Trust Home / Compliance

Compliance posture

Our compliance programme is built for healthcare enterprise customers. This page shows the live status of all certifications and regulatory programmes.

HIPAA Ready

Active

Business Associate Agreements available

March 2026

Cernia FHIR completed its HIPAA readiness assessment in March 2026. BAA templates are available for all customers. Our platform enforces HIPAA technical safeguards including access controls, audit controls, integrity controls, and transmission security.

SOC 2 Type 2

In progress

Audit period Nov 2025 – Apr 2026 — report available

Audit completed May 2026

Our first SOC 2 Type 2 audit was conducted by an independent AICPA-licensed CPA firm for the period November 1, 2025 through April 30, 2026. The report covers the Trust Service Criteria: Security, Availability, and Confidentiality. Enterprise customers may request a copy under NDA.

HITRUST e1

Roadmap

Assessment beginning July 2026

Target: Q4 2026

We are targeting HITRUST e1 Certified status by Q4 2026. The HITRUST e1 assessment covers 44 requirement statements addressing foundational cybersecurity controls. Enterprise customers who require HITRUST will be notified as milestones are reached.

ONC Certified HIT

Roadmap

2015 Edition certification roadmap in progress

Target: 2027

We are evaluating relevant ONC 2015 Edition Health IT certification criteria for interoperability, including §170.315(g)(10) — Standardised API for Patient and Population Services. Certification roadmap targets 2027.

Need compliance evidence for a vendor review?

Our security team can provide questionnaire responses, audit reports, and penetration test summaries.

Request evidence