Ankr HealthAnkr Health

Security · Privacy · Compliance

How Ankr Health protects
the data you trust us with.

We operate a healthcare technology platform, so protected health information sits at the centre of our threat model. Every control, policy and task shown here is pulled live from the compliance system our security team runs — not a marketing snapshot.

Last verified
July 27, 2026
Last change
March 18, 2026
Data source
Live compliance system

2

Frameworks

actively monitored

35

Controls

mapped to requirements

25

Policies

published and in force

100%

Tasks complete

28 of 28 compliance tasks

Frameworks

2 tracked

SOC 2 Type II

Compliant

Security, availability and confidentiality controls, observed over a review period.

All mapped controls implemented, evidenced and monitored continuously.

HIPAA

Compliant

Administrative, physical and technical safeguards for protected health information.

All mapped controls implemented, evidenced and monitored continuously.

Documentation

Reports available on request

Audit reports, security questionnaires and architecture summaries are released to customers and prospects after review by our security team. Requests are recorded in our compliance system and may require a signed NDA.

  • PDFSOC 2 reportGated
  • PDFHIPAA security risk assessmentGated
  • PDFPenetration test summaryGated
  • PDFSecurity questionnaire responsesGated

Policies in force

25 published

  1. 01

    Acceptable Use & Workstation Security

    Sets responsible use rules, enforces endpoint encryption, patching, auto-lock, and restricts personal storage of company data.

  2. 02

    Access Control & Least Privilege

    Implements a Joiner-Mover-Leaver workflow, role-based access control, quarterly reviews, and strict approval for elevated privileges.

  3. 03

    Authentication & Password

    Defines robust password rules, enforces MFA on sensitive systems, secures credential storage, and locks or resets risky accounts.

  4. 04

    Background Screening & On/Off-boarding

    Screens new hires, provisions least-privilege access, disables accounts and recovers assets at exit, and archives records securely.

  5. 05

    Backup, Business Continuity & Disaster Recovery

    Establishes backup frequency, off-site encrypted storage, quarterly restore tests, and concise BCP/DR activation playbooks.

  6. 06

    Change & Release Management

    Requires ticketed, peer-reviewed changes, pre-deployment testing, scheduled releases, emergency-change documentation, and post-release reviews.

  7. 07

    Compliance & Regulatory Monitoring

    Catalogues all legal, regulatory, and contractual obligations, links them to controls and evidence, and tracks enquiries and gaps to closure.

  8. 08

    Data Classification & Handling

    Uses a four-tier classification scheme to label data and prescribes access, encryption, sharing, and disposal rules for each level.

  9. 09

    Encryption & Crypto Controls

    Mandates strong encryption for data in transit and at rest, governs key generation, storage, rotation, and audits for weak configurations.

  10. 10

    Incident Response & Breach Notification

    Defines detection, triage, containment, communication, legal notification, and post-incident lessons with clear team roles.

  11. 11

    Information Security & Privacy Governance

    Assigns clear ownership and management accountability for security and privacy, keeps policies current, and measures compliance through regular reviews.

  12. 12

    Information Sharing & Transfer

    Restricts data transfers to approved encrypted channels, enforces NDAs and minimisation, records international safeguards, and audits transfer logs.

  13. 13

    Logging, Monitoring & Audit

    Centralises and protects logs, sets real-time alerting for critical events, retains audit trails, and reviews metrics and samples monthly.

  14. 14

    Physical Security & Environmental

    Controls facility and server-room access, manages visitors, safeguards against fire, flood, or climate risks, and audits logs and walk-throughs.

  15. 15

    Policy Management & Exception Handling

    Inventories every policy, enforces version control and annual reviews, and documents, time-boxes, and sunsets any approved exceptions.

  16. 16

    Privacy & Data-Subject Rights

    Ensures personal data is processed on a lawful basis, keeps users informed, and fulfils data-subject requests within required timelines.

  17. 17

    Remote Access & BYOD

    Approves secure VPN or zero-trust methods, sets endpoint hardening and mobile controls, and logs and reviews remote sessions.

  18. 18

    Retention & Secure Disposal

    Sets record-specific retention periods, runs periodic purge reviews, and requires cryptographic or physical destruction of outdated data.

  19. 19

    Risk Management

    Maintains a living risk register, scores and prioritises threats, sets treatment actions, and injects threat-intel updates into decision-making.

  20. 20

    Sanctions & Disciplinary

    Applies a progressive, documented disciplinary framework for security or privacy violations, ensuring fair process and consistent sanctions.

  21. 21

    Secure Configuration & Hardening

    Publishes baseline hardening guides, uses version-controlled IaC, detects configuration drift, and backs up critical configs.

  22. 22

    Secure Software Development Lifecycle

    Embeds security user stories, automated code scans, dependency checks, secrets detection, and pre-release penetration testing into every build.

  23. 23

    Security & Privacy Awareness Training

    Delivers onboarding and annual refresher training, role-based modules, simulated phishing, and tracks completion metrics.

  24. 24

    Vendor & Third-Party Risk

    Inventories vendors, tiers them by data impact, conducts due diligence, embeds security clauses in contracts, and monitors attestations and incidents.

  25. 25

    Vulnerability & Patch Management

    Runs routine scans, prioritises patches by CVSS and exploit activity, enforces remediation SLAs, and verifies closure.

Policy documents themselves are available under the document request process above.

Found a security issue, or need something not listed here?

Our security team monitors this inbox directly. Vulnerability reports are triaged within one business day.

support@ankr.us