Healthcare-grade compliance at the core
Vocca is built to protect patient data: HIPAA and GDPR by design, encryption in transit and at rest, on SOC 2, ISO 27001 and HDS certified infrastructure.
HIPAA
Complies with U.S. health data protection requirements. BAA available upon request.
GDPR
Built to meet GDPR requirements, with data for European customers hosted in the EU.

How we protect patient data
Security isn't a feature we added later. Vocca was built to handle patient data securely from day one.
Encrypted in transit and at rest
All patient data is encrypted in transit and at rest.
Data hosted where your patients are
Vocca runs separate production environments: data is hosted in the United States for American customers and in the EU for European ones.
Strictly controlled access
Access to patient data is strictly controlled and limited to what is needed to handle the conversation.
Certified infrastructure
Our infrastructure partners hold the certifications healthcare requires, in the United States and in Europe.
SOC 2
Our infrastructure partners are SOC 2 certified.
ISO 27001
Our infrastructure partners are ISO 27001 certified.
HDS
Our infrastructure partners are HDS certified, the French standard for hosting health data.
Security questions
Anything else? Our team will answer directly.
In the United States for American customers and in the EU for European ones. Vocca runs separate production environments on each side of the Atlantic.
Yes. Vocca complies with U.S. health data protection requirements, and a Business Associate Agreement (BAA) is available upon request.
SOC 2, ISO 27001 and HDS (Hébergeur de Données de Santé, the French certification for hosting health data).

Questions about security?
Our team is happy to walk your IT or compliance lead through how Vocca handles patient data.