Solera Health · Trust Center

Solera Health Trust Center

Trust center

Solera Health maintains a public trust center documenting SOC 2 Type 2, HITRUST CSF Certified (r2), HIPAA, and FIPS 140-2 (key management) compliance.

CompanyHealthHealthcareDigital HealthBenefitsEmployee BenefitsHealth PlansPayerProvider NetworkChronic Condition ManagementPreventive CareTelehealth
Trust center:

Certifications & Compliance

SOC 2 Type 2HITRUST CSF Certified (r2)HIPAAFIPS 140-2 (key management)

Source

Trust Center

solera-health-trust-center.yml Raw ↑
generated: '2026-08-28'
method: searched
source: https://www.soleranetwork.com/trust-center
trust_center:
  url: https://www.soleranetwork.com/trust-center
  status: 200
  public: true
  authentication_required: false
certifications:
- id: soc-2-type-2
  name: SOC 2 Type 2
  status: attested
  scope: Security, Availability, Processing Integrity, Confidentiality, Privacy
  evidence: >-
    Trust Center states a SOC 2 Type 2 report is maintained - "an internal controls report
    capturing how a company safeguards customer data" - across all five trust services criteria.
  report_available: not stated on the public page
- id: hitrust-r2
  name: HITRUST CSF Certified (r2)
  status: certified
  evidence: HITRUST Certified badge displayed on the Trust Center page.
- id: hipaa
  name: HIPAA
  status: conformant
  evidence: >-
    "Conform to HIPAA and HITRUST industry healthcare specific requirements." Solera Health
    operates as a business associate handling protected health information for payers and employers.
- id: fips-140-2
  name: FIPS 140-2 (key management)
  status: component-level
  evidence: >-
    Trust Center describes a "sophisticated, FIPS 140-2-certified, HSM-based, key management
    architecture." This is a claim about the HSM used, not a certification of Solera Health itself.
controls_published:
  encryption_at_rest: AES-256, BitLocker Drive Encryption
  encryption_in_transit: SSL/TLS (TLS 1.1 or higher stated), IPsec
  key_management: FIPS 140-2 certified HSM
contacts:
- purpose: compliance
  email: compliance@soleranetwork.com
  source: https://www.soleranetwork.com/trust-center
privacy:
- name: Privacy Policy
  url: https://www.soleranetwork.com/privacy-policy
  status: 200
- name: Notice of Privacy Practices
  url: https://www.soleranetwork.com/notice-of-privacy-practices
  status: 200
gaps:
- No subprocessor list published.
- No security status page (status.soleranetwork.com does not resolve).
- No vulnerability disclosure policy, no security.txt, no bug bounty program.
- No downloadable report request flow on the public page.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/solera-health-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.