging

Comprehensive audit trails for all system access and PHI operations. Logs retained for 7 years per HIPAA requirements.

Infrastructure Security

Hosted on SOC 2-certified cloud providers (AWS, GCP, Azure). Network isolation, firewalls, and intrusion detection. VynaLink SOC 2 Type II certification is on the 2026 roadmap.

Compliance Status

We're committed to achieving and maintaining the certifications that matter for healthcare. Here's our current status:

HIPAA Technical Safeguards

Implemented

Access controls, audit controls, integrity controls, and transmission security as required by 45 CFR § 164.312.

Business Associate Agreements

Available

We sign BAAs with all customers who handle PHI. Contact us to execute a BAA before going live.

SOC 2 Type II

Planned 2026

SOC 2 Type II audit planned for 2026. Contact us for our current security documentation.

Penetration Testing

Planned 2026

Annual third-party penetration testing. Results available to customers under NDA.

PHI Data Protection

  • PHI is never stored on local devices or laptops
  • All database backups are encrypted
  • Data retention policies aligned with HIPAA (7 years)
  • Secure data deletion upon contract termination
  • Geographic data residency options available
  • No PHI in log files or error messages

Need More Information?

We're happy to provide additional security documentation, complete security questionnaires, or discuss our security practices in detail.

Security FAQs

Is VynaLink HIPAA compliant?

VynaLink implements the technical safeguards required by HIPAA. We sign Business Associate Agreements (BAAs) with all customers who handle PHI. Note that HIPAA compliance is a shared responsibility—we provide the secure platform, and you implement appropriate policies for your organization.

Do you have a SOC 2 report?

We are pursuing SOC 2 Type II certification in 2026. In the meantime, we can provide detailed security documentation and complete security questionnaires. Our infrastructure runs on SOC 2 certified cloud providers.

Where is my data stored?

By default, data is stored in US-based data centers. We offer geographic data residency options for customers with specific requirements. All data is encrypted at rest and in transit.

How do you handle security incidents?

We have an incident response plan that includes immediate containment, investigation, and notification procedures. For any incident involving PHI, we follow HIPAA breach notification requirements and will notify affected customers within 24 hours of discovery.