Hiive Health Security & Compliance Posture Overview

CLASSIFICATION: External — Approved for Client Distribution

Field

Value

Document version

v3.3

Last updated

August 21, 2026

Document owner

Compliance — compliance@hiivehealth.com

Applies to

Hiive Health SaaS Products

1. Overview

This document summarizes the security and compliance posture of the Hiive Health Saas products. It is intended for prospective and current clients, and may be shared in response to security and vendor-risk questionnaires. It describes our current control environment as of the date above, including certification status, encryption practices, incident response, and third-party subprocessors.

Where a control is in progress rather than fully attested, this document states so plainly. Nothing in this overview should be read as a claim of certification that has not yet been formally achieved.

2. Compliance & Certifications

SOC 2

Status: In Preparation (not currently certified). Hiive Health has mapped its internal controls to the AICPA Trust Service Criteria and is preparing for a formal SOC 2 examination. A third-party audit has not yet been completed, and no SOC 2 report is available at this time. This overview will be updated when the examination is underway or complete.

HIPAA

The platform is operated in alignment with the HIPAA Security Rule and Breach Notification Rule. Business Associate Agreements (BAAs) are maintained with the subprocessors listed in Section 5, and breach handling follows the process described in Section 4.

3. Data Encryption

Customer data is encrypted both at rest and in transit using industry-standard algorithms and protocols.

Layer

Control

At rest

AES-256 encryption via AWS KMS using customer-managed keys (CMK).

In transit

TLS 1.2 or higher enforced for all client and service traffic.

Database layer

SSL/TLS enforced at the infrastructure layer for Amazon RDS connections.

4. Incident Response & Breach Notification

In the event of a confirmed breach of protected health information, Hiive Health notifies affected parties within 60 days, consistent with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). Documented notification templates are maintained to support timely and consistent communication.

Incidents are managed through a documented seven-phase incident response process:

  • Detection — identify and log the potential incident.

  • Triage — assess scope, severity, and data involved.

  • Containment — limit the spread and impact of the incident.

  • Eradication — remove the root cause and any residual threat.

  • Recovery — restore affected systems to normal operation.

  • Notification — inform affected parties and regulators as required.

  • Post-Incident Review — capture lessons learned and remediate gaps.

5. Subprocessors

Hiive Health uses the following third-party subprocessors in the delivery of the ePA platform. A Business Associate Agreement (BAA) is in place with each subprocessor that may process protected health information.[a]

Subprocessor

Purpose

Agreement

Amazon Web Services (AWS)

Cloud infrastructure, hosting, storage, and key management.

BAA in place

Slack

Internal operational communication and alerting.

BAA in place

PagerDuty

On-call incident alerting and escalation.

BAA in place

Note: This list reflects vendors with active Business Associate Agreements. Clients requiring a formal, versioned subprocessor disclosure as part of a Data Processing Agreement should contact the document owner below.

6. Contact

For the current version of this document, a copy under NDA, or to raise a security or compliance question, contact compliance@hiivehealth.com.

This overview is provided for informational purposes and reflects the platform’s posture as of the last-updated date. It does not constitute a warranty or a certification.

External — Approved for Client DistributionPage of

[a]Working with @Audrey Brown to make sure epa subs are included here. Will add others as we go live with our other products.

Protected by U.S. Patent Nos. 10,320,903 and 11,431,796

©2026 Hiive Health. All Rights Reserved.

Protected by U.S. Patent Nos. 10,320,903 and 11,431,796

©2026 Hiive Health. All Rights Reserved.

Protected by U.S. Patent Nos. 10,320,903 and 11,431,796

©2026 Hiive Health. All Rights Reserved.

Protected by U.S. Patent Nos. 10,320,903 and 11,431,796

©2026 Hiive Health. All Rights Reserved.