Information about our compliance standards, certifications, controls, and data protection practices
Elderwise documents security and privacy controls aligned with applicable healthcare requirements. Current assurance scope and supporting documentation are available to qualified organizations.
Current scope and documentation available for qualified review
ISMS documentation available for qualified review
Trust Services Criteria control mapping available for qualified review
U.S. healthcare privacy and security law governing PHI.
U.S. healthcare privacy and security requirements governing PHI handling by covered entities and business associates.
BAAs in place with processors, enforced RBAC/MFA/SSO, centralized audit logs, least-privilege defaults, AES-256/TLS 1.3 encryption, incident response runbooks, and recurring HIPAA training.
EU data protection regulation covering lawful processing and rights.
EU/EEA framework for data protection, lawful processing, and data subject rights.
Consent capture and audit trails, DPA addenda with vendors, privacy by design reviews, DSR workflows, and transfer impact assessments where applicable.
Singapore data protection law emphasizing consent and purpose limitation.
Singapore data protection obligations for consent, purpose limitation, notification, and access/correction.
Localized consent statements, retention schedules, access/correction channels, and breach notification procedures aligned with PDPC guidance.
International ISMS standard for managing information security risks.
International standard for establishing, implementing, maintaining, and continuously improving an ISMS.
ISMS control materials and current assurance scope are available through qualified review.
Attestation of security controls effectiveness over a period (Type II).
Attestation of control effectiveness over a review period per AICPA Trust Services Criteria.
TSC control materials and current assurance scope are available through qualified review.
Healthcare-centric certifiable security framework harmonizing multiple standards.
Healthcare-focused certifiable framework harmonizing HIPAA, ISO, NIST, and other requirements.
HITRUST scope and applicable control-mapping materials available through qualified review.
U.S. breach notification and enforcement enhancements to HIPAA.
U.S. breach notification and enforcement enhancements to HIPAA.
Incident response runbooks, evidence preservation, decision trees for materiality and reporting timelines.
Modern interoperability standard for structured clinical data exchange.
Modern healthcare interoperability standard for structured clinical data exchange.
FHIR-first data modeling for core entities, versioned profiles, and OAuth2/OpenID Connect for secure access.
Healthcare messaging standards used by EHRs and labs.
Legacy and current healthcare messaging standards widely used by EHRs and labs.
Adapters for HL7 v2.x integration where required, normalization to internal schemas, and secure transport.
AI management system standard for responsible AI governance.
Framework for governing responsible AI systems across lifecycle.
Map existing controls to AI risks, define KPIs and documentation for transparency, and institute model governance workflows.
Elderwise documents security and privacy controls aligned with applicable healthcare requirements. Current assurance scope and supporting documentation are available to qualified organizations.
Data Protection Officer:dpo@elderwise.ai
EU Representative (Art. 27 GDPR):eu-rep@elderwise.ai
APAC Representative:apac-rep@elderwise.ai
Security Team:security@elderwise.ai
Vulnerability Reporting:security-alerts@elderwise.ai
Elderwise documents security and privacy controls aligned with applicable healthcare requirements. Current assurance scope and supporting documentation are available to qualified organizations.
Elderwise Healthcare Compliance Commitment:
Our compliance strategy follows industry-standard "security by design" principles, embedding healthcare compliance requirements into our development process from inception to deployment. We recognize that healthcare data security directly impacts patient outcomes and provider efficiency, so our approach integrates technical safeguards with clinical workflow considerations to create a secure environment that enhances rather than impedes care delivery. Our compliance program emphasizes both regulatory adherence and the ethical responsibility we have to protect sensitive health information.