Rhapsody · Trust Center

Rhapsody Trust Center

Trust center

Rhapsody maintains a public trust center documenting SOC 2 Type II, ISO/IEC 27001:2022, HITRUST e1, EU-US & UK-US Data Privacy Framework, Cyber Essentials Plus, and Penetration Test Attestation compliance.

HealthcareUnited StatesInteroperabilityIntegration EngineFHIRHL7EMPITerminologyHealth DataMCP
Trust center: https://rhapsody.health/trust-center/

Certifications & Compliance

SOC 2 Type IIISO/IEC 27001:2022HITRUST e1EU-US & UK-US Data Privacy FrameworkCyber Essentials PlusPenetration Test Attestation

Source

Trust Center

rhapsody-trust-center.yml Raw ↑
generated: '2026-07-24'
method: searched
probe: false
source: https://rhapsody.health/trust-center/
url: https://rhapsody.health/trust-center/
summary: >-
  Rhapsody publishes a Trust and Compliance Center naming a full third-party
  certification and attestation program covering its cloud interoperability
  platform. Encryption is TLS 1.2+ in transit and AES-256 at rest. Regulatory
  posture is supported contractually (HIPAA via BAAs, GDPR via a DPA with SCCs).
certifications:
- name: SOC 2 Type II
  scope: Security trust service criteria; data integrity, backup and recovery
  validity: Reporting period May 2025 - April 2026
- name: ISO/IEC 27001:2022
  scope: Information security management; all Rhapsody solutions
  validity: Valid until April 2028
- name: HITRUST e1
  scope: Essential cybersecurity hygiene; Rhapsody cloud solutions (incl. Corepoint Integration)
  validity: Valid until December 2026
- name: EU-US & UK-US Data Privacy Framework
  scope: Lawful transatlantic data transfers
  validity: Valid until July 2026
- name: Cyber Essentials Plus
  scope: Hands-on technical verification of UK cyber security
  validity: Valid until June 2026
- name: Penetration Test Attestation
  scope: Third-party validation of platform and infrastructure security
  validity: Valid until March 2027
regulatory_frameworks:
- name: HIPAA
  mechanism: Business Associate Agreements (BAAs)
- name: GDPR
  mechanism: Data Processing Addendum (DPA) with Standard Contractual Clauses (SCCs)
- name: ONC Cures Act
  mechanism: Platform designed to support interoperability requirements
encryption:
  in_transit: TLS 1.2+
  at_rest: AES-256
contact:
  compliance: compliance@rhapsody.health
related_pages:
- https://rhapsody.health/data-privacy-and-security/
- https://rhapsody.health/onc-compliance/
- https://rhapsody.health/privacy-policy/