For Health Systems and Providers
When your compliance or security team evaluates ConnectHealth, these are the questions typically covered in a vendor security review.
Does PHI leave our environment?
ConnectHealth’s standard deployment model routes data inside your AWS VPC. Your security team should review the full architecture documentation, including logs, monitoring, support pathways, and third-party service integrations to confirm the data flow for your specific implementation.
What about AI features and patient data?
ConnectHealth includes PHI redaction controls designed to help limit patient data exposure to AI model endpoints. Your compliance team should review the specific controls, model integrations, and failure-handling documentation with the ConnectHealth technical team before enabling AI features in a production PHI environment.
What does the audit trail look like?
CloudWatch can be configured to capture FHIR resource access events: operation type, user identity, and timestamp. Retention is configurable. Your compliance team can query access records directly. Review the audit configuration with the ConnectHealth team to confirm it meets your organization’s specific audit requirements.