Healthie · Trust Center

Healthie Trust Center

Trust center

Healthie maintains a public trust center documenting HIPAA, SOC 2 Type 2, HITRUST CSF r2, ONC Health IT Certification, PCI DSS Service Provider Level 1 (held by Healthie’s payment processor, not by Healthie), GDPR, and PIPEDA compliance.

API-FirstAppointmentsBillingCare PlansChartingClaimsClinicalDigital HealthEHREMRFormsGraphQLHealth TechHealthcareInsuranceIntakeOnline ProgramsPatient EngagementPatient PortalPractice ManagementProgramsSchedulingTelehealthWellnessWebhook
Trust center: https://trust.gethealthie.com

Certifications & Compliance

HIPAASOC 2 Type 2HITRUST CSF r2ONC Health IT CertificationPCI DSS Service Provider Level 1 (held by Healthie's payment processor, not by Healthie)GDPRPIPEDA

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://trust.gethealthie.com
url: https://trust.gethealthie.com
platform: Vanta
platform_evidence: 'og:image resolves to https://app.vanta.com/doc?s=7fl6tpu48qh2pynckbhde'
rendering: javascript-rendered
rendering_note: >-
  The trust center returns HTTP 200 but its served HTML is an empty shell — the certification list,
  document requests and subprocessor table only exist after script execution. The certification list
  below was therefore read from the server-rendered security page at
  https://www.gethealthie.com/security, which enumerates the same programs in crawlable HTML.
secondary_source: https://www.gethealthie.com/security
certifications:
- HIPAA
- SOC 2 Type 2
- HITRUST CSF r2
- ONC Health IT Certification
- PCI DSS Service Provider Level 1 (held by Healthie's payment processor, not by Healthie)
- GDPR
- PIPEDA
baa:
  available: true
  url: https://www.gethealthie.com/baa
security_program:
- Annual third-party penetration testing
- Annual disaster recovery tabletop exercises
- Annual risk assessments
- Quarterly vulnerability scans
- Biometric access control, surveillance and 24/7 guards at hosting facilities
- Redundant power and data backup under a documented disaster recovery plan
- 256-bit TLS for data in transit
- Audit logging across application, SQL query and platform backend activity
cyber_insurance:
  published: true
  note: >-
    Healthie publishes a cybersecurity coverage article covering technology and professional
    liability, security and privacy liability and security breach response.
  url: https://help.gethealthie.com/article/1114-cybersecurity-coverage
contacts:
  compliance: compliance@gethealthie.com
  general: hello@gethealthie.com
vulnerability_disclosure:
  published: false
  note: >-
    No vulnerability disclosure program was found. There is no /.well-known/security.txt on any
    Healthie host, no /responsible-disclosure or /vulnerability-disclosure page, and no HackerOne or
    Bugcrowd program (hackerone.com/healthie and bugcrowd.com/healthie both 404). Healthie publishes
    a compliance@ address but no security-reporting address and no safe-harbour statement. For a
    HITRUST- and SOC 2-certified platform holding PHI, this is the most conspicuous single gap on the
    public security surface — and the cheapest to close. No VulnerabilityDisclosure or Security
    pointer is wired into apis.yml, because there is nothing to point at.
  checked: '2026-08-14'
supersedes:
  previous_source: https://www.gethealthie.com/hipaa-compliant-software
  previous_certifications: [HIPAA, GDPR]
  reason: >-
    The automated probe (0-working/probe-security-programs.py) matched a marketing page carrying only
    two keywords. This pass replaces it with the actual Vanta trust center plus the full
    server-rendered certification list.
evidence:
- {source: 'https://trust.gethealthie.com', http_status: 200, keywords: [trust center, security,
      compliance]}
- {source: 'https://www.gethealthie.com/security', http_status: 200, keywords: [hipaa, soc 2, hitrust,
      onc, pci, gdpr, pipeda]}
- {source: 'https://www.gethealthie.com/baa', http_status: 200, keywords: [business associate agreement]}
- {source: 'https://hackerone.com/healthie', http_status: 404}
- {source: 'https://bugcrowd.com/healthie', http_status: 404}
- {source: 'https://www.gethealthie.com/.well-known/security.txt', http_status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/healthie-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.