Cernia FHIR is built for healthcare-grade trust
Security, compliance, and privacy are first-class features — not afterthoughts. This trust center documents our posture, certifications, and commitments to customers.
Certifications
Our certification programme is designed around the requirements of healthcare enterprise customers.
HIPAA Ready
ActiveBusiness Associate Agreements available. HIPAA-ready infrastructure and processes.
2026-03-01
SOC 2 Type 2
In progressSystem and Organisation Controls audit for security, availability, and confidentiality.
Audit period: Nov 2025 – Apr 2026. Report available Q2 2026.
HITRUST e1
RoadmapHITRUST e1 Certified assessment beginning July 2026. HITRUST CSF roadmap in progress.
Target: Q4 2026
ONC Certified HIT
Roadmap2015 Edition ONC Health IT Certification Program. Roadmap for relevant criteria.
Target: 2027
Trust pillars
Four dimensions that define our approach to customer trust.
Security
End-to-end encryption, zero-trust network controls, RBAC + ABAC access policies, immutable audit trail, and real-time breach detection.
Compliance
HIPAA-ready BAA, SOC 2 Type 2 in progress, HITRUST roadmap, ONC certification roadmap, GDPR data-subject rights.
Status
Live API availability per region, component health, incident history for 90 days, and scheduled maintenance notices.
Privacy
FHIR-native consent management, 42 CFR Part 2 disclosure gating, data minimisation, retention policies, and right-to-erasure flows.