How VectorCare Handles SOC 2 and HIPAA Compliance

Last updated: June 9, 2026

Article Information

Who is this for: Customers, prospects, and procurement or security teams evaluating VectorCare's security posture

Time to complete: ~5 minutes to read

Prerequisites: None

Summary

VectorCare maintains SOC 2 Type II and operates under HIPAA as a business associate, and we run both programs in-house rather than leaning on a hosting provider's certifications. This article covers how we own our compliance program, the tools we use to run it, how our approach differs from competitors who outsource theirs, and where to find our security documentation.

Security and compliance aren't a checkbox at VectorCare. They're built into how we run the company. This article explains how we manage SOC 2 and HIPAA in-house, the tools we use, and how our approach differs from vendors who outsource their compliance posture to a hosting platform.

We own our compliance program

VectorCare's SOC 2 and HIPAA programs are run in-house by our team. We don't delegate them to a hosting vendor's certification. That means we directly own:

  • The administrative and organizational safeguards HIPAA requires, including security risk assessments, workforce training, policies and procedures, incident response, designated Security and Privacy Officers, and sanction policies.

  • Application-layer security, including how PHI flows through our product, how we handle secrets, how we validate inputs, and how we manage application dependencies.

  • Access management decisions, including who gets access to what, periodic access reviews, and offboarding.

  • Third-party vendor management and BAAs with every subprocessor that touches PHI.

  • Data classification and PHI handling decisions across the platform.

These are the controls that determine whether a company is actually secure. No hosting provider can do them for you.

The tools we use

We run our compliance program on best-in-class tooling rather than building it from scratch or relying on a single vendor to package everything.

Drata continuously monitors our controls across SOC 2 and HIPAA. Evidence collection is automated, drift is detected in real time, and our auditor works directly from the Drata workspace. Our controls are operating between audits, not just at audit time.

We pair Drata with the rest of our security stack: an identity provider with enforced SSO and MFA, endpoint management, vulnerability scanning, secrets management, encryption in transit and at rest, audit logging, and a documented incident response process. Each tool was selected because it's the right tool for the job, not because it came bundled.

How we're different from competitors

Many smaller vendors in our space rely on a Platform-as-a-Service provider like Aptible for HIPAA-compliant hosting, and then point to that vendor's SOC 2 as a proxy for their own security posture. Aptible is a reputable provider and we have no issue with the platform itself. Customers should understand what that arrangement covers and what it doesn't.

Aptible publishes a clear breakdown of the shared responsibility model at aptible.com/secured-by-aptible. Their infrastructure controls cover encryption, network protection, intrusion detection, audit logging, and similar platform-layer concerns. The same page is explicit that the following remain the customer's responsibility:

  • Application security

  • Data classification and PHI handling decisions

  • Organizational and administrative safeguards, including HIPAA risk assessments, workforce training, policies, Security Officer designation, and contingency planning

  • Third-party vendor management

  • Access management decisions

These are exactly the controls a SOC 2 audit examines for any healthcare SaaS company. When a vendor leans on a PaaS provider's certification to answer security questionnaires, they're answering for the infrastructure layer only, not for the application, the organizational program, or the way their team operates day to day.

At VectorCare, we build and audit those controls ourselves. Our SOC 2 covers VectorCare's application and Organization, not a hosting provider's data centers.

Where to find our security documentation

Our security and compliance information is published at security.vectorcare.com. There you can:

  • View our current SOC 2 and HIPAA status

  • Review our subprocessor list and security controls

  • Request our SOC 2 Type II report, HIPAA assessment, penetration test summary, and other documentation under NDA

If you have specific questions that aren't answered there, your account team can route them to our security team directly.

Tips

  • If you're filling in a security questionnaire about VectorCare, check security.vectorcare.com first. Common questions are answered and supporting documents are downloadable under NDA. Faster than waiting for our security team to respond directly.

  • Security teams sometimes ask whether our SOC 2 covers Aptible. It doesn't. Our SOC 2 covers VectorCare's application and Organization. Aptible's SOC 2 is theirs.

  • For HIPAA, our role is business associate and your Organization is the covered entity. A BAA is signed as part of customer onboarding.

Permissions Required

None. This article is informational and doesn't describe in-product permissions.

Next Article

📄 VectorCare's Accessibility Statement