Healthy.io · Trust Center

Healthy.Io Trust Center

Trust center

Healthy.io maintains a public trust center documenting ISO/IEC 27001:2013, ISO 22301:2019, ISO 13485:2016, HITRUST, UK Cyber Essentials, and NHS Data Security and Protection Toolkit compliance.

CompanyHealthHealthcareDigital HealthMedical DevicesDiagnosticsUrinalysisKidney CareWound CareComputer VisionRemote Patient MonitoringTelehealthSMART on FHIRHIPAA
Trust center:

Certifications & Compliance

ISO/IEC 27001:2013ISO 22301:2019ISO 13485:2016HITRUSTUK Cyber EssentialsNHS Data Security and Protection Toolkit

Source

Trust Center

healthy.io-trust-center.yml Raw ↑
generated: '2026-08-22'
method: searched
source: https://healthy.io/trust-center/
name: Healthy.io Trust Center
trust_center:
  url: https://healthy.io/trust-center/
  status: 200
  hosted: first-party
  platform: self-hosted (healthy.io/trust-center/*, indexed in the site sitemap)
  gated: false
  note: >-
    Healthy.io publishes a first-party trust center on its own domain with 60+ individually
    addressable, crawlable pages across four sections - Security, Privacy, Compliance and
    Availability. Every page probed returned HTTP 200 with no login, form or NDA. This is the
    single richest public machine-reachable surface the company publishes; it is substantially
    more detailed than the trust page of most companies of this size.
sections:
- name: Security
  url: https://healthy.io/trust-center/security
  status: 200
  topics:
  - access control
  - asset management
  - background checks
  - configuration management
  - data disposal
  - emergency changes
  - encryption at rest
  - encryption in transit
  - endpoint security
  - incident response
  - information protection program
  - logs
  - mobile device security
  - network protection
  - password management
  - penetration test
  - physical security
  - portable media security
  - privileged account monitoring
  - reporting suspected vulnerabilities
  - risk management
  - secure SDLC
  - security awareness program
  - security team
  - third parties insurance
  - transmission protection
  - vulnerability management
  - wireless security
- name: Privacy
  url: https://healthy.io/trust-center/privacy
  status: 200
  topics:
  - data retention
  - GDPR
  - government request
  - HIPAA
  - Healthy.io privacy policy
- name: Compliance
  url: https://healthy.io/trust-center/compliance
  status: 200
  topics:
  - anti-kickback and Stark laws
  - business continuity
  - certifications
  - data breach notification
  - DTAC
  - FDA
  - GDPR
  - government request
  - HIPAA
  - HITRUST
  - ISO 22301:2019
  - ISO 27001:2013
  - medical devices quality management systems
  - NHS Data Security and Protection Toolkit
  - UK Cyber Essentials
- name: Availability
  url: https://healthy.io/trust-center/availability
  status: 200
  topics:
  - business continuity
  - certifications
  - data backups
  - data center location
  - data retention
  - disaster recovery
  - information security and privacy policy statement
  - ISO 22301:2019
certifications:
- name: ISO/IEC 27001:2013
  category: information security management
  url: https://healthy.io/trust-center/compliance/iso-27001-2013
  status: 200
  evidence: named on the trust center certifications page
- name: ISO 22301:2019
  category: business continuity management
  url: https://healthy.io/trust-center/compliance/iso-22301-2019
  status: 200
  evidence: named on the trust center certifications page
- name: ISO 13485:2016
  category: medical devices quality management systems
  url: https://healthy.io/trust-center/compliance/medical-devices-quality-management-systems-requirements-for-regulatory-purposes
  status: 200
  evidence: >-
    named verbatim as "Medical devices - Quality management systems - Requirements for
    regulatory purposes" on the trust center
- name: HITRUST
  category: healthcare security framework
  url: https://healthy.io/trust-center/compliance/hitrust
  status: 200
  evidence: HITRUST Validated Assessment Report named on the certifications page; scope not stated
- name: UK Cyber Essentials
  category: UK government cyber baseline
  url: https://healthy.io/trust-center/compliance/uk-cyber-essentials
  status: 200
  evidence: certificate dated 2022-2023 on the certifications page
- name: NHS Data Security and Protection Toolkit
  category: UK NHS data security
  url: https://healthy.io/trust-center/compliance/nhs-data-security-and-protection-toolkit
  status: 200
  evidence: 2022-23 version, "standards met"
regulatory_programs:
- name: HIPAA
  url: https://healthy.io/trust-center/compliance/hipaa
  status: 200
- name: GDPR
  url: https://healthy.io/trust-center/compliance/gdpr
  status: 200
- name: FDA
  url: https://healthy.io/trust-center/compliance/fda
  status: 200
  note: Minuteful Kidney holds FDA 510(k) clearance for home use
- name: NHS DTAC (Digital Technology Assessment Criteria)
  url: https://healthy.io/trust-center/compliance/dtac
  status: 200
- name: Anti-Kickback Statute and Stark Law
  url: https://healthy.io/trust-center/compliance/anti-kickback-and-stark-laws
  status: 200
- name: Data breach notification
  url: https://healthy.io/trust-center/compliance/data-breach-notification
  status: 200
gaps:
- >-
  Certification currency is not machine-readable: the UK Cyber Essentials certificate is dated
  2022-2023 and the NHS DSPT entry is the 2022-23 version, with no stated renewal date on the
  page. A reader cannot tell from the trust center whether these are current.
- >-
  No SOC 2 report is named anywhere on the trust center - notable for a US-market health
  vendor selling to health systems and payers.
- >-
  There is no machine-readable index of the trust center (no JSON, no .well-known/api-catalog);
  the only crawlable index is the HTML sitemap at https://healthy.io/sitemap.xml.
x-evidence:
  fetched: '2026-08-22'
  probes:
  - url: https://healthy.io/trust-center/
    status: 200
  - url: https://healthy.io/trust-center/compliance/certifications
    status: 200
  - url: https://healthy.io/trust-center/security
    status: 200
  - url: https://healthy.io/trust-center/privacy
    status: 200
  - url: https://healthy.io/trust-center/availability
    status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/healthy.io-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.