100% Azure-Hosted  ·  HIPAA Business Associate Ready  ·  SOC 2 Roadmap Published

Trust & Security
Center

VitaAI is built for healthcare — where data integrity, patient privacy, and regulatory compliance aren't optional. Review our security controls, our real-time compliance roadmap, and our documentation library.

256-bit AES Encryption at Rest
TLS 1.2+ Encryption in Transit
FHIR R4 Standards-Based EHR Integration
1 Hour Database Recovery Time Objective

Built on Microsoft Azure's certified infrastructure

We show our work, not just our badges

Vendor security reviews shouldn't require reading between the lines of marketing copy. Our Compliance Roadmap shows exactly which controls are implemented today, which are in progress, and our target dates — control by control, updated as our program matures.

View the Live Roadmap

Enterprise-grade protection
at every layer

VitaAI implements defense-in-depth across infrastructure, application, and data layers — ensuring PHI is protected regardless of where it resides or transits.

🔒

Encryption at Rest

All stored data encrypted with AES-256. Azure Storage Service Encryption applied by default. Customer-managed key (CMK) support via Azure Key Vault available for enterprise accounts.

🔗

Encryption in Transit

All data in transit protected with TLS 1.2 minimum (1.3 where supported). Strict HTTPS enforcement with HSTS (1-year max-age, preload). Forward secrecy via ECDHE cipher suites.

📋

Audit Logging

Comprehensive, tamper-evident, hash-chained audit logs for all PHI access events. Logs retained for six years in immutable WORM storage, per HIPAA §164.312(b). Exportable to SIEM systems (Sentinel, Splunk).

👤

Role-Based Access Control

Least-privilege RBAC with Azure Active Directory integration. Clinician, admin, and read-only roles with granular resource scoping. Just-in-time privileged access for administrative operations.

🔐

Field-Level Encryption

Sensitive PHI fields (SSN, DOB, diagnosis codes) encrypted individually at the application layer — separate from disk-level encryption — ensuring data is protected even within the database engine.

📱

MFA & SSO

Multi-factor authentication enforced for all user accounts. SAML 2.0 / OIDC single sign-on for seamless, secure integration with your organization's existing identity provider (Okta, Azure AD, Ping).

🌐

Network Isolation

Database access restricted to the application's connection string only — no direct SQL admin access to production. Azure's platform-level DDoS protection covers all endpoints. HTTPS redirect enforced everywhere.

🔍

Vulnerability Management

Continuous dependency scanning with automated CVE alerting (NuGet/npm audit gates in CI/CD). Independent third-party penetration testing scheduled for Q3 2026, with an annual cadence thereafter — see our Compliance Roadmap for current status.

Business Continuity

Geo-redundant data replication across Azure paired regions. Recovery Point Objective (RPO) of 5 minutes; Recovery Time Objective (RTO) of 1 hour for the database tier. Redeploy drills run quarterly — full detail on our Disaster Recovery page.

HIPAA Compliance

Security & Privacy Rule Coverage
Administrative Safeguards Security management, training, contingency planning
Physical Safeguards Azure SOC-certified data centers with biometric access
Technical Safeguards Access controls, audit controls, integrity, transmission security
Organizational Requirements BAA available for all covered entity relationships
HITECH Act Compliance Breach notification, business associate obligations

Purpose-built for covered entities and business associates

VitaAI operates as a Business Associate under HIPAA when processing Protected Health Information on behalf of covered entities. We execute a Business Associate Agreement (BAA) with every customer that handles PHI.

Our security posture is grounded in a formal HIPAA risk assessment (HHS SRA Tool, aligned with the NIST Cybersecurity Framework), reviewed on an annual cycle. See the full control-by-control status on our Compliance Roadmap.

  • Signed BAA available to all customers
  • PHI processed only as directed under the BAA
  • Breach notification within 60 days per HITECH
  • De-identification methods per 45 CFR §164.514
  • Minimum Necessary Standard enforced
  • Employee HIPAA training required annually
  • Incident response plan reviewed annually

Standards-based EHR connectivity

VitaAI integrates with Epic and other major EHR platforms via industry-standard HL7 FHIR R4 APIs — no custom interfaces, no shadow copies of data.

FHIR R4 EHR Integration

VitaAI connects to Epic and other FHIR R4-compliant EHR systems via the HL7 FHIR R4 API, enabling real-time, bidirectional clinical data exchange without bulk data exports or custom ETL pipelines. Patient data is queried on-demand, minimizing PHI at rest in VitaAI's systems. OAuth 2.0 SMART on FHIR authorization ensures patient-level consent is enforced at the EHR layer.

HL7 FHIR R4 SMART on FHIR OAuth 2.0 CDS Hooks US Core 4.0

Security & compliance documentation

Download our security documentation to accelerate your organization's vendor assessment and procurement process. All compliance documents are available in both PDF and Word formats.

27 documents available

Core Trust Documents

🗃
HIPAA

HIPAA Security Controls Overview

Detailed mapping of VitaAI's administrative, physical, and technical safeguards to the HIPAA Security Rule.

📄
Overview

Trust & Security Overview

Executive summary of VitaAI's security program, infrastructure architecture, and compliance posture for procurement teams.

📝
Legal

Business Associate Agreement (BAA)

Standard BAA template for covered entities. Pre-signed by VitaAI. Send to legal for review or request a countersigned copy.

Checklist

Self-Assessment Security Checklist

Vendor questionnaire responses aligned to NIST CSF, CIS Controls v8, and common hospital procurement frameworks.

🌎
Architecture

Client Deployment Architecture

Reference architecture diagrams showing network topology, data flows, integration points, and security boundaries.

Azure

Microsoft Azure HIPAA BAA

The signed Business Associate Agreement between Microsoft and Azure customers confirming HIPAA-compliant infrastructure obligations.

📋
SOC 2

SOC 2 Risk Register

Formal CC9 risk register mapping 12 identified risks to SOC 2 Trust Services Criteria with current controls, residual risk ratings, and mitigation owners.

Legal & Customer Agreements

🔒
Legal · CUST-19

Privacy Policy

Describes how VitaAI collects, uses, discloses, and protects personal information and PHI. Covers patient rights under HIPAA.

📜
Legal · CUST-18

Terms of Use

Governs authorized use of the VitaAI platform, user responsibilities, IP rights, liability limitations, and prohibited activities.

📑
Legal · CUST-17

Master Services Agreement

Standard enterprise healthcare SaaS agreement governing subscriptions, data protection obligations, SLAs, and IP rights.

HR & People

👥
HR · HR-13

Employee Handbook & Code of Conduct

Company values, workplace standards, HIPAA obligations, anti-harassment policy, remote work guidelines, and professional conduct standards.

🔐
HR · HR-15

Confidentiality & NDA

Workforce confidentiality agreement signed by all employees and contractors. Covers PHI handling, trade secrets, and post-separation obligations.

💼
HR · HR-16

Job Descriptions

Formal role definitions, responsibilities, and qualifications for all key positions: CEO, Lead Engineer, Security Officer, DevOps, and Customer Success.

📋
HR · HR-7

Disciplinary Process

Progressive discipline policy for policy violations and HIPAA infractions. Defines sanctions from verbal warning through immediate termination.

🛡
HR · HR-19

Security Officer Designation

Formal designation of the HIPAA Security Officer and Privacy Officer as required by 45 CFR §164.308(a)(2) and §164.530(a).

IT & Security Policy

📵
IT · IT-11

Acceptable Use Policy

Defines authorized use of VitaAI systems, PHI handling requirements, password standards, device controls, and prohibited activities for all workforce members.

Engineering

🔑
Engineering · APPS-2

Encryption Documentation

Cryptographic standards for data at rest (AES-256-GCM), in transit (TLS 1.3), key management via Azure Key Vault, and cipher suite configuration.

🔄
Engineering · PDP-7

Change Management Workflow

Process for requesting, reviewing, approving, and deploying changes to production. Covers standard, normal, and emergency change categories.

💻
Engineering · PDP-11

SDLC Security Review Process

Security activities at each SDLC phase: threat modeling, secure coding standards, OWASP code review checklist, SAST, DAST, and annual penetration testing.

Risk & Compliance

🗄
Compliance · DATA-16

Data Retention Policy

HIPAA-aligned retention schedule for PHI (6 years), audit logs, contracts, and financial records. Covers legal holds and automated enforcement.

🗑
Compliance · DATA-17

Data Disposal Policy

Secure destruction procedures for PHI on electronic media, cloud storage, and physical documents. Covers certificate of destruction requirements.

📊
Risk · BIZOPS-1

Risk Management Policy

Enterprise risk framework aligned to NIST RMF. Covers risk identification, scoring (Likelihood × Impact), treatment selection, and annual review cycle.

📈
Risk · BIZOPS-11

Risk Register

Active register of 12 identified risks — credential theft, ransomware, injection, insider threat, vendor breach — with scores, controls, and remediation status.

🙂
Risk · BIZOPS-12

Fraud Risk Assessment

Annual fraud risk review covering financial operations, healthcare billing, and technology domains with controls evaluation and anti-fraud program.

👥
Vendor · VNDR-2

Vendor Risk Assessment

Tier-based evaluation of critical vendors (Microsoft Azure, DoseSpot, Availity, Resend). Covers BAA status, certifications, and onboarding requirements.

🔥
Compliance · LOG-4

Security Event Logging Policy

Audit logging requirements for PHI access, authentication, API calls, and infrastructure events. Covers 6-year immutable retention and real-time alerting rules.

Infrastructure & DevOps

🏗
DevOps · INFRA-8

Host Hardening Documentation

Azure App Service security hardening: TLS configuration, cipher suites (Qualys A+), HSTS, security response headers, network isolation, and patch management.

🔍 No documents match your search. Try different keywords or .

Documents under NDA or not listed above? Contact steven@altnetix.com

Ready to proceed?

Our security team can provide a signed BAA, answer procurement questions, or schedule a technical deep-dive for your IT and compliance teams.