Trust & Safety
Security controls designed for healthcare operations.
Uverse Health maintains a security and compliance readiness program aligned to the needs of enterprise privacy, security, and regulatory teams.
Who this is for
CISOs, privacy officers, compliance teams and procurement reviewers evaluating Uverse Health for regulated healthcare data.
Compliance matrix
Frameworks & attestations.
Statuses below indicate readiness scope, not completed certification. Supporting materials are available during procurement when applicable.
| Framework | Status | Scope |
|---|---|---|
| HIPAA | In scope | US · PHI |
| SOC 2 Type II | In scope | Readiness program |
| HITRUST r2 | In scope | Readiness program |
| GDPR | In scope | EU · UK |
| ISO 27001 | In scope | Global |
| PIPEDA | In scope | Canada |
Subprocessors
Who we work with.
| Vendor | Purpose | Region |
|---|---|---|
| AWS | Primary infrastructure | US · EU · SG · AU |
| Cloudflare | Edge & DDoS | Global |
| Twilio | Secure notifications | Regional |
| Datadog | Monitoring | US · EU |
| Snowflake | Analytics data plane | Per residency |
Readiness checklist
Where the platform stands today.
A view of enterprise readiness and control implementation. Supporting details are available when applicable.
Readiness
Residency
Data stays where policy says it should.
Region
United States
Isolated storage · regional compute
Region
European Union
Isolated storage · regional compute
Region
Singapore
Isolated storage · regional compute
Region
Australia
Isolated storage · regional compute