Security
Health Gorilla maintains an enterprise security and compliance program designed to protect clinical data, support regulatory obligations, and preserve trust across nationwide interoperability. Security controls are applied consistently across the platform and integrated into how data is accessed, exchanged, and audited.
The security program combines technical safeguards, operational controls, and independent assurance to support secure clinical data exchange at scale across all solutions and participation models.
Core Security Controls
Health Gorilla applies layered safeguards to protect clinical data throughout its lifecycle.
Key controls include:
-
Encryption in transit and at rest: Data in transit is protected using industry-standard transport encryption. Data stored by the platform is encrypted at rest using strong, industry-accepted encryption methods.
-
Tenant isolation: Each organization operates within a logically isolated tenant. Data is segregated by tenant and access across tenants is restricted through enforced isolation and access controls.
-
Role-based access control: Access follows least-privilege principles. Permissions are assigned based on role, enforced through OAuth 2.0 scopes, and reviewed on a regular basis to ensure appropriate access.
-
Audit logging: Exchange activity and key system actions are logged with request identifiers, timestamps, and contextual metadata to support auditing, compliance reviews, and investigations.
These controls apply uniformly across API access, subscription services, and supported user interfaces.
Access Control and Authentication
Authentication and authorization are central to platform security.
Health Gorilla enforces:
- OAuth 2.0–based authentication for API access
- Scope-based authorization to limit access to approved resources and actions
- Separation of credentials and access between sandbox and production environments
These measures ensure that only authorized systems and users can access clinical data, and only within approved use cases.
Certifications and Compliance
Health Gorilla maintains independent certifications and assessments that validate its security posture and alignment with federal and industry standards.
These include:
-
HIPAA: Operations and controls align with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) for safeguarding protected health information.
-
TEFCA (QHIN): As a designated Qualified Health Information Network (QHIN), Health Gorilla meets applicable security, privacy, and audit requirements under the Trusted Exchange Framework and Common Agreement (TEFCA).
-
HITRUST: Health Gorilla maintains HITRUST Common Security Framework (CSF) r2 certification, demonstrating enterprise-level security and risk management controls.
-
SOC 2 Type II: Independent audits assess controls related to security, availability, and confidentiality over an extended operating period.
These assessments are performed by third parties and reviewed regularly.
Monitoring and Incident Response
Security controls are continuously monitored to identify potential threats, vulnerabilities, or anomalous activity.
Security operations include:
- Continuous monitoring and alerting
- Defined incident response procedures aligned with healthcare and regulatory expectations
- Investigation and remediation of confirmed security incidents
- Post-incident review and corrective action tracking when required
Incident response and business continuity plans are maintained and tested to support platform resilience.
Program Governance
Security policies, standards, and controls are governed through a centralized security program.
Program governance includes:
- Regular review and update of security controls
- Ongoing risk assessment and management
- Coordination across engineering, operations, and compliance teams
- Consistent application of security standards across products and integration models
These practices help ensure that security remains effective as the platform and exchange ecosystem evolve.
Updated about 6 hours ago

