Security & Compliance

Healthcare-grade compliance at the core

Vocca is built to protect patient data: HIPAA and GDPR by design, encryption in transit and at rest, on SOC 2, ISO 27001 and HDS certified infrastructure.

HIPAA

Complies with U.S. health data protection requirements. BAA available upon request.

GDPR

Built to meet GDPR requirements, with data for European customers hosted in the EU.

How we protect patient data

Security isn't a feature we added later. Vocca was built to handle patient data securely from day one.

Encrypted in transit and at rest

All patient data is encrypted in transit and at rest.

Data hosted where your patients are

Vocca runs separate production environments: data is hosted in the United States for American customers and in the EU for European ones.

Strictly controlled access

Access to patient data is strictly controlled and limited to what is needed to handle the conversation.

Certified infrastructure

Our infrastructure partners hold the certifications healthcare requires, in the United States and in Europe.

SOC 2

Our infrastructure partners are SOC 2 certified.

ISO 27001

Our infrastructure partners are ISO 27001 certified.

HDS

Our infrastructure partners are HDS certified, the French standard for hosting health data.

Security questions

Anything else? Our team will answer directly.

In the United States for American customers and in the EU for European ones. Vocca runs separate production environments on each side of the Atlantic.

Yes. Vocca complies with U.S. health data protection requirements, and a Business Associate Agreement (BAA) is available upon request.

SOC 2, ISO 27001 and HDS (Hébergeur de Données de Santé, the French certification for hosting health data).

Questions about security?

Our team is happy to walk your IT or compliance lead through how Vocca handles patient data.