Holmusk · Trust Center
Holmusk Trust Center
Trust center
Holmusk maintains a public trust center documenting HITRUST CSF and HIPAA / HITECH compliance.
CompanyHealthcareReal-World EvidenceBehavioral HealthMental HealthNeuropsychiatryClinical DataData AnalyticsLife SciencesHIPAA
Trust center: https://policy.holmusk.com/
Certifications & Compliance
HITRUST CSFHIPAA / HITECH
Source
Trust Center
generated: '2026-08-22'
method: searched
probe: true
url: https://policy.holmusk.com/
title: Holmusk HIPAA Compliance Policies
source: https://policy.holmusk.com/
note: >-
Holmusk does not run a conventional "trust center" (trust.holmusk.com does not resolve;
holmusk.com/trust, /security and /compliance all return 404). What it does publish — openly,
with no login — is its full HIPAA compliance policy set at policy.holmusk.com: ~176,000
characters covering policy management, risk management, roles, data management, system access,
incident response, breach notification, business continuity, configuration management and
vulnerability management, each section mapped to the HITRUST Common Security Framework control
and the HIPAA Security Rule citation it satisfies. That is a stronger public compliance artifact
than most trust pages, so it is recorded here.
certifications:
- name: HITRUST CSF
status: claimed
evidence: >-
"current production systems on this platform are included in Holmusk's third-party audits and
HITRUST compliance" — policy.holmusk.com §1.2 Compliance Inheritance. Every policy section
lists "Applicable Standards from the HITRUST Common Security Framework".
- name: HIPAA / HITECH
status: claimed
evidence: >-
Policy set is structured as HIPAA Security Rule + HITECH Act control mappings
(e.g. 164.316(b)(1)(i), 13402(a)/(b)); Holmusk operates as a HIPAA business associate for
customer ePHI.
not_claimed:
- name: SOC 2
note: >-
SOC 2 appears on policy.holmusk.com only as something Holmusk REVIEWS in its vendors
("annual assessment of SOC2 reports for all Holmusk infrastructure partners"). Holmusk does
not claim a SOC 2 report of its own anywhere public, and it is not recorded as one here.
- name: ISO 27001
note: Not mentioned on any public Holmusk surface probed on 2026-08-22.
audit_reports:
public: false
detail: >-
"Holmusk, at its sole discretion, shares audit reports, including its HITRUST reports and
Corrective Action Plans (CAPs), with customers on a case by case basis. All audit reports are
shared under explicit NDA." — policy.holmusk.com §1.4
hosting:
provider: Amazon Web Services
detail: Production infrastructure hosted on AWS; nginx web servers with Haskell, Java and NodeJS application servers (policy.holmusk.com §1.3).
evidence:
- source: https://policy.holmusk.com/
status: 200
keywords: [hipaa, hitrust, hitech, penetration testing, incident response, breach]
- source: https://trust.holmusk.com/
status: DNS NXDOMAIN
- source: https://www.holmusk.com/security
status: 404
- source: https://www.holmusk.com/trust
status: 404
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/holmusk-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.