Security

Your data,gold standard.

Our interoperability platform keeps patient information safe with 100% cloud hosting, HITRUST certifications, and third-party audits. Just Connect exceeds industry, HIPAA-compliant, and NIST-recommended encryption standards.

Certifications

HITRUST r2. SOC 2 Type 2. HIPAA. Every year.

For all our cloud environments, Just Connect maintains HITRUST certification. For transactions on AWS and GCP, we hold the HITRUST r2 certification, the highest standard achievable, validated by a third-party auditor. We maintain a SOC 2 Type 2 report continuously, with SOC 3 available on request.

  • HITRUST CSF r2
  • SOC 2 Type 2
  • HIPAA
  • GDPR
  • CCPA / CPRA
  • NIST CSF

Safe data connections you can trust.

100% hosted on AWS and GCP, with BAAs in place.

CapabilityLayerControlDetail
TransportEncryptionEnd-to-end over HTTPS and managed VPNTLS 1.2+, forced HTTPS
HostingIsolationPrivate subnets for databases and app containersAutomatic security updates
AuthenticationZero TrustOAuth, salted and hashed credentialsMFA for every dashboard user
ResilienceFailoverEncrypted redundant backupsNo interruptions during deploys
AssuranceBug bountyPublic program managed by HackerOne500+ researchers per year
Monitoring24/7Dark-web and intel monitoring for compromised accountsAssisted resolution
Controls

Application security you can count on.

Defense in depth, from connection to dashboard.

Connection safeguards

End-to-end encryption over HTTPS, private subnet hosting, automatic endpoint updates.

Authentication

OAuth and other protocols, salted and hashed credentials, Zero Trust built on CISA guidance.

Access control

SSO, RBAC, two-factor authentication for all dashboard users and support employees.

Audit APIs

Pull every access and configuration change into your own SIEM.

Data minimization

Filters keep PHI from traveling further than a workflow requires.

Incident response

Compromised-account alerts, assisted resolution, and a public disclosure process.

Shared responsibility

Security is a partnership.

We publish a shared responsibility model, allow-listing guidance, and trust documentation so your security team knows exactly where the line is.

  • Shared responsibility model
  • Allow-listing guidance
  • BAA templates
  • SOC 3 on request

Stuff your CISO needs to see.

Request our HITRUST certificate, SOC 2 report, and penetration test summary.