b.well · Trust Center
B Well Trust Center
Trust center
b.well maintains a public trust center documenting HITRUST, NIST Cybersecurity Framework (CSF), and HIPAA compliance.
CompanyHealthHealthcareDigital HealthFHIRHealth DataInteroperabilityPatient AccessHealth RecordsMCP
Certifications & Compliance
HITRUSTNIST Cybersecurity Framework (CSF)HIPAA
Source
Trust Center
generated: '2026-08-15'
method: searched
source: https://www.icanbwell.com/health-data-security-for-consumers/
url: https://www.icanbwell.com/health-data-security-for-consumers/
name: b.well Health Data Security
detail: >-
b.well does not operate a hosted trust center (no trust.icanbwell.com — TLS
handshake fails — and no /security/ or /trust/ page on the corporate site). It
publishes its security and compliance posture as a narrative page on its own domain,
which names the certifications below and describes the audit cadence behind them.
certifications:
- HITRUST
- NIST Cybersecurity Framework (CSF)
- HIPAA
frameworks:
- name: CARIN Alliance Trust Framework and Code of Conduct
voluntary: true
detail: >-
b.well states it "voluntarily follows the CARIN Alliance Trust Framework and Code
of Conduct" — the consumer-directed health data exchange code of conduct, which is
the relevant governance layer for a consumer-mediated network.
audit:
cadence: annual security reviews; independent external verification at least biennially
quote: >-
"Our systems are subject to annual security reviews and have achieved HITRUST and
US NIST cybersecurity framework (CSF) certification, which require independent
verification of our security-related policies, procedures, and implemented controls
by external auditors on at least a biennial (2 year) basis."
encryption:
quote: >-
"Your data is encrypted in secure servers, not stored on your local device; and
always encrypted during transmissions."
at_rest: true
in_transit: true
gaps:
- No downloadable or gated report portal (no SOC 2 / HITRUST report request flow published).
- No report date, scope statement or auditor named, so the currency of each certification
cannot be verified from the public page.
- SOC 2 is claimed for the bailey product in press material but is not asserted on b.well's
own security page, so it is NOT recorded as a certification here.
evidence:
- source: https://www.icanbwell.com/health-data-security-for-consumers/
keywords:
- hitrust
- nist cybersecurity framework
- hipaa
- carin alliance
x-evidence:
fetched: '2026-08-15'
evidence:
- url: https://www.icanbwell.com/health-data-security-for-consumers/
status: 200
- url: https://www.icanbwell.com/security/
status: 404
- url: https://www.icanbwell.com/trust/
status: 404
- url: https://trust.icanbwell.com/
status: 0
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/b-well-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.