Holmusk · Trust Center

Holmusk Trust Center

Trust center

Holmusk maintains a public trust center documenting HITRUST CSF and HIPAA / HITECH compliance.

CompanyHealthcareReal-World EvidenceBehavioral HealthMental HealthNeuropsychiatryClinical DataData AnalyticsLife SciencesHIPAA
Trust center: https://policy.holmusk.com/

Certifications & Compliance

HITRUST CSFHIPAA / HITECH

Source

Trust Center

holmusk-trust-center.yml Raw ↑
generated: '2026-08-22'
method: searched
probe: true
url: https://policy.holmusk.com/
title: Holmusk HIPAA Compliance Policies
source: https://policy.holmusk.com/
note: >-
  Holmusk does not run a conventional "trust center" (trust.holmusk.com does not resolve;
  holmusk.com/trust, /security and /compliance all return 404). What it does publish — openly,
  with no login — is its full HIPAA compliance policy set at policy.holmusk.com: ~176,000
  characters covering policy management, risk management, roles, data management, system access,
  incident response, breach notification, business continuity, configuration management and
  vulnerability management, each section mapped to the HITRUST Common Security Framework control
  and the HIPAA Security Rule citation it satisfies. That is a stronger public compliance artifact
  than most trust pages, so it is recorded here.
certifications:
- name: HITRUST CSF
  status: claimed
  evidence: >-
    "current production systems on this platform are included in Holmusk's third-party audits and
    HITRUST compliance" — policy.holmusk.com §1.2 Compliance Inheritance. Every policy section
    lists "Applicable Standards from the HITRUST Common Security Framework".
- name: HIPAA / HITECH
  status: claimed
  evidence: >-
    Policy set is structured as HIPAA Security Rule + HITECH Act control mappings
    (e.g. 164.316(b)(1)(i), 13402(a)/(b)); Holmusk operates as a HIPAA business associate for
    customer ePHI.
not_claimed:
- name: SOC 2
  note: >-
    SOC 2 appears on policy.holmusk.com only as something Holmusk REVIEWS in its vendors
    ("annual assessment of SOC2 reports for all Holmusk infrastructure partners"). Holmusk does
    not claim a SOC 2 report of its own anywhere public, and it is not recorded as one here.
- name: ISO 27001
  note: Not mentioned on any public Holmusk surface probed on 2026-08-22.
audit_reports:
  public: false
  detail: >-
    "Holmusk, at its sole discretion, shares audit reports, including its HITRUST reports and
    Corrective Action Plans (CAPs), with customers on a case by case basis. All audit reports are
    shared under explicit NDA." — policy.holmusk.com §1.4
hosting:
  provider: Amazon Web Services
  detail: Production infrastructure hosted on AWS; nginx web servers with Haskell, Java and NodeJS application servers (policy.holmusk.com §1.3).
evidence:
- source: https://policy.holmusk.com/
  status: 200
  keywords: [hipaa, hitrust, hitech, penetration testing, incident response, breach]
- source: https://trust.holmusk.com/
  status: DNS NXDOMAIN
- source: https://www.holmusk.com/security
  status: 404
- source: https://www.holmusk.com/trust
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/holmusk-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.