Is this your company?Buyers are checking Elaborate here. Claim elaborate.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Elaborate is a platform that healthcare organizations and their practitioners use to modernize how lab results are delivered to patients. We partner with health care organizations to reduce their operating expense and eliminate clinical admin burden.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Elaborate SOC 2 compliant?
Elaborate is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Elaborate HIPAA compliant?
According to Elaborate's public trust center, Elaborate is HIPAA compliant. On SOC2C this listing is Listed.
Is Elaborate SOC 2 Type I or Type II?
Elaborate is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Elaborate's SOC 2 for a vendor risk assessment?
Yes. Elaborate's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Elaborate penetration tested?
Elaborate hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Elaborate secure?
Security isn't a single yes/no, but Elaborate is SOC 2 Type II compliant and holds SOC 2 Type I, SOC 2 Type II, HIPAA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Elaborate have a bug bounty or vulnerability disclosure program?
Elaborate hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@elaborate.com or via a /security page (Elaborate lists a security contact).
Who are Elaborate's subprocessors?
Elaborate lists 3 subprocessors on its trust center, including Vanta, Google Workspace, Amazon Web Services. Buyers use this for fourth-party risk review.
Where does Elaborate host or store data?
Elaborate hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Elaborate's trust center or security page?
Elaborate's trust center is at https://trust.elaborate.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What enterprise privacy and security settings are available?
As a trusted partner to healthcare organizations, we commit to the following security and privacy best practices : 1. Have a named individual responsible for information security 2. Maintain a documented information security training and awareness program 3. Have controls to prevent and/or detect malware in a timely manner 4. Have documented policies and procedures to ensure that information security is maintained 5. Implement effective encryption to protect confidential data in transit and at rest 6. Establish segregation of data and systems to limit access to sensitive and confidential data 7. Have a policy on account management to ensure appropriate access is granted 8. Secure mobile and portable devices with encryption and passwords 9. Require multifactor authentication (MFA) for remote access to systems 10. Require passwords are stored in a secure manner - hashed or encrypted 11. Implement controls to prevent the use of weak or insecure passwords 12. Address system vulnerabilities in a timely manner 13. Have policies and controls to address our use of mobile storage devices 14. Have policies and controls to address our use of cloud and hosting services 15. Have a defined policy and procedure for event and incident management 16. Have systems in place to detect system intrusion or data breach 17. Implement controls to physically secure systems and access to data We offer all prospective clients our security and privacy documentation, including our latest SOC2 Type2 report, upon request.
Do you encrypt data at rest?
Your connection is encrypted with 256-bit encryption. The connection uses TLS 1.2. The connection is encrypted using AES\_256\_CBC, with SHA256 for message authentication and ECDHE\_RSA as the key exchange mechanism. The connection supports three encryption algorithms (RSA, DSA, and ECC) within the same SSL certificate. Our system is assessed for vulnerability and daily website malware scanning.
How do you handle and use the collected data?
Elaborate is committed to complying with all applicable federal and state laws relating to Personal Health Information. Elaborate complies with all the rules outlined by Health Insurance Portability and Accountability Act (HIPAA), which prohibits unauthorized access to Protected Health Information (PHI). Elaborate uses patients' Personal Health Information to administer your Elaborate account and to improve the overall quality of the Elaborate algorithm. We may use de-identified data (sometimes called “anonymous data”) for research purposes. De-identified information is information that does not identify any persons and with respect to which there is no reasonable basis to believe that the information could be used to identify an individual. Because this information is anonymous, it is not protected under HIPAA and may be used without consent. Elaborate reserves the right to use, disclose and retain de-identified information without any restriction and in perpetuity. Elaborate will never share Personal Health Information. If you know of or suspect any violation of security, please send an email to sos@elaborate.com.
Is there an SLA for resolving identified security issues?
Sometimes, problems arise. When they do, your team can count on us to be there for you! Our team will respond to service-related incidents and requests within the following time frames. If you experience any issues with our service, we ask that you submit service requests with the priority level specified to your account manager (or implementation manager) and cc: [sos@elaborate.com](mailto:sos@elaborate.com). Our team will make all efforts to resolve all requests promptly, but cannot guarantee a time to resolution due to the inherent variability in effort and corresponding time required to resolve issues. However, rest assured we will communicate resolution efforts with you and keep you apprised of our progress. ###### Severe ###### Solution is unavailable or a substantial subset of platform functionality is unavailable without a workaround, security issues, or data integrity issues. *Response Time: 4 hours, 24x7x365* ###### High ###### Intermittent issues with Solution performance, and issues with available workarounds. *Response Time: 48 hours, 24x7x365* ###### Medium ###### Any other bugs and issues that are not considered Severe and High. *Response Time: 10 business days* ###### Low ###### Enhancements and tech questions. *Response Time: 30 business days*