HIPAA-Compliant  ·  SOC 2 Ready  ·  Azure-Hosted

Trust & Security
Center

VitaAI is built for healthcare — where data integrity, patient privacy, and regulatory compliance aren't optional. Review our security controls, certifications, and compliance documentation.

256-bit AES Encryption at Rest
TLS 1.3 Encryption in Transit
FHIR R4 Epic-Certified Integration
99.9% SLA Uptime Guarantee

Infrastructure certifications & compliance — powered by Microsoft Azure

Enterprise-grade protection
at every layer

VitaAI implements defense-in-depth across infrastructure, application, and data layers — ensuring PHI is protected regardless of where it resides or transits.

🔒

Encryption at Rest

All stored data encrypted with AES-256. Azure Storage Service Encryption applied by default. Customer-managed key (CMK) support via Azure Key Vault available for enterprise accounts.

🔗

Encryption in Transit

All data in transit protected with TLS 1.3. Strict HTTPS enforcement with HSTS. Mutual TLS (mTLS) available for API integrations with EHR systems and internal service mesh.

📋

Audit Logging

Comprehensive, tamper-evident audit logs for all PHI access events. Logs retained for seven years minimum. Exportable to SIEM systems (Sentinel, Splunk). Real-time alerting on anomalous access patterns.

👤

Role-Based Access Control

Least-privilege RBAC with Azure Active Directory integration. Clinician, admin, and read-only roles with granular resource scoping. Just-in-time privileged access for administrative operations.

🔐

Field-Level Encryption

Sensitive PHI fields (SSN, DOB, diagnosis codes) encrypted individually at the application layer — separate from disk-level encryption — ensuring data is protected even within the database engine.

📱

MFA & SSO

Multi-factor authentication enforced for all user accounts. SAML 2.0 / OIDC single sign-on for seamless, secure integration with your organization's existing identity provider (Okta, Azure AD, Ping).

🌐

Network Isolation

Deployed within Azure Virtual Network with private endpoints. No public internet exposure of database or internal services. Azure DDoS Protection Standard enabled. Web Application Firewall (WAF) in front of all endpoints.

🔍

Vulnerability Management

Continuous dependency scanning with automated CVE alerting. Penetration testing conducted annually by independent third party. Responsible disclosure program in place for coordinated vulnerability reporting.

Business Continuity

Geo-redundant data replication across Azure paired regions. Recovery Point Objective (RPO) of 1 hour. Recovery Time Objective (RTO) of 4 hours. Automated failover tested quarterly.

HIPAA Compliance

Security & Privacy Rule Coverage
Administrative Safeguards Security management, training, contingency planning
Physical Safeguards Azure SOC-certified data centers with biometric access
Technical Safeguards Access controls, audit controls, integrity, transmission security
Organizational Requirements BAA available for all covered entity relationships
HITECH Act Compliance Breach notification, business associate obligations

Purpose-built for covered entities and business associates

VitaAI operates as a Business Associate under HIPAA when processing Protected Health Information on behalf of covered entities. We execute a Business Associate Agreement (BAA) with every customer that handles PHI.

Our security posture is validated through annual third-party HIPAA risk assessments aligned with the NIST Cybersecurity Framework and OCR guidance.

  • Signed BAA available to all customers
  • PHI processed only as directed under the BAA
  • Breach notification within 60 days per HITECH
  • De-identification methods per 45 CFR §164.514
  • Minimum Necessary Standard enforced
  • Employee HIPAA training required annually
  • Incident response plan tested bi-annually

Certified EHR connectivity

VitaAI integrates directly with Epic and other major EHR platforms via industry-standard APIs — no custom interfaces, no shadow copies of data.

Epic FHIR R4 Integration

VitaAI connects to Epic via the HL7 FHIR R4 API, enabling real-time, bidirectional clinical data exchange without bulk data exports or custom ETL pipelines. Patient data is queried on-demand, minimizing PHI at rest in VitaAI's systems. OAuth 2.0 SMART on FHIR authorization ensures patient-level consent is enforced at the Epic layer.

HL7 FHIR R4 SMART on FHIR OAuth 2.0 Epic MyChart CDS Hooks US Core 4.0 Cerner / Oracle Health Allscripts

Security & compliance documentation

Download our security documentation to accelerate your organization's vendor assessment and procurement process.

🗃
HIPAA

HIPAA Security Controls Overview

Detailed mapping of VitaAI's administrative, physical, and technical safeguards to the HIPAA Security Rule.

⇓ Download PDF
📄
OVERVIEW

Trust & Security Overview

Executive summary of VitaAI's security program, infrastructure architecture, and compliance posture for procurement teams.

⇓ Download PDF
📝
Template

Business Associate Agreement (BAA)

Standard BAA template for covered entities. Pre-signed by VitaAI. Send to legal for review or request a countersigned copy.

⇓ Download DOCX
Checklist

Self-Assessment Security Checklist

Vendor questionnaire responses aligned to NIST CSF, CIS Controls v8, and common hospital procurement frameworks.

⇓ Download PDF
🌎
Architecture

Client Deployment Architecture

Reference architecture diagrams showing network topology, data flows, integration points, and security boundaries for on-premise and cloud deployments.

⇓ Download PDF

Documents under NDA or not listed above? Contact steven@altnetix.com

Ready to proceed?

Our security team can provide a signed BAA, answer procurement questions, or schedule a technical deep-dive for your IT and compliance teams.