Hiive Health Security & Compliance Posture Overview
CLASSIFICATION: External — Approved for Client Distribution
Field | Value |
|---|---|
Document version | v3.3 |
Last updated | August 21, 2026 |
Document owner | Compliance — compliance@hiivehealth.com |
Applies to | Hiive Health SaaS Products |
1. Overview
This document summarizes the security and compliance posture of the Hiive Health Saas products. It is intended for prospective and current clients, and may be shared in response to security and vendor-risk questionnaires. It describes our current control environment as of the date above, including certification status, encryption practices, incident response, and third-party subprocessors.
Where a control is in progress rather than fully attested, this document states so plainly. Nothing in this overview should be read as a claim of certification that has not yet been formally achieved.
2. Compliance & Certifications
SOC 2
Status: In Preparation (not currently certified). Hiive Health has mapped its internal controls to the AICPA Trust Service Criteria and is preparing for a formal SOC 2 examination. A third-party audit has not yet been completed, and no SOC 2 report is available at this time. This overview will be updated when the examination is underway or complete.
HIPAA
The platform is operated in alignment with the HIPAA Security Rule and Breach Notification Rule. Business Associate Agreements (BAAs) are maintained with the subprocessors listed in Section 5, and breach handling follows the process described in Section 4.
3. Data Encryption
Customer data is encrypted both at rest and in transit using industry-standard algorithms and protocols.
Layer | Control |
|---|---|
At rest | AES-256 encryption via AWS KMS using customer-managed keys (CMK). |
In transit | TLS 1.2 or higher enforced for all client and service traffic. |
Database layer | SSL/TLS enforced at the infrastructure layer for Amazon RDS connections. |
4. Incident Response & Breach Notification
In the event of a confirmed breach of protected health information, Hiive Health notifies affected parties within 60 days, consistent with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). Documented notification templates are maintained to support timely and consistent communication.
Incidents are managed through a documented seven-phase incident response process:
Detection — identify and log the potential incident.
Triage — assess scope, severity, and data involved.
Containment — limit the spread and impact of the incident.
Eradication — remove the root cause and any residual threat.
Recovery — restore affected systems to normal operation.
Notification — inform affected parties and regulators as required.
Post-Incident Review — capture lessons learned and remediate gaps.
5. Subprocessors
Hiive Health uses the following third-party subprocessors in the delivery of the ePA platform. A Business Associate Agreement (BAA) is in place with each subprocessor that may process protected health information.[a]
Subprocessor | Purpose | Agreement |
|---|---|---|
Amazon Web Services (AWS) | Cloud infrastructure, hosting, storage, and key management. | BAA in place |
Slack | Internal operational communication and alerting. | BAA in place |
PagerDuty | On-call incident alerting and escalation. | BAA in place |
Note: This list reflects vendors with active Business Associate Agreements. Clients requiring a formal, versioned subprocessor disclosure as part of a Data Processing Agreement should contact the document owner below.
6. Contact
For the current version of this document, a copy under NDA, or to raise a security or compliance question, contact compliance@hiivehealth.com.
This overview is provided for informational purposes and reflects the platform’s posture as of the last-updated date. It does not constitute a warranty or a certification.
External — Approved for Client DistributionPage of
[a]Working with @Audrey Brown to make sure epa subs are included here. Will add others as we go live with our other products.