
Bright Health Platform is built with health data privacy as a first principle. While Bright Health Platform operates as a direct-to-patient advocacy platform - not as a Business Associate of a Covered Entity under HIPAA - we've voluntarily implemented security controls aligned with HIPAA best practices and the FTC Health Breach Notification Rule. This page documents those controls.
Bright Health Platform's security controls are aligned with HIPAA standards for all subscribers. For organizations managing 10 or more patients, we offer a formal HIPAA compliance program including a signed Business Associate Agreement, documented risk assessments, and dedicated compliance support. Contact us to learn more.
We implement the policies, procedures, and training programs that govern how ePHI is managed, accessed, and protected across our organization.
We control physical access to every system and facility that stores or processes ePHI, including data center security and device management.
We enforce technology-based controls - including encryption, access control, audit logging, and transmission security - that protect ePHI at every layer of our system.
Here's how we handle the policies, procedures, and training that govern ePHI management across our organization.
Here's how we secure the physical infrastructure that stores and processes ePHI.
Here's how we use technology to protect ePHI at every layer of our system.
We designed every layer of Bright Health Platform's architecture with security and compliance as first principles.
For enterprise subscribers who require a formal data processing agreement, we provide one upon request. This agreement establishes the permitted uses and disclosures of health data, our obligations to safeguard that information, and the procedures for reporting any data incidents.
Our agreements are designed to reflect best practices in health data protection and are aligned with applicable regulatory frameworks.
Bright Health Platform operates as a direct-to-patient advocacy platform. We aren't a Business Associate of a Covered Entity under HIPAA, but we've voluntarily adopted security controls aligned with HIPAA best practices because we believe health data deserves the highest level of protection.
Our security practices are also aligned with the FTC Health Breach Notification Rule, which applies to health data held by non-HIPAA-covered entities.
If you have questions about how our security posture fits your specific needs, we're happy to discuss. Contact our team for a detailed walkthrough.
We're happy to discuss our security architecture, provide documentation, or walk through our compliance controls with your team.
Contact Our Security Team