Skip to main content

Security is part of the infrastructure

VectorCare sits inside clinical workflows, connects to EHRs, and handles protected health information for 2,500+ facilities. We hold ourselves to the same standard we'd expect from any vendor in our stack.

Certifications & compliance

SOC 2 Type IISOC 2 Type II

Independently audited

VectorCare has completed a SOC 2 Type II audit — the more rigorous standard that requires continuous evidence collection over an audit period, not just a point-in-time assessment. Our report is available under NDA for procurement teams.

Request the report
HIPAAHIPAA

Built for protected health information

All VectorCare systems, APIs, and data flows are designed for HIPAA compliance. We sign Business Associate Agreements with all covered entities we work with, and our subprocessor chain is reviewed and documented.

Epic Connection HubEpic Connection Hub

Listed on Epic's Connection Hub

VectorCare is listed on Epic's Connection Hub, built to SMART on FHIR standards. Our apps connect directly to Epic workflows without switching context.

How we protect your data

Eight controls that are documented, tested, and reviewed — not just technically possible.

Encrypted in transit and at rest

All data transmitted between VectorCare and connected systems uses TLS 1.2+. Data at rest is encrypted using strong cryptographic algorithms across all storage layers.

Role-based access controls

Access to patient data is scoped strictly to the functions required. Every user role is defined, documented, and reviewed on a defined cadence — at least twice a year.

Incident response

We maintain a documented, tested incident response plan with defined escalation paths and response SLAs. Incident response plan is documented and tested annually.

Continuous monitoring

Real-time alerting on access anomalies and failed authentication attempts — monitored and reviewed by our engineering and compliance leads.

Vendor risk management

Every subprocessor that handles patient data has a documented risk assessment and review cycle. We audit our vendors with the same rigour our customers apply to us.

Change management

Every production deployment follows a documented approval workflow with separation of duties. No unreviewed code reaches clinical environments.

Annual penetration testing

Annual black-box penetration testing by an independent third party against our web app, iOS app, backend APIs, and network assets. All findings are tracked to resolution.

Vulnerability scanning

Continuous container image scanning with 100% coverage. Production systems are scanned at least quarterly with high-priority findings tracked to SLA.

Infrastructure & data residency

Hosted on AWS

All VectorCare infrastructure runs on Amazon Web Services. All data is stored in the United States.

Data retention

Data is retained while your account is active and for a minimum of one year after closure before permanent deletion. Full data export is available on request.

Continuous compliance monitoring

Controls are monitored continuously via Drata. An annual internal risk assessment is conducted — the 2026 assessment identified zero high-severity risks.

For procurement teams

If you're evaluating VectorCare for your health system, here's what we're prepared to share with documented evidence:

  • SOC 2 Type II report (available under NDA)
  • HIPAA Business Associate Agreement
  • Penetration testing results
  • Subprocessor list
  • Incident response SLAs
  • Data retention and deletion policy
  • Annual penetration test results (most recent: December 2025, zero high-severity findings)
  • Vulnerability scanning reports

You can also visit our live trust centre at security.vectorcare.com for real-time compliance status.

Our security philosophy

VectorCare is infrastructure. We sit inside the EHR, orchestrate patient logistics decisions in real time, and connect clinical workflows to the supply chain of healthcare delivery. If that layer isn't secure, nothing built on top of it is secure either.

SOC 2 attestation isn't the finish line — it's the baseline. We continue to invest in security at the same level we invest in product capability, because for the health systems that trust us with their clinical workflows, those are the same thing.

Read how we approached our SOC 2 audit