TECHNICALViHA is built to meet the most demanding patient information, clinical, and operational data security requirements, such as ISO 27001, ISO 9001, HIPAA, and PDPL. We also ensure data security compliance with every country's local requirements.
Request a DemoAES-256 encryption for all stored patient data. TLS 1.2/1.3 for all data in transit — enforced with no fallback. Separate encryption keys per tenant, rotated automatically and managed through an enterprise-grade HSM. No plaintext PHI ever written to disk or logs.
Data is stored exclusively in the country's local and compliant cloud. We ensure zero cross-border data transfer without explicit contractual permission. We satisfy local requirements, including EU, UK, Switzerland, KSA (SDAIA, CHI), UAE, and other countries.
Fine-grained RBAC with TCP scopes enforced at the API boundary on every request. Clinicians see only their own patients identifiably — cross-organizational or regulatory users see aggregated, de-identified data only. Full SSO via SAML 2.0 and OIDC. MFA enforced for all privileged roles.
Every data access, modification, export, and login event written to an immutable audit log — retained for 7 years and queryable for regulatory inspection within hours. Includes field-level change tracking, session context, and IP source. Compliant with HIPAA, ISO 27001, and select local audit requirements.
Annual independent penetration testing against OWASP Top 10 and healthcare-specific attack vectors. Automated SAST and dependency scanning on every CI/CD build. Critical vulnerabilities addressed within 24 hours; high within 7 days. Full disclosure to enterprise clients on request.
Each client organization operates in a fully isolated tenant with separate data stores, encryption keys, and access scopes. Tenant boundaries enforced at the data layer — not just the application layer. No shared tables, no shared caches, no cross-tenant data leakage by design.