Security is part of the infrastructure
VectorCare sits inside clinical workflows, connects to EHRs, and handles protected health information for 2,500+ facilities. We hold ourselves to the same standard we'd expect from any vendor in our stack.
Certifications & compliance
SOC 2 Type IIIndependently audited
VectorCare has completed a SOC 2 Type II audit — the more rigorous standard that requires continuous evidence collection over an audit period, not just a point-in-time assessment. Our report is available under NDA for procurement teams.
Request the reportBuilt for protected health information
All VectorCare systems, APIs, and data flows are designed for HIPAA compliance. We sign Business Associate Agreements with all covered entities we work with, and our subprocessor chain is reviewed and documented.
Epic Connection HubListed on Epic's Connection Hub
VectorCare is listed on Epic's Connection Hub, built to SMART on FHIR standards. Our apps connect directly to Epic workflows without switching context.
How we protect your data
Eight controls that are documented, tested, and reviewed — not just technically possible.
Encrypted in transit and at rest
All data transmitted between VectorCare and connected systems uses TLS 1.2+. Data at rest is encrypted using strong cryptographic algorithms across all storage layers.
Role-based access controls
Access to patient data is scoped strictly to the functions required. Every user role is defined, documented, and reviewed on a defined cadence — at least twice a year.
Incident response
We maintain a documented, tested incident response plan with defined escalation paths and response SLAs. Incident response plan is documented and tested annually.
Continuous monitoring
Real-time alerting on access anomalies and failed authentication attempts — monitored and reviewed by our engineering and compliance leads.
Vendor risk management
Every subprocessor that handles patient data has a documented risk assessment and review cycle. We audit our vendors with the same rigour our customers apply to us.
Change management
Every production deployment follows a documented approval workflow with separation of duties. No unreviewed code reaches clinical environments.
Annual penetration testing
Annual black-box penetration testing by an independent third party against our web app, iOS app, backend APIs, and network assets. All findings are tracked to resolution.
Vulnerability scanning
Continuous container image scanning with 100% coverage. Production systems are scanned at least quarterly with high-priority findings tracked to SLA.
Infrastructure & data residency
Hosted on AWS
All VectorCare infrastructure runs on Amazon Web Services. All data is stored in the United States.
Data retention
Data is retained while your account is active and for a minimum of one year after closure before permanent deletion. Full data export is available on request.
Continuous compliance monitoring
Controls are monitored continuously via Drata. An annual internal risk assessment is conducted — the 2026 assessment identified zero high-severity risks.
For procurement teams
If you're evaluating VectorCare for your health system, here's what we're prepared to share with documented evidence:
- SOC 2 Type II report (available under NDA)
- HIPAA Business Associate Agreement
- Penetration testing results
- Subprocessor list
- Incident response SLAs
- Data retention and deletion policy
- Annual penetration test results (most recent: December 2025, zero high-severity findings)
- Vulnerability scanning reports
You can also visit our live trust centre at security.vectorcare.com for real-time compliance status.
Our security philosophy
VectorCare is infrastructure. We sit inside the EHR, orchestrate patient logistics decisions in real time, and connect clinical workflows to the supply chain of healthcare delivery. If that layer isn't secure, nothing built on top of it is secure either.
SOC 2 attestation isn't the finish line — it's the baseline. We continue to invest in security at the same level we invest in product capability, because for the health systems that trust us with their clinical workflows, those are the same thing.
Read how we approached our SOC 2 audit