Trust · Security

Security program

A summary of the technical and organizational measures protecting the platform. This page mirrors Annex B of our Data Processing Addendum and is written to answer a security review without a call.

Last updated · August 13, 2026

Reporting a vulnerability

Email security@myorbithealth.com with reproduction steps. We acknowledge reports within two business days. We will not pursue legal action against good-faith researchers who avoid privacy violations, service degradation, and data destruction, and who give us reasonable time to remediate before disclosure. Please do not test against production patient data.

01

Architecture and data residency

Platform infrastructure and primary data stores are hosted in United States regions with major cloud providers. Protected Health Information is not stored outside the United States. Environments are logically separated, and customer data is segregated by tenant with authorization enforced at the data layer rather than only in the interface.

02

Encryption

  • In transit: TLS 1.2 or higher for all external connections, with modern cipher suites and HTTP Strict Transport Security.
  • At rest: AES-256 for databases, object storage, and backups.
  • Key management: provider-managed keys with restricted administrative access and rotation.
  • Secrets: stored in a managed secret store, never in source control, and injected at runtime.

03

Access control

Access follows least privilege and need-to-know. Workforce access requires single sign-on with multi-factor authentication. Production access is role-based, time-boxed where possible, reviewed at least quarterly, and revoked on the same business day as a role change or departure. Administrative actions are individually attributable — shared credentials are prohibited.

04

Audit logging and monitoring

Access to Protected Health Information is logged with actor, action, record, and timestamp. Logs are retained on write-limited storage for at least six years, in line with HIPAA documentation retention, and are monitored for anomalous access patterns. Partner organizations can request access reports for their own records.

05

Secure development and change management

  • Peer review required before production merge; no direct production pushes.
  • Automated dependency and secret scanning in continuous integration, with a defined remediation window by severity.
  • Static analysis and infrastructure-as-code review for privilege and exposure changes.
  • Separate development, staging, and production environments; production data is not copied into lower environments.

06

Testing and assessment

We conduct third-party penetration testing at least annually and after significant architectural change, run continuous automated vulnerability scanning, and perform an annual HIPAA Security Rule risk analysis under 45 C.F.R. § 164.308(a)(1). Executive summaries of test results and our current audit report status are available to customers and prospects under NDA.

Compliance posture

Controls are designed to satisfy the HIPAA Security Rule, SOC 2 Trust Services Criteria, and LegitScript certification requirements applicable to our pharmacy and prescribing partners. We publish audit status and evidence on request rather than claiming outcomes we cannot document here.

07

Availability and resilience

Encrypted automated backups run on a defined schedule with periodic restore testing. We maintain documented business continuity and disaster recovery plans with recovery objectives stated in the applicable order form, and we exercise them at least annually.

08

Incident response

We maintain a documented incident response plan covering detection, triage, containment, eradication, recovery, and post-incident review. On confirming a security incident affecting customer data, we notify the affected customer's designated contact without undue delay with the information reasonably available. For Protected Health Information, we report breaches to the affected Covered Entity in line with the Business Associate Agreement and the sixty-day outer limit in 45 C.F.R. § 164.410.

09

Workforce and vendors

Personnel undergo background screening where permitted by law, sign written confidentiality obligations, and complete HIPAA privacy and security training at hire and annually. Vendors that process data on our behalf are assessed before engagement and listed on our subprocessor page.

10

Contact

Security questionnaires, audit reports, and BAA requests: security@myorbithealth.com.