Security & Trust Center
At Grelin Health, protecting the security, privacy, and confidentiality of healthcare and customer information is fundamental to how we operate.
Our security and compliance program is designed to protect the information entrusted to us while supporting the regulatory and contractual requirements of the healthcare organizations we serve.
Grelin maintains a security and privacy program aligned with HIPAA, SOC 2 Trust Services Criteria, and applicable data protection requirements.
Last reviewed: September 2026
Security & Compliance at a Glance
High-level overview of our regulatory alignment, technical safeguards, and continuous compliance assurance program.
Grelin Health operates as a HIPAA Business Associate and maintains administrative, technical, and physical safeguards designed to protect Protected Health Information (PHI).
Our HIPAA program includes security risk management, workforce training, access controls, encryption, audit controls, incident response, and Business Associate Agreements (BAAs), as applicable.
Grelin's security controls are designed and implemented in alignment with the SOC 2 Trust Services Criteria. Our control environment is continuously monitored as we progress toward our SOC 2 Type II examination.
The SOC 2 Type II report will be made available to customers and qualified prospects under appropriate confidentiality terms once issued.
Grelin Health operates as a HIPAA Business Associate and maintains administrative, technical, and physical safeguards designed to protect Protected Health Information (PHI).
Our HIPAA program includes security risk management, workforce training, access controls, encryption, audit controls, incident response, and Business Associate Agreements (BAAs), as applicable.
Grelin uses industry-standard encryption to protect data in transit and at rest.
Detailed technical information regarding encryption configurations and key management is available to qualified customers and prospects through our security review process.
Grelin maintains an ongoing vulnerability management and security testing program. Security findings are identified, prioritized based on risk, remediated within defined timelines, and tracked through resolution.
Independent vulnerability assessment and penetration testing are also incorporated into our security assurance program.
Grelin executes Business Associate Agreements with applicable covered entities before receiving or processing PHI on their behalf.
Our standard BAA is available for review during the contracting and procurement process.
How We Protect Your Information
Security Controls & Safeguards
Grelin's security program incorporates administrative, technical, and physical safeguards designed to protect customer information throughout its lifecycle.
Access Control
Access to systems and information is restricted based on business need and the principle of least privilege. Access is assigned according to defined roles and is reviewed and removed as appropriate.
Identity & Multi-Factor Authentication
Grelin uses identity and access controls, including multi-factor authentication, to help protect access to corporate systems and systems that process or store sensitive information.
Encryption
Sensitive information is protected using encryption in transit and at rest.
Endpoint Security
Workforce devices are subject to security requirements designed to protect against unauthorized access, malware, data loss, and other security threats.
Vulnerability Management
Grelin maintains a vulnerability management process to identify, assess, prioritize, remediate, and track security vulnerabilities.
Secure Development
Security considerations are incorporated into the software development and change management lifecycle, including appropriate review and approval processes.
Logging & Monitoring
Security-relevant activities are logged and monitored to support detection, investigation, and response to potential security events.
Security Awareness
Employees and relevant workforce members receive security, privacy, and HIPAA training as applicable, with training completion tracked.
Risk Management
Security and privacy risks are identified, assessed, assigned to appropriate owners, and addressed through documented risk treatment processes.
Vendor Risk Management
Third-party vendors and subprocessors are evaluated based on their security, privacy, data access, and business risk before onboarding and are subject to appropriate contractual and ongoing oversight requirements.
Data Protection & Privacy
Responsible Use of Customer Data
Grelin processes customer information only for legitimate business purposes and in accordance with applicable contractual, legal, and regulatory requirements.
Our approach to data protection includes:
Purpose Limitation
Customer information is used only for permitted purposes associated with the services provided by Grelin.
Data Minimization
Grelin seeks to limit the collection and use of information to what is necessary for the intended business purpose.
Access Restriction
Access to customer information is limited to authorized personnel with an appropriate business need.
Retention & Deletion
Information is retained, returned, or deleted in accordance with applicable contractual requirements, customer instructions, and legal obligations.
No Sale of Customer Data
Grelin does not sell customer data.
Privacy by Design
Security and privacy considerations are incorporated into relevant technology, workflow, and process decisions.
Learn More About Our Privacy Practices
For more information about how Grelin Health collects, uses, protects, retains, and manages personal information, please review our Data Privacy Notice.
HIPAA & Healthcare Data Protection
Protecting Healthcare Information
Healthcare organizations trust Grelin with sensitive information, and protecting that information is central to our security program. Grelin operates as a HIPAA Business Associate and maintains safeguards addressing the HIPAA Security, Privacy, and Breach Notification requirements applicable to our role.
Administrative Safeguards
- Security and privacy policies and procedures
- Security risk assessments and risk management
- Workforce security requirements
- HIPAA and security awareness training
- Incident response procedures
- Contingency and continuity planning
HIPAA Privacy, Security & Breach Rules
Technical Safeguards
- Unique user identification
- Role-based access controls
- Multi-factor authentication
- Encryption in transit and at rest
- Audit logging
- Access monitoring
- Session and authentication controls
Encryption, Role-Based Access & Audit Logs
Physical Safeguards
SOC 2 Type II Program
Grelin is progressing toward a SOC 2 Type II examination.
Our control environment is designed around the SOC 2 Trust Services Criteria, with controls implemented across people, processes, and technology and monitored on an ongoing basis.
As our SOC 2 program progresses, we will continue to provide transparency regarding our current status.
Once the SOC 2 Type II report is issued, it will be made available to customers and qualified prospects under appropriate confidentiality terms.
Request SOC 2 InformationAligned Trust Services Criteria
Continuous control monitoring across people, process & technology.
Business Associate Agreement &
Data Processing Agreement
Contracts for Data Protection
Grelin supports appropriate contractual safeguards for the processing of healthcare and personal information.
Business Associate Agreement (BAA)
Healthcare PHI Safeguards
Where applicable, Grelin enters into a Business Associate Agreement with healthcare customers before receiving or processing PHI.
Our standard BAA is available during the procurement and contracting process.
Data Processing Agreement (DPA)
Privacy Framework & Responsibilities
Where applicable, Grelin enters into Data Processing Agreements to establish the requirements for processing personal data and the responsibilities of each party.
Our standard DPA is available during the procurement and contracting process.
Security Testing & Assurance
Continuous Security Assurance
Security testing is an ongoing component of Grelin's security program.

Vulnerability identification and assessment

Risk-based vulnerability remediation

Security monitoring

Secure development and change management practices

Independent vulnerability assessment and penetration testing

Tracking and verification of remediation activities
Incident Response
Responding to Security Events
Grelin maintains a documented incident response process designed to identify, assess, contain, remediate, and recover from security incidents.
Detection and reporting
Phase 01
Investigation and assessment
Phase 02
Containment
Phase 03
Notification where required
Phase 04
Remediation and recovery
Phase 05
Post-incident review
Phase 06
Vendor & Subprocessor Security
Managing Third-Party Risk
Grelin recognizes that third-party providers are an important part of the overall security environment.
Workforce Security
Security Starts With Our People
Grelin maintains workforce security requirements designed to ensure that employees and contractors understand their responsibilities for protecting company and customer information.

Confidentiality and data protection obligations

Security and privacy training

HIPAA training where applicable

Acceptable use requirements

Secure onboarding and offboarding

Appropriate access provisioning and removal

Security responsibilities throughout the employment lifecycle
Data Location & Access
Where Data Is Stored and Accessed
Grelin understands that customers need transparency regarding where their information is hosted and where authorized personnel may access it.
During the security review process, Grelin provides appropriate information regarding:
Security Documentation Request
Request Our Security & Compliance Package
Security and compliance documentation is available to customers and qualified prospects as part of our security review process.
- 1
Submit your request
Tell us which documents your security, privacy, or procurement review needs.
- 2
Verified & triaged
Our Compliance & Security team reviews requests, typically within 1 business day.
- 3
Shared under NDA
Qualified customers and prospects receive the package under appropriate confidentiality terms.
Available Security Package Items
Select documents relevant to your review
Depending on your requirements, the package may include:
Provisioned to qualified customers under standard confidentiality terms.
Documents & Reports
Review public privacy notices and request compliance, legal, and security documentation for security assessments and vendor onboarding.
Data Privacy Notice
Outlines our personal data processing practices, rights, and regulatory protections.
Privacy Policy
Detailed overview of information handling, privacy rights, and corporate safeguards.
Terms of Use
Governing terms and operational guidelines for using Grelin Health platforms.
Business Associate Agreement (BAA)
Standard HIPAA BAA ready for execution with covered entities prior to receiving PHI.
Data Processing Agreement (DPA)
Contractual framework establishing terms for processing personal data under privacy laws.
Subprocessor Information
List of third-party infrastructure and service partners evaluated under vendor risk management.
Security & Compliance Package
Complete security overview, questionnaire responses, HIPAA mappings, and SOC 2 materials.
Frequently Asked Questions
Official responses to common compliance, HIPAA, SOC 2, and data protection questions.
Yes. Grelin Health operates as a HIPAA Business Associate and maintains administrative, technical, and physical safeguards designed to protect PHI. Our HIPAA program includes security risk management, access controls, encryption, workforce training, incident response, and appropriate contractual safeguards.
Yes. Grelin enters into Business Associate Agreements with applicable covered entity customers before receiving or processing PHI.
HIPAA compliance is not established through a government-issued certification. Instead, Grelin provides documentation of its HIPAA program, including applicable policies, controls, risk management documentation, and supporting evidence through our security review process.
Grelin is currently progressing toward its SOC 2 Type II examination. Our controls are designed and implemented in alignment with the SOC 2 Trust Services Criteria and are continuously monitored. The final Type II report will be made available once issued.
Grelin protects customer data through a combination of administrative, technical, and physical safeguards, including access controls, multi-factor authentication, encryption, logging and monitoring, vulnerability management, workforce training, and vendor risk management.
Yes. Grelin enters into Data Processing Agreements where applicable based on the nature of the processing and applicable privacy requirements.
Grelin evaluates relevant third-party providers before onboarding and applies appropriate security, privacy, contractual, and ongoing monitoring requirements. Subprocessor information is available to customers and qualified prospects upon request.
You can use the Request Security Package form on this page. Our Compliance & Security team will work with your organization to provide the appropriate documentation for your security, privacy, legal, or procurement review.
Security & Compliance Inquiries
For security-related questions or to report a Security and Privacy concern, contact the Grelin Compliance Team.
Official Security & Compliance Inbox
compliance@grelinhealth.com
Inquiries regarding security assessments, questionnaires, BAAs, and privacy requests are typically triaged within 1 business day.