Trust Center · Purpose Health
Trust Center

Trust CenterCertified where it counts. Governed everywhere else.

Our cloud and data platforms are HITRUST r2 certified and operate inside HIPAA, ISO 27001, GxP, and PCI aligned environments. Every AI deployment is governed under NIST AI RMF. The commitments below are the same ones we put in writing.


Certifications & Frameworks

The frameworks your compliance office already audits to.

Certified

HITRUST r2

Cloud and data platforms certified against the HITRUST CSF.

Aligned

HIPAA

Privacy and Security Rule safeguards, BAA on every engagement touching PHI.

Aligned

ISO 27001

Information security management aligned to ISO/IEC 27001 controls.

Aligned

GxP

Validated environments for life sciences clients under GxP.

Aligned

PCI

Payment card handling aligned to PCI DSS where payment data is in scope.

Aligned

NIST AI RMF

Risk tiers, controls, and monitoring for every AI deployment we build or govern.

Industry Memberships
Member

CHIME Foundation

Standard membership in the College of Healthcare Information Management Executives Foundation, the partner community for health system CIOs.

Member

Epic Vendor Services

Sandbox access, API programs, and Epic support channels for the connectors and agents we build.

Accredited

Epic Connect

Accredited for Community Connect program build and extension.

Member

MEDITECH Alliance

Alliance member and MEDITECH READY for Expanse implementation, optimization, and hosting.


Data Handling

Where your data sits, and who can reach it.

Every engagement starts with a data-flow map and a signed BAA. Access follows least privilege.

Residency and hosting

Client environments run in US regions on AWS or Google Cloud. Production data stays in the client tenant unless a hosted model is contracted.

Encryption

TLS 1.2 or higher in transit, AES-256 at rest, with customer-managed keys supported where the platform allows.

Access control

Named-consultant access, MFA enforced, quarterly entitlement reviews, and revocation inside one business day of roll-off.

PHI minimization

De-identified or synthetic data for development and testing. Production PHI access is scoped to the task and logged.

AI inference

BAA-covered models with zero-retention inference. No prompt or output retained by the model provider.

Retention and return

Engagement artifacts are returned or destroyed on a documented schedule at contract close, with attestation provided.


Documentation

Available on request, under NDA.

Security reviews move faster when the artifacts arrive with the first email. Your security team can request the package before a contract exists.

Current HITRUST certification letter and scope, plus the latest third-party assessment summary.Standard BAA, data processing terms, and the security exhibit we sign with health systems and payers.Completed security questionnaires, refreshed annually, with named owners for follow-up questions.

Accessibility

Built to WCAG 2.2 AA.

This site is designed for keyboard navigation, screen readers, and reduced-motion preferences: skip links, visible focus states, minimum 4.5:1 text contrast, and one heading hierarchy per page. Report an accessibility issue to info@purposehealth.ai.

Send us your security questionnaire.

We return it with the artifacts attached.

Contact Us →