ViHATECHNICAL

Data Security and Compliance

ViHA is built to meet the most demanding patient information, clinical, and operational data security requirements, such as ISO 27001, ISO 9001, HIPAA, and PDPL. We also ensure data security compliance with every country's local requirements.

Request a Demo

Data Security and Compliance Pillars

Encryption at Rest and In Transit

AES-256 encryption for all stored patient data. TLS 1.2/1.3 for all data in transit — enforced with no fallback. Separate encryption keys per tenant, rotated automatically and managed through an enterprise-grade HSM. No plaintext PHI ever written to disk or logs.

Data Residency and Sovereignty

Data is stored exclusively in the country's local and compliant cloud. We ensure zero cross-border data transfer without explicit contractual permission. We satisfy local requirements, including EU, UK, Switzerland, KSA (SDAIA, CHI), UAE, and other countries.

Role-Based Access Control

Fine-grained RBAC with TCP scopes enforced at the API boundary on every request. Clinicians see only their own patients identifiably — cross-organizational or regulatory users see aggregated, de-identified data only. Full SSO via SAML 2.0 and OIDC. MFA enforced for all privileged roles.

Immutable Audit Trail

Every data access, modification, export, and login event written to an immutable audit log — retained for 7 years and queryable for regulatory inspection within hours. Includes field-level change tracking, session context, and IP source. Compliant with HIPAA, ISO 27001, and select local audit requirements.

Vulnerability and Penetration Testing

Annual independent penetration testing against OWASP Top 10 and healthcare-specific attack vectors. Automated SAST and dependency scanning on every CI/CD build. Critical vulnerabilities addressed within 24 hours; high within 7 days. Full disclosure to enterprise clients on request.

Multi-Tenant Isolation

Each client organization operates in a fully isolated tenant with separate data stores, encryption keys, and access scopes. Tenant boundaries enforced at the data layer — not just the application layer. No shared tables, no shared caches, no cross-tenant data leakage by design.

Certified and Compliant: ISO 27001:2022 ISO 9001 HIPAA PDPL
Certifications

Internationally Recognized, Regionally Certified

ISO 27001 ISO 9001 HIPAA Compliant SDAIA / PDPL SFDA