Start Your 7-Day Free Trial
Security Controls Aligned with HIPAA Standards

Privacy & Security.
Documented. Verified. Built in.

Bright Health Platform is built with health data privacy as a first principle. While Bright Health Platform operates as a direct-to-patient advocacy platform - not as a Business Associate of a Covered Entity under HIPAA - we've voluntarily implemented security controls aligned with HIPAA best practices and the FTC Health Breach Notification Rule. This page documents those controls.

Full HIPAA Compliance Available

Bright Health Platform's security controls are aligned with HIPAA standards for all subscribers. For organizations managing 10 or more patients, we offer a formal HIPAA compliance program including a signed Business Associate Agreement, documented risk assessments, and dedicated compliance support. Contact us to learn more.

45 CFR §164.308

Administrative Safeguards

We implement the policies, procedures, and training programs that govern how ePHI is managed, accessed, and protected across our organization.

6 requirements addressed
45 CFR §164.310

Physical Safeguards

We control physical access to every system and facility that stores or processes ePHI, including data center security and device management.

3 requirements addressed
45 CFR §164.312

Technical Safeguards

We enforce technology-based controls - including encryption, access control, audit logging, and transmission security - that protect ePHI at every layer of our system.

5 requirements addressed
45 CFR §164.308

Administrative Safeguards

Here's how we handle the policies, procedures, and training that govern ePHI management across our organization.

45 CFR §164.310

Physical Safeguards

Here's how we secure the physical infrastructure that stores and processes ePHI.

45 CFR §164.312

Technical Safeguards

Here's how we use technology to protect ePHI at every layer of our system.

Technical Architecture

Security by design.

We designed every layer of Bright Health Platform's architecture with security and compliance as first principles.

Frontend Layer

  • We build with React and TypeScript for type-safe, predictable code
  • We enforce HTTPS with HTTP Strict Transport Security (HSTS)
  • We sanitize all user inputs to prevent cross-site scripting (XSS) attacks
  • We use secure token storage with automatic refresh token rotation
  • We enforce session expiration with short-lived access tokens

Authentication Layer

  • We require multi-factor authentication (MFA) with cell phone verification at every sign-in
  • We issue JWT tokens with short expiration windows (1 hour)
  • We rotate refresh tokens so stolen tokens expire quickly
  • We require email verification for all new accounts
  • We protect against brute-force attacks with rate limiting

Database Layer

  • We enforce Row-Level Security (RLS) policies in PostgreSQL
  • We ensure users can only query rows they are authorized to access
  • We encrypt all ePHI at rest with AES-256
  • We run continuous backups with point-in-time recovery
  • We support query-level audit logging

Infrastructure Layer

  • We host on a SOC 2 Type II certified cloud platform
  • We deliver the frontend via a globally distributed edge network
  • We encrypt all data in transit with TLS 1.3
  • We store encrypted backups in geographically distributed storage
  • We maintain high availability with automated failover
Compliance Checklist

24 requirements. 24 addressed.

Administrative Safeguards

We conduct and document regular risk analyses
We maintain an active risk management plan
We have a designated Security Officer
We run an annual workforce training program
We document and enforce access management procedures
We test our contingency plan regularly
We provide a Data Processing Agreement for enterprise subscribers
We maintain documented incident response procedures

Physical Safeguards

We host on SOC 2 Type II certified infrastructure
We enforce physical access controls at all data centers
We maintain and enforce workstation use policies
We follow device and media disposal procedures

Technical Safeguards

We assign unique user identification for all accounts
We require multi-factor authentication (MFA)
We enforce automatic session timeouts
We implement role-based access control (RBAC)
We enforce row-level security at the database layer
We maintain immutable audit logs for all data events
We provide a consent audit log for access grants
We encrypt all data in transit with TLS 1.3
We encrypt all data at rest with AES-256
We encrypt all database backups
We enforce HTTPS with HSTS on every connection
We use short-lived API authentication tokens
Data Agreements

Data Processing Agreements for enterprise subscribers.

For enterprise subscribers who require a formal data processing agreement, we provide one upon request. This agreement establishes the permitted uses and disclosures of health data, our obligations to safeguard that information, and the procedures for reporting any data incidents.

Our agreements are designed to reflect best practices in health data protection and are aligned with applicable regulatory frameworks.

Available for enterprise subscribers
Request a Data Processing Agreement at any time
Aligned with HIPAA and FTC standards
Drafted to reflect health data protection best practices

Important Note

Bright Health Platform operates as a direct-to-patient advocacy platform. We aren't a Business Associate of a Covered Entity under HIPAA, but we've voluntarily adopted security controls aligned with HIPAA best practices because we believe health data deserves the highest level of protection.

Our security practices are also aligned with the FTC Health Breach Notification Rule, which applies to health data held by non-HIPAA-covered entities.

If you have questions about how our security posture fits your specific needs, we're happy to discuss. Contact our team for a detailed walkthrough.

Questions about our security posture?

We're happy to discuss our security architecture, provide documentation, or walk through our compliance controls with your team.

Contact Our Security Team