Compliance claims are normalized from current vendor documentation and independently reviewed by SOTA2.
HIPAA
ISO 22301
ISO/IEC 27001
SOC 2
End-to-end encryption of all data, both in storage and during transmission
Secure HTTPS protocol with SSL encryption for all website communications
Technical and organizational security measures consistent with HIPAA security safeguards
Strict access controls limiting data visibility to essential personnel only
Minimum necessary access policies for all health information
Organizational, technical and administrative measures to protect against unauthorized access, misuse, loss, disclosure, alteration and destruction of personal information
Data retention:
Benchmarks and comparisons
Independent benchmarksStructured task results are being verified.
Side-by-side comparisonsComparison workspaces will be available in a later release.