Is this your company?Buyers are checking AlayaCare here. Claim alayacare.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Data security and privacy are core values at AlayaCare. We build them into our organization, our processes, and into the home care software platform we deliver. Our Trust Center is just one of the ways by which we demonstrate how we protect your most valuable asset. Please refer to the FAQ section link below for more detailed information regarding AlayaCare's security and privacy protections.
Alayacare Cloud SOC2 report 2025 is ready!Oct 2025
Our latest SOC 2 Type II report (2025) is now available to AlayaCare Cloud customers. To access: sign in to the Trust Center and navigate to Resources. SOC 2 reports for Alayacare Residential and Procura CS will follow in the next days. Need help? Contact security@alayacare.com or your Customer Success Manager.
🚀 New Whitepaper Available on Our Trust CenterMay 2025
Secure and Streamlined Authentication: Leveraging Your IDP with AlayaCare Cloud We're excited to share our latest whitepaper exploring how organizations can enhance security and user experience by integrating their Identity Provider (IDP) with AlayaCare Cloud. This guide outlines best practices, implementation tips, and key benefits of a federated authentication model to streamline access while maintaining robust protection for sensitive healthcare data. 📄 Now available on the Trust Center using this link.
Our compliance docs have been refreshed. - New SOC 2 reports for AC Cloud and AlayaCare Residential (2024) - New SOC 1 Report for AC Cloud (2024) Stay tuned for more compliance updates.
This listing is partial
6/11 details · 55%
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is AlayaCare SOC 2 compliant?
AlayaCare is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is AlayaCare HIPAA compliant?
According to AlayaCare's public trust center, AlayaCare is HIPAA compliant. On SOC2C this listing is Listed.
Is AlayaCare HITRUST certified?
According to AlayaCare's public trust center, AlayaCare is HITRUST certified. On SOC2C this listing is Listed.
Is AlayaCare CSA STAR certified?
According to AlayaCare's public trust center, AlayaCare is CSA STAR certified. On SOC2C this listing is Listed.
Is AlayaCare SOC 2 Type I or Type II?
AlayaCare is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use AlayaCare's SOC 2 for a vendor risk assessment?
Yes. AlayaCare's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is AlayaCare penetration tested?
AlayaCare hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is AlayaCare secure?
Security isn't a single yes/no, but AlayaCare is SOC 2 Type II compliant and holds SOC 2 Type II, HIPAA, HITRUST, CSA STAR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does AlayaCare have a bug bounty or vulnerability disclosure program?
AlayaCare hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@alayacare.com or via a /security page (AlayaCare lists a security contact).
Who are AlayaCare's subprocessors?
AlayaCare lists 9 subprocessors on its trust center, including Amazon Web Services, Cloudflare, Wiz, Snowflake, ElevenLabs. Buyers use this for fourth-party risk review.
Where does AlayaCare host or store data?
AlayaCare hosts on AWS, GCP. Data residency details are on its trust center.
Where is AlayaCare's trust center or security page?
AlayaCare's trust center is at https://trustcenter.alayacare.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Audit Logs
AlayaCare's SaaS platform maintains audit logs and audit trails of (i) a comprehensive set of user activities performed in the application, and (ii) access to the application within the secure infrastructure of the Customer's AWS instance/tenant. As audit logs and trails become a bigger part of healthcare and privacy regulation, AlayaCare takes a comprehensive but user-driven approach to many audit inquiries. Via in-app clinical functions, user can audit activities along with changes to user roles and permissions. This overview of the elements of AlayaCare's capabilities can serve as a baseline from which Customers can map to their specific requirements and use cases. Some additional configurations can be implement upon request by AlayaCare's professional services and data management teams. More detailed information can be access through this requestable document: https://trustcenter.alayacare.com/resources?s=jp6i11wg5fbz8rmjsagkn&name=alayacare-core-audit-logging-and-related-capabilities-xlsx
Does AlayaCare support SAML SSO?
AlayaCare supports all SAML 2.0 Identity Providers for Single Sign-On (SSO)
Privacy Policy
AlayaCare’s Privacy Policies describe how we address the privacy and security of the data and other information entrusted to us: - by our customers through their access and use of the AlayaCare electronic health record platform; - by our business partners and specific third-party providers of key services to us; and - by everyone else, including partners, prospective customers, and those who seek information or contact us through our website.
Privacy & Data Management
Overview Privacy and data protection practices at AlayaCare complement the core security infrastructure and tools that ensure the integrity of the personal and protected health information in AlayaCare's custody. Using a shared-responsibility model, individual consents and requests for access are managed by AlayaCare's customers. AlayaCare, in its capacity as a business associate or data custodian, assumes responsibility for the integrity and redundancy of the data in its secure, AWS cloud-based infrastructure. A data map sets out the key flows of information in and out of the AlayaCare infrastructure; https://trustcenter.alayacare.com/resources?s=si6ekbq9ejdwf3031zoxur&name=overview-of-alayacare-system-architecture-diagram-png Privacy Impact Assessments (PIAs) Assessing the impact of its products and services on the privacy and data of customers is an important component of AlayaCare's approach to safeguarding patient data and maintaining compliance with privacy regulations. AlayaCare's PIA serves as an important evaluation of its data management practices and their impact on privacy. By conducting a thorough assessment, AlayaCare can identify and address potential privacy risks associated with its EHR platform and its key functional capabilities. This proactive approach allows AlayaCare to ensure that the confidentiality, integrity, and availability of the health information maintained in our platform are effectively protected. Key benefits of AlayaCare’s PIAs include: 1. Privacy Compliance: A PIA enables AlayaCare to assess its compliance with applicable privacy laws and regulations, such as the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the Personal Health Information and Protection Act (PHIPA) in Ontario. By conducting a PIA, AlayaCare can identify any gaps in compliance and implement necessary measures to meet regulatory requirements. 2. Risk Identification and Mitigation: The PIA process helps AlayaCare to identify…
Business Continuity
AlayaCare's electronic health records platform uses a variety of tools and mechanisms to achieve high availability and resiliency. Its infrastructure spans multiple fault-independent AWS availability zones in geographic regions physically separated from one another. AlayaCare’s infrastructure is able to detect and route around issues experienced by hosts or even whole data centers in real-time and employ orchestration tooling that has the ability to regenerate hosts, building them from the latest backup. AlayaCare also leverages specialized tools that monitor server performance, data, and traffic load capacity within each availability zone and colocation data center. If sub-optimal server performance or overloaded capacity is detected on a server within an availability zone or colocation data center, these specialized tools increase the capacity or shift traffic to relieve any suboptimal server performance or capacity overload. AlayaCare is also immediately notified in the event of any sub-optimal server performance or overloaded capacity.
Business Associate (and equivalent) Agreements (BAAs)
AlayaCare enters into BAAs or equivalents with all of its customers and partners to ensure that the data protection and usage rights, along with breach notification protocols are set out in detail.
Incident Management & Response
Data Breach Notification AlayaCare promptly investigates all suspected security incidents or potential data compromises. To the extent permitted by applicable law, AlayaCare will notify all affected customers of any such incident in accordance with the Privacy Policy, BAA, or DPA (as applicable). Since its inception, AlayaCare has had no data breach, neither external nor internal and no reportable violations of HIPAA or any other applicable privacy laws. Incident Response Plan (IRP) AlayaCare maintains a comprehensive Security Incident Response Plan (SIRP) which includes detailed processes and resource inventories designed to provide a comprehensive roadmap to manage its response in the event of a suspected or actual data breach or security incident. AlayaCare, in conjunction with its partnership with AWS and AWS-provided protocols, conducts regular "table-top" exercises performed with key members of its SRE infrastructure team and with the guidance of insurer-provided subject matter experts.
Availability & Reliability
Infrastructure Redundancy As a cloud-based SaaS provider, AlayaCare relies heavily on the redundancy and fault tolerance of its cloud service provider to avoid, respond, and recover from major service interruptions or other disasters. The production platform is designed and implemented within AWS such that critical components are distributed across multiple availability zones, providing fault tolerance to service failures. Availability zones are geographically segregated data centers maintained by AWS that operate in high-availability mode. In the event of a data center failure, failover and failback occur automatically in real-time and are transparent to AlayaCare and its customers. AlayaCare's status page includes all scheduled maintenance and current status information; https://alayacare.status.io/
Organizational Security
AlayaCare maintains security and data protection programs comprising administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and the confidentiality, integrity, and availability of Customer Data. AlayaCare's risk-based approach ensures an appropriate level of oversight and management of security programs and facilitates both independent third-party and internal audits and risk assessments, including privacy impact risk assessment and threat & risk assessments. AlayaCare’s security framework is based on the SOC 2 infosec security management system and includes programs in the following areas; - Policies and Procedures - Asset Management - Access Management - Cryptography - Physical Security - Operations Security - Communications Security - Business Continuity - People Security - Product Security - Cloud and Network Infrastructure - Security Compliance - Third-Party Security - Vulnerability Management - Security Monitoring and Incident Response
Confidentiality Agreements
AlayaCare has controls in place to maintain the confidentiality of all data in accordance with its data risk classifications and the terms of its customer agreements. All AlayaCare employees and contractors receive training in and are bound by AlayaCare’s policies regarding the confidentiality of data.
Physical Access Control - Data Center
AWS data centers that host the AlayaCare Services are strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication (2FA) a minimum of two (2) times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. These facilities are designed to withstand adverse weather and other reasonably predictable natural conditions. Each data center has redundant electrical power systems that are available twenty-four (24) hours a day, seven (7) days a week. Uninterruptible power supplies and on-site generators are available to provide back-up power in the event of an electrical failure. For further information, please refer to AWS Physical Controls at; https://aws.amazon.com/compliance/data-center/controls/ In addition, AlayaCare headquarters and office spaces have a physical security program that manages visitors, building entrances, CCTVs (closed circuit televisions), and overall office security. All employees, contractors, and visitors are required to wear identification badges.
Threat & Risk Management
Threat and Risk Assessments (TRAs) AlayaCare provides TRAs covering its core cloud electronic health record (EHR) platform and associated infrastructure. This assessment provides an organization-wide overview designed to evaluate and identify potential vulnerabilities and risks within our EHR platform, allowing us to implement robust security measures and proactive mitigation strategies. Key benefits of AlayaCare’s TRAs: 1. Comprehensive Risk Evaluation: The TRA includes internal and external factors that could compromise the confidentiality, integrity, and availability of patient data. By conducting this assessment, we gain insights into vulnerabilities, enabling us to develop effective risk management strategies. 2. Proactive Mitigation Measures: By understanding potential vulnerabilities in systems and processes and mapping them to primary potential threat vectors, we can implement appropriate security controls, encryption protocols, access management, intrusion detection systems, and incident response plans. 3. Compliance and Regulatory Alignment: The TRA allows us to address compliance with industry-specific regulations and standards, including the HIPAA Security Rule in the US and increasing specificity in healthcare regulations in many jurisdictions. You can request a copy of our AlayaCare Cloud TRA by clicking on this link: https://trustcenter.alayacare.com/resources?s=j9lldmlz7byqttj3vjny3&name=alayacare-master-threat-risk-and-vulnerabilities-assessment-tra-ac-23-1-allprod-xlsx