HIPAA Compliant

Security & Trust Center

At Grelin Health, protecting the security, privacy, and confidentiality of healthcare and customer information is fundamental to how we operate.

Our security and compliance program is designed to protect the information entrusted to us while supporting the regulatory and contractual requirements of the healthcare organizations we serve.

Grelin maintains a security and privacy program aligned with HIPAA, SOC 2 Trust Services Criteria, and applicable data protection requirements.

Last reviewed: September 2026

Security & Compliance at a Glance

High-level overview of our regulatory alignment, technical safeguards, and continuous compliance assurance program.

HIPAAHIPAA Compliant

Grelin Health operates as a HIPAA Business Associate and maintains administrative, technical, and physical safeguards designed to protect Protected Health Information (PHI).

Our HIPAA program includes security risk management, workforce training, access controls, encryption, audit controls, incident response, and Business Associate Agreements (BAAs), as applicable.

Documentation available upon request.Request
SOC 2 TYPE IISOC 2 Type II – In Progress

Grelin's security controls are designed and implemented in alignment with the SOC 2 Trust Services Criteria. Our control environment is continuously monitored as we progress toward our SOC 2 Type II examination.

The SOC 2 Type II report will be made available to customers and qualified prospects under appropriate confidentiality terms once issued.

Current program information available upon request.Request
DATA PRIVACYPrivacy & Data Protection Program

Grelin Health operates as a HIPAA Business Associate and maintains administrative, technical, and physical safeguards designed to protect Protected Health Information (PHI).

Our HIPAA program includes security risk management, workforce training, access controls, encryption, audit controls, incident response, and Business Associate Agreements (BAAs), as applicable.

Privacy documentation available upon request.Request
ENCRYPTIONData Encrypted in Transit and at Rest

Grelin uses industry-standard encryption to protect data in transit and at rest.

Detailed technical information regarding encryption configurations and key management is available to qualified customers and prospects through our security review process.

Available to qualified customers upon review.Request
SECURITY TESTINGContinuous Security Monitoring & Independent Testing

Grelin maintains an ongoing vulnerability management and security testing program. Security findings are identified, prioritized based on risk, remediated within defined timelines, and tracked through resolution.

Independent vulnerability assessment and penetration testing are also incorporated into our security assurance program.

Security testing documentation is available to qualified customers and prospects upon request.Request
BUSINESS ASSOCIATE AGREEMENTSBAAs Available

Grelin executes Business Associate Agreements with applicable covered entities before receiving or processing PHI on their behalf.

Our standard BAA is available for review during the contracting and procurement process.

Standard BAA executed prior to PHI ingestion.Request

How We Protect Your Information

Security Controls & Safeguards

Grelin's security program incorporates administrative, technical, and physical safeguards designed to protect customer information throughout its lifecycle.

Access Control

EnforcedTechnical

Access to systems and information is restricted based on business need and the principle of least privilege. Access is assigned according to defined roles and is reviewed and removed as appropriate.

Identity & Multi-Factor Authentication

EnforcedTechnical

Grelin uses identity and access controls, including multi-factor authentication, to help protect access to corporate systems and systems that process or store sensitive information.

Encryption

EnforcedTechnical

Sensitive information is protected using encryption in transit and at rest.

Endpoint Security

EnforcedOperational

Workforce devices are subject to security requirements designed to protect against unauthorized access, malware, data loss, and other security threats.

Vulnerability Management

EnforcedOperational

Grelin maintains a vulnerability management process to identify, assess, prioritize, remediate, and track security vulnerabilities.

Secure Development

EnforcedOperational

Security considerations are incorporated into the software development and change management lifecycle, including appropriate review and approval processes.

Logging & Monitoring

EnforcedTechnical

Security-relevant activities are logged and monitored to support detection, investigation, and response to potential security events.

Security Awareness

EnforcedAdministrative

Employees and relevant workforce members receive security, privacy, and HIPAA training as applicable, with training completion tracked.

Risk Management

EnforcedAdministrative

Security and privacy risks are identified, assessed, assigned to appropriate owners, and addressed through documented risk treatment processes.

Vendor Risk Management

EnforcedAdministrative

Third-party vendors and subprocessors are evaluated based on their security, privacy, data access, and business risk before onboarding and are subject to appropriate contractual and ongoing oversight requirements.

Data Protection & Privacy

Responsible Use of Customer Data

Grelin processes customer information only for legitimate business purposes and in accordance with applicable contractual, legal, and regulatory requirements.

Our approach to data protection includes:

1

Purpose Limitation

Customer information is used only for permitted purposes associated with the services provided by Grelin.

2

Data Minimization

Grelin seeks to limit the collection and use of information to what is necessary for the intended business purpose.

3

Access Restriction

Access to customer information is limited to authorized personnel with an appropriate business need.

4

Retention & Deletion

Information is retained, returned, or deleted in accordance with applicable contractual requirements, customer instructions, and legal obligations.

5

No Sale of Customer Data

Grelin does not sell customer data.

6

Privacy by Design

Security and privacy considerations are incorporated into relevant technology, workflow, and process decisions.

Learn More About Our Privacy Practices

For more information about how Grelin Health collects, uses, protects, retains, and manages personal information, please review our Data Privacy Notice.

View Data Privacy Notice

HIPAA & Healthcare Data Protection

Protecting Healthcare Information

Healthcare organizations trust Grelin with sensitive information, and protecting that information is central to our security program. Grelin operates as a HIPAA Business Associate and maintains safeguards addressing the HIPAA Security, Privacy, and Breach Notification requirements applicable to our role.

Administrative Safeguards

  • Security and privacy policies and procedures
  • Security risk assessments and risk management
  • Workforce security requirements
  • HIPAA and security awareness training
  • Incident response procedures
  • Contingency and continuity planning

HIPAA Privacy, Security & Breach Rules

Technical Safeguards

  • Unique user identification
  • Role-based access controls
  • Multi-factor authentication
  • Encryption in transit and at rest
  • Audit logging
  • Access monitoring
  • Session and authentication controls

Encryption, Role-Based Access & Audit Logs

Physical Safeguards

Our physical safeguards include appropriate controls for workstations, devices, media, and physical access to environments used to support Grelin's operations.

SOC 2 Type II Program

Current Status: SOC 2 Type II Examination in Progress

Grelin is progressing toward a SOC 2 Type II examination.

Our control environment is designed around the SOC 2 Trust Services Criteria, with controls implemented across people, processes, and technology and monitored on an ongoing basis.

As our SOC 2 program progresses, we will continue to provide transparency regarding our current status.

Once the SOC 2 Type II report is issued, it will be made available to customers and qualified prospects under appropriate confidentiality terms.

Request SOC 2 Information

Aligned Trust Services Criteria

SecurityAligned
AvailabilityAligned
Processing IntegrityAligned
ConfidentialityAligned
PrivacyAligned

Continuous control monitoring across people, process & technology.

Business Associate Agreement & Data Processing Agreement

Contracts for Data Protection

Grelin supports appropriate contractual safeguards for the processing of healthcare and personal information.

Business Associate Agreement (BAA)

Healthcare PHI Safeguards

Where applicable, Grelin enters into a Business Associate Agreement with healthcare customers before receiving or processing PHI.

Our standard BAA is available during the procurement and contracting process.

Data Processing Agreement (DPA)

Privacy Framework & Responsibilities

Where applicable, Grelin enters into Data Processing Agreements to establish the requirements for processing personal data and the responsibilities of each party.

Our standard DPA is available during the procurement and contracting process.

Security Testing & Assurance

Continuous Security Assurance

Security testing is an ongoing component of Grelin's security program.

Vulnerability identification and assessment

Vulnerability identification and assessment

Risk-based vulnerability remediation

Risk-based vulnerability remediation

Security monitoring

Security monitoring

Secure development and change management practices

Secure development and change management practices

Independent vulnerability assessment and penetration testing

Independent vulnerability assessment and penetration testing

Tracking and verification of remediation activities

Tracking and verification of remediation activities

Incident Response

Responding to Security Events

Grelin maintains a documented incident response process designed to identify, assess, contain, remediate, and recover from security incidents.

1

Detection and reporting

Phase 01

2

Investigation and assessment

Phase 02

3

Containment

Phase 03

4

Notification where required

Phase 04

5

Remediation and recovery

Phase 05

6

Post-incident review

Phase 06

Vendor & Subprocessor Security

Managing Third-Party Risk

Grelin recognizes that third-party providers are an important part of the overall security environment.

Security and privacy due diligence before onboarding
Risk-based vendor assessment
Review of relevant security and compliance documentation
Contractual security and confidentiality requirements
BAA/DPA requirements where applicable
Ongoing vendor monitoring and reassessment
Appropriate offboarding and data-handling requirements

Workforce Security

Security Starts With Our People

Grelin maintains workforce security requirements designed to ensure that employees and contractors understand their responsibilities for protecting company and customer information.

Confidentiality and data protection obligations

Confidentiality and data protection obligations

Security and privacy training

Security and privacy training

HIPAA training where applicable

HIPAA training where applicable

Acceptable use requirements

Acceptable use requirements

Secure onboarding and offboarding

Secure onboarding and offboarding

Appropriate access provisioning and removal

Appropriate access provisioning and removal

Security responsibilities throughout the employment lifecycle

Security responsibilities throughout the employment lifecycle

Data Location & Access

Where Data Is Stored and Accessed

Grelin understands that customers need transparency regarding where their information is hosted and where authorized personnel may access it.

During the security review process, Grelin provides appropriate information regarding:

01Production hosting environment
02Data residency
03Delivery and operational locations
04Authorized personnel access
05Applicable security and privacy safeguards

Security Documentation Request

Request Our Security & Compliance Package

Security and compliance documentation is available to customers and qualified prospects as part of our security review process.

  1. 1

    Submit your request

    Tell us which documents your security, privacy, or procurement review needs.

  2. 2

    Verified & triaged

    Our Compliance & Security team reviews requests, typically within 1 business day.

  3. 3

    Shared under NDA

    Qualified customers and prospects receive the package under appropriate confidentiality terms.

Available Security Package Items

Select documents relevant to your review

Depending on your requirements, the package may include:

Provisioned to qualified customers under standard confidentiality terms.

Confidentiality Notice

Please do not submit Protected Health Information (PHI) or other sensitive patient information through this form.

Direct inquiries may also be emailed to compliance@grelinhealth.com

Documents & Reports

Review public privacy notices and request compliance, legal, and security documentation for security assessments and vendor onboarding.

Web PagePublic

Data Privacy Notice

Outlines our personal data processing practices, rights, and regulatory protections.

No NDA requiredView Notice
Web PagePublic

Privacy Policy

Detailed overview of information handling, privacy rights, and corporate safeguards.

No NDA requiredRead Policy
Web PagePublic

Terms of Use

Governing terms and operational guidelines for using Grelin Health platforms.

No NDA requiredView Terms
Legal Document (PDF)Request Access

Business Associate Agreement (BAA)

Standard HIPAA BAA ready for execution with covered entities prior to receiving PHI.

Requires verificationRequest BAA
Legal Document (PDF)Request Access

Data Processing Agreement (DPA)

Contractual framework establishing terms for processing personal data under privacy laws.

Requires verificationRequest DPA
Confidential OverviewUnder NDA

Subprocessor Information

List of third-party infrastructure and service partners evaluated under vendor risk management.

Requires verificationRequest List
Comprehensive BundleUnder NDA

Security & Compliance Package

Complete security overview, questionnaire responses, HIPAA mappings, and SOC 2 materials.

Requires verificationRequest Package
FAQ

Frequently Asked Questions

Official responses to common compliance, HIPAA, SOC 2, and data protection questions.

Yes. Grelin Health operates as a HIPAA Business Associate and maintains administrative, technical, and physical safeguards designed to protect PHI. Our HIPAA program includes security risk management, access controls, encryption, workforce training, incident response, and appropriate contractual safeguards.

Yes. Grelin enters into Business Associate Agreements with applicable covered entity customers before receiving or processing PHI.

HIPAA compliance is not established through a government-issued certification. Instead, Grelin provides documentation of its HIPAA program, including applicable policies, controls, risk management documentation, and supporting evidence through our security review process.

Grelin is currently progressing toward its SOC 2 Type II examination. Our controls are designed and implemented in alignment with the SOC 2 Trust Services Criteria and are continuously monitored. The final Type II report will be made available once issued.

Grelin protects customer data through a combination of administrative, technical, and physical safeguards, including access controls, multi-factor authentication, encryption, logging and monitoring, vulnerability management, workforce training, and vendor risk management.

Yes. Grelin enters into Data Processing Agreements where applicable based on the nature of the processing and applicable privacy requirements.

Grelin evaluates relevant third-party providers before onboarding and applies appropriate security, privacy, contractual, and ongoing monitoring requirements. Subprocessor information is available to customers and qualified prospects upon request.

You can use the Request Security Package form on this page. Our Compliance & Security team will work with your organization to provide the appropriate documentation for your security, privacy, legal, or procurement review.

Security & Compliance Inquiries

For security-related questions or to report a Security and Privacy concern, contact the Grelin Compliance Team.

Official Security & Compliance Inbox

compliance@grelinhealth.com

Inquiries regarding security assessments, questionnaires, BAAs, and privacy requests are typically triaged within 1 business day.