Compliance

Protect patients and ensure regulatory compliance.

Compliance with applicable healthcare standards is paramount to protecting patients and delivering high-quality care. With international presence and a strong track record serving UK and US care providers, Genesis is fully committed to the principles of data privacy, standardization, and patient safety, and we hold the certifications, controls, and documentation to prove it.

Request security documentation

A solution that upholds best practices

Certified, audited, and continuously reviewed.

HIPAA

Privacy and security of US
patient health information. Genesis is a HIPAA-compliant
solution.

We are GS1 Solution Partners.

International barcoding standard for identifying, capturing, and sharing supply chain data. Genesis is GS1 and barcode accredited.

Scan4Safety

NHS-led initiative for patient safety, traceability, and supply chain efficiency. Genesis powered 3 of 6 demonstrator sites.

SOC 2 Type II

Independently audited controls for security, availability, processing integrity, confidentiality, and privacy.

GDPR

EU and UK data-protection compliance for the handling of personal and patient data.

HL7 / FHIR

Compliance with the leading healthcare data-interchange standards used by every major EHR.

DCB0129

Certified to the NHS DCB0129 standard, demonstrating a robust clinical risk management process that supports the safe use of our digital health solutions.

Data Security & Protections Toolkit

Awarded Exceeds Expectations for meeting NHS data security standards and protecting sensitive patient information.

Cyber Essentials Accredited

Certified under the UK Cyber Essentials scheme, demonstrating essential cybersecurity controls to protect systems, data, and users from common cyber threats.

Security, access, infrastructure, monitoring

Patient safety extends beyond the patient bedside

Hands placing a tablet device into a white docking station with curved handles.
  • 01

    Security

    AES-256 encryption at rest. TLS 1.2+ in transit. Mutual TLS available for integrations

  • 02

    Access

    SAML-based SSO, role-based access control, MFA enforced, least-privilege provisioning

  • 03

    Infrastructure

    Hosted in geographically-segregated regions. UK data stays in the UK. US data stays in the US.

  • 04

    Monitoring

    24/7 monitoring with audit logs retained for compliance. Incident response managed by our in-house ops team.

Data handling, end to end

Realised savings only happen when the loop closes.

PPI Protection draws on the full Genesis Platform: clean data from Genesis Data, contract terms from Genesis Sourcing, real-time bill-only capture from Genesis Clinical, peer benchmarks from the Genesis dataset, and feeds realised-savings reporting back into Genesis Intelligence for the executive view. This closed loop is what makes the savings stick. Point solutions can solve a slice; only Genesis owns every link.

1. Ingress

Data enters Genesis through authenticated, encrypted interfaces (HL7 / FHIR / EDI / REST / SFTP). Every payload is validated against its interface specification before it lands.

2. Process

Inside Genesis, data is processed in tenant-isolated environments. Application-layer controls enforce role-based access; no engineer touches production patient data outside a logged, time-boxed support session.

3. Store

Data is encrypted at rest using AES-256. Each customer's data lives in its own tenant boundary. UK data is stored in UK regions. US data is stored in US regions. We do not co-mingle.

4. Egress

Outbound data flows through the same authenticated, encrypted interfaces — back to your ERP, EHR, BI, or finance system. Every transaction is logged.

5. Retain & Purge

Retention follows customer policy and applicable law. On contract termination, data is exported and purged on a defined schedule, with a signed certificate of deletion provided.

Vendor rep submits bill sheet via the CaseSnap mobile app within minutes of surgery.

Genesis Matrix normalizes every line item by hospital, procedure, vendor, surgeon, product, and brand, with primary-vs-revision and capitated-construct intelligence.

Each line audited in real time against contract tier, capitated construct, primary-vs-revision rules, wasted-item allowances, off-contract flags, expired items, recalls, and benchmark pricing.

Discrepancies flagged via HIPAA-compliant messaging, both hospital and vendor notified, corrections made before payment, clinical review specialists adjudicate edge cases.

Cleared cases generate approved POs into Oracle, Infor, Workday, or PeopleSoft. Realized savings, compliance rates, benchmark coverage, and rebate capture flow into the CFO dashboard via Genesis Intelligence.

Subprocessors

Every third party we use, named.

We disclose the subprocessors that touch customer data — by name, by purpose, by region. The full, current list is available on request; the categories below summarize the footprint.

PROVIDER

PURPOSE

DATA REGION

Amazon Web Services (AWS)

Primary production hosting infrastructure

US / UK / EU

Microsoft Azure

Secondary hosting and customer-routed deployments

US / UK / EU

Atlassian (Jira Service Desk)

Customer support ticketing and incident management

EU

Email / Communications

Transactional notifications, customer correspondence

US / EU

Trusted to protect data at scale

Live across 400+ hospital sites.

Barts Health NHS Trust logo
Royal United Hospitals Bath NHS Foundation Trust logo
Hermitage Medical Clinic logo
Jackson logo
Manchester University NHS Foundation Trust logo
NHS England logo
NHS Scotland logo
University Hospitals Plymouth NHS Trust logo
Royal Devon University Healthcare NHS Foundation Trust logo
Royal Free London NHS Foundation Trust logo
Royal Victoria Eye and Ear Hospital logo

For security review

Need the full evidence package?
We have it ready.

We have the following documentation available and can respond to SIG, SIG Lite, CAIQ, and HECVAT questionnaires on a continuous basis. We share our latest SOC 2 Type II report and regular independent pen-test summaries under NDA.

SOC 2 Type II Report

Independent audit of security, availability, and confidentiality controls.

Penetration Test Summary

Most recent third-party penetration test, summarized.

SIG / SIG Lite Response

Pre-completed Standardized Information Gathering questionnaire.

CAIQ Response

Pre-completed Cloud Security Alliance Consensus Assessments Initiative Questionnaire.

HECVAT (on request)

Higher Education Community Vendor Assessment Toolkit response, available where applicable.

Custom Questionnaires

Our compliance team responds to bespoke security reviews within 3 business days.

"Our customers hold themselves to an exceptional standard when it comes to patient safety. Compliance, for us, means holding ourselves to that same standard with their data. That's why we don't treat HIPAA, GS1, or SOC 2 as boxes to check at audit time — they're the floor, not the ceiling. We don't sell customer data. We don't train models on PHI. And we don't weaken encryption for our own convenience. Those aren't marketing positions. They're commitments our customers can hold us to in writing."

Mike O’Flynn

Chief Technology Officer, Genesis

Common questions, answered directly

Frequently Asked Questions

Hand this section to your security team. We respond to SIG, SIG Lite, CAIQ, and HECVAT questionnaires on a continuous basis, and we share our latest SOC 2 Type II report and pen-test summary under NDA.

No engineer touches production patient data outside a logged, time-boxed support session authorized by the customer. Role-based access control, SAML SSO, and MFA are enforced by default.

Yes. SOC 2 Type II. The current report is available on request under NDA via the Request Security Documentation form.

Your data is exported on a defined schedule, purged from production and backups according to the agreed timeline, and a signed certificate of deletion is provided.

AES-256 at rest. TLS 1.2 or higher in transit. Mutual TLS is available for
sensitive integrations on request.

Yes. Genesis is a HIPAA-compliant solution. We sign BAAs as
standard for US customers handling PHI.

Yes. We respond on a rolling basis, typically within 3 business days. Use the request form in Section 08 above.

.grid { display: grid; width: 100%; grid-auto-columns: 1fr; column-gap: var(--site--gap); grid-template-rows: auto; --_column-count---value: 12; grid-template-columns: repeat(var(--_column-count---value), minmax(0, 1fr)); } .section-tertiary { position: relative; display: flex; padding-top: var(--_spacing---section-space--main); padding-bottom: var(--_spacing---section-space--main); flex-flow: column; align-items: center; background-color: var(--_theme---background-tertiary); color: var(--_theme---text-secondary); } .accordion-item { overflow: clip; padding-top: 1.25rem; padding-bottom: 1.25rem; border-bottom-style: solid; border-bottom-width: 0.0625rem; border-bottom-color: var(--swatch--white-20); transition-property: color, border-color, background-color; transition-duration: 200ms, 200ms, 200ms; transition-timing-function: ease, ease, ease; cursor: pointer; list-style: none; } .accordion-item.-wfp-hover, .accordion-item:hover { border-bottom-color: var(--swatch--white); } @media screen and (max-width: 991px) { .accordion-item.-wfp-hover, .accordion-item:hover { border-color: white white rgb(225, 227, 225); } }

What You Don't See Is Costing You

Identify hidden leakage, inefficiencies and compliance gaps with a free Genesis assessment, built for healthcare supply chain, finance and clinical leaders.

Looking up at tall modern skyscrapers against a clear blue sky.

Explore Our Solutions

Other Solutions

Genesis Data

Connect and
enrich what you know.

Create a clean, normalized single source of truth across your item master, ERP, EHR, and supply chain, eliminating manual data entry, duplicate records, and disconnected workflows.

Empty search bar with a yellow 'Create' button on a dark green abstract background.

Genesis Sourcing

Control what you buy.

Enforce contract compliance at the point of purchase with automated workflows that ensure what was negotiated is what gets paid, without manual oversight.

Dark interface with a circular progress bar labeled 'Payed' and a tag for 'Automated workflows'.

Genesis Inventory

Know what you have, wherever it is.

Gain real-time visibility and full traceability across clinical inventory, reducing stockouts, eliminating expired products, and enabling rapid recall response.

Search bar with highlighted Inventory and surrounding options recall response reducing stockouts

Genesis Clinical

Capture what you use.

Automate point-of-care documentation and bill-only workflows to ensure accurate, real-time capture of supply usage—without adding burden to clinical staff.

Blurry dark abstract background with a translucent user interface showing a plus sign and bar graph.

 Genesis Savings

Protect what you spend.

Detect pricing errors, prevent vendor overbilling, and validate every transaction against contract terms, protecting margins before charges are posted.

Yellow shield icon with check mark and user shield icon on dark abstract background with Detect Errors text.

Genesis Intelligence

Insights needed to take action.

Continuously transform data across every solution into actionable insights, driving smarter decisions, surfacing savings opportunities, and improving performance at every stage of the lifecycle.

Graph on translucent panel with white upward arrow line and yellow dashed line on dark abstract background.