1. Ingress
Data enters Genesis through authenticated, encrypted interfaces (HL7 / FHIR / EDI / REST / SFTP). Every payload is validated against its interface specification before it lands.
Compliance
Compliance with applicable healthcare standards is paramount to protecting patients and delivering high-quality care. With international presence and a strong track record serving UK and US care providers, Genesis is fully committed to the principles of data privacy, standardization, and patient safety, and we hold the certifications, controls, and documentation to prove it.
A solution that upholds best practices
Security, access, infrastructure, monitoring

01
AES-256 encryption at rest. TLS 1.2+ in transit. Mutual TLS available for integrations
02
SAML-based SSO, role-based access control, MFA enforced, least-privilege provisioning
03
Hosted in geographically-segregated regions. UK data stays in the UK. US data stays in the US.
04
24/7 monitoring with audit logs retained for compliance. Incident response managed by our in-house ops team.
Data handling, end to end
From the moment data enters Genesis to the moment a record is purged, every step is governed by a documented control.
Data enters Genesis through authenticated, encrypted interfaces (HL7 / FHIR / EDI / REST / SFTP). Every payload is validated against its interface specification before it lands.
Inside Genesis, data is processed in tenant-isolated environments. Application-layer controls enforce role-based access; no engineer touches production patient data outside a logged, time-boxed support session.
Data is encrypted at rest using AES-256. Each customer's data lives in its own tenant boundary. UK data is stored in UK regions. US data is stored in US regions. We do not co-mingle.
Outbound data flows through the same authenticated, encrypted interfaces — back to your ERP, EHR, BI, or finance system. Every transaction is logged.
Retention follows customer policy and applicable law. On contract termination, data is exported and purged on a defined schedule, with a signed certificate of deletion provided.
Subprocessors
We disclose the subprocessors that touch customer data — by name, by purpose, by region. The full, current list is available on request; the categories below summarize the footprint.
PROVIDER
PURPOSE
DATA REGION
Primary production hosting infrastructure
US / UK / EU
Secondary hosting and customer-routed deployments
US / UK / EU
Customer support ticketing and incident management
EU
Transactional notifications, customer correspondence
US / EU
Trusted to protect data at scale
"Our customers hold themselves to an exceptional standard when it comes to patient safety. Compliance, for us, means holding ourselves to that same standard with their data. That's why we don't treat HIPAA, GS1, or SOC 2 as boxes to check at audit time — they're the floor, not the ceiling. We don't sell customer data. We don't train models on PHI. And we don't weaken encryption for our own convenience. Those aren't marketing positions. They're commitments our customers can hold us to in writing."
Common questions, answered directly
Frequently Asked Questions
Hand this section to your security team. We respond to SIG, SIG Lite, CAIQ, and HECVAT questionnaires on a continuous basis, and we share our latest SOC 2 Type II report and pen-test summary under NDA.
No engineer touches production patient data outside a logged, time-boxed support session authorized by the customer. Role-based access control, SAML SSO, and MFA are enforced by default.
Yes. SOC 2 Type II. The current report is available on request under NDA via the Request Security Documentation form.
Your data is exported on a defined schedule, purged from production and backups according to the agreed timeline, and a signed certificate of deletion is provided.
AES-256 at rest. TLS 1.2 or higher in transit. Mutual TLS is available for
sensitive integrations on request.
Yes. Genesis is a HIPAA-compliant solution. We sign BAAs as
standard for US customers handling PHI.
Yes. We respond on a rolling basis, typically within 3 business days. Use the request form in Section 08 above.
We make it easy. Send us your questionnaire, your NDA, and your timeline, and we'll respond quickly with the evidence pack, a Genesis compliance contact, and a clear path through your security gate.

Explore Our Solutions