Epic vendor security review: the 200-question questionnaire, every hospital
Every new hospital you sell into runs you through a full vendor security review — 200+ question questionnaire, BAA negotiation with their legal team, an IT validation cycle on their schedule, and an evidence packet they'll re-request every renewal.
Most healthcare vendors hit a wall around their fifth or sixth hospital. Compliance ops becomes a permanent function. Per-hospital cost goes up, not down.
SoFaaS™ centralizes the compliance posture so your tenth hospital deploys at the same speed as your first. Hospitals review SoFaaS™ once at the platform level. Every app on the runtime inherits that trust.
SOC 2 Type II
SoFaaS™ is SOC 2 Type II audited. The full report is available under NDA — request it from your account contact and we share it the same day.
HIPAA & BAA
A Business Associate Agreement is in place with every hospital deployment. The BAA is available on day one — request it from your account contact for the standard template, or ask about per-hospital amendments if a specific health system requires one.
The standardized evidence packet
For every hospital security review, SoFaaS™ provides a pre-built evidence packet so your team doesn't have to assemble it from scratch:
- • SOC 2 Type II report (most recent)
- • Penetration test summary
- • Sub-processor list
- • Incident response policy
- • Data flow diagrams
- • Encryption posture (in-transit, at-rest, key management)
The packet is updated continuously. When the hospital comes back next year for renewal, you re-share the same materials in their current state.
Data residency
Production PHI for SoFaaS™ stays in U.S. regions; cross-region replication is U.S.-only. Specific residency requirements (e.g. for academic medical centers with stricter rules) can be scoped per deployment.
Encryption
All in-flight traffic is TLS 1.2 or higher. All at-rest data is encrypted with managed keys. Key rotation is automated and logged.
Access controls
Role-based access control at the vendor workspace level. SSO available for vendor teams. Every administrative action is audit-logged.
Audit logging
Every request through the runtime is logged with caller identity, requested scope, FHIR resource, and outcome. Logs are queryable by your team and exportable for hospital review on demand.
Incident response
We follow a documented incident response plan with defined severity levels, escalation paths, and customer-notification SLAs. The runbook is available under NDA.
Sub-processors
The current list of SoFaaS™ sub-processors is published at /security/sub-processors. Customers receive notice before any new sub-processor is added.
Penetration testing
Independent penetration tests are run on a defined cadence by a qualified third party. Summary results are part of the evidence packet; full reports are available under NDA.
Vulnerability disclosure
Security researchers and customers can responsibly disclose vulnerabilities to security@vectorcare.com. We acknowledge within one business day.
What you still own as a vendor
SoFaaS™ is the runtime — it's not a substitute for your own security program. As the vendor, you remain responsible for:
- • Security of your own application code and the dependencies you ship
- • Your employee access policies, device management, and offboarding
- • Any customer data you handle outside SoFaaS™
- • The contractual relationship with your hospital customer
Setting these expectations up front prevents post-sale surprises.
Need to send this to a CISO?
Talk to us and we'll send the full SOC 2 report and evidence packet under NDA.
Talk to us