Defense-in-depth security model — independently audited, continuously monitored, mapped to HIPAA, SOC 2 Type II, HITRUST CSF r2, and the ONC Cures Update. Every audit log exportable. Every sub-processor public. Every breach disclosure baked into the contract before you sign.
BAA included on every plan. Annual third-party assessment.
Audited annually by Schellman. Report on request.
2015 Edition Cures Update. Full criteria list public.
r2 certified. Mapped to HIPAA, NIST, ISO 27001.
AES-256 at rest, TLS 1.3 in transit, field-level envelope encryption for the most sensitive data.
Zero-trust by default. Every request authenticated, every action logged, every role minimized.
Multi-region active-active on AWS. Redundancy at every layer, recovery measured in minutes.
Background-checked staff, principle-of-least-privilege, public security disclosure program.
Your data is never used to train models without explicit, written, opt-in consent.
Independently audited and continuously monitored against the standards that matter.
Reviewing Focus for your compliance team? We make it easy. Sign an NDA and you'll have access to our SOC 2 report, penetration test summaries, sub-processor list, and architecture diagrams within an hour.
Email security@focusehr.com — a real human on our security team will respond within one business day.