Security and compliance, built in from day one
Vantly Health was built by healthcare technology veterans. In long-term care, compliance isn't optional. It's the foundation.
Looking for the subprocessor list, BAA request, or vulnerability-disclosure policy? Visit the Trust Center.
Independently verified, every year
Our security posture is validated not just by our own engineers, but by independent auditors who assess our controls against the most rigorous healthcare standards.
HIPAA-Aligned
Built to the Health Insurance Portability and Accountability Act. PHI is encrypted in transit (TLS 1.3) and at rest (AES-256); application-layer field encryption of resident demographics is rolling out. Access is role-based with strict per-facility isolation and audit logging.
- PHI encrypted in transit (TLS 1.3) + at rest (AES-256)
- Application-layer field encryption rolling out
- Audit logging on PHI changes (read logging rolling out)
- Self-serve BAA, countersigned within one business day
SOC 2 readiness in progress
Our SOC 2 readiness program is in progress. We do not currently represent that a completed Type I or Type II attestation is available. Contact us for current evidence and scope.
- Readiness work in progress
- Current evidence available on request
256-bit TLS Encryption
All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed using FIPS 140-2 compliant key management with automatic rotation.
- AES-256 encryption at rest
- TLS 1.3 in transit
- FIPS 140-2 key management
- Automatic key rotation
High availability
Multi-region redundancy with automatic failover ensures your facility stays operational around the clock. Real-time infrastructure status is available publicly at status.vantlyhealth.com.
- Multi-region redundancy
- Automatic failover
- Real-time status monitoring
- status.vantlyhealth.com
Every layer of security, covered
From access controls to data recovery, Vantly Health provides defence-in-depth across every aspect of your facility's data.
Your data stays where you need it
By default, all Vantly Health data is stored in US-based AWS data centers (us-east-1 and us-west-2) with full geographic redundancy. Enterprise customers can elect EU-based data residency, so no data ever leaves your selected region.
- US data centres: AWS us-east-1 + us-west-2
- EU data residency available for Enterprise customers
- No cross-region data transfer without explicit consent
- Region selection locked at account creation
We sign Business Associate Agreements
Every Vantly Health customer receives a fully executed Business Associate Agreement (BAA) at no additional cost. The BAA is delivered digitally and countersigned by our legal team within one business day of your account activation. Enterprise customers can request a custom BAA with negotiated terms.
Have questions about our security posture?
Our security team is available to walk your compliance officer, CISO, or IT leadership through our controls, audit reports, and penetration test results.
Request a security review