Security and privacy

Privacy by design for healthcare referral workflows.

Elvra is HIPAA, PIPEDA and PHIPA compliant, offers Business Associate Agreements for applicable U.S. customers and has a SOC 2 program in progress.

01

HIPAA, PIPEDA and PHIPA compliant

Elvra maintains the processes and controls required for compliant use across U.S. and Canadian healthcare environments.

02

Business Associate Agreements

Elvra can enter into a Business Associate Agreement with applicable U.S. customers.

03

SOC 2 in progress

Elvra’s SOC 2 program is underway.

For specialty practices

Get the essentials for a confident review.

Use authorized access, human approval and a Business Associate Agreement for your referral workflow. Request Elvra’s current security materials when your team is ready.

For health systems

Support a complete security evaluation.

  • Data flow and deployment information
  • Access, tenant and identity controls
  • Encryption and infrastructure information
  • Subprocessor, retention and residency details
  • Audit, monitoring and incident processes
  • Current SOC 2 program status

External references

Official privacy and security references.

Applicable requirements depend on the organization, information, jurisdiction and data flow. These primary government sources provide the governing context for U.S. and Canadian evaluations.

HIPAA Security Rule

The HHS HIPAA Security Rule establishes safeguards for electronic protected health information in the United States.

Request Elvra’s current security materials.

Book a demo to discuss the security and privacy questions that matter to your organization.

Book a demo