• Skip to main content
  • Skip to navigation
  • Skip to footer
Elderwise Logo
Elderwise
For CliniciansFor CaregiversImpactInvestors & Partners

For Caregivers

  • Download App
  • Privacy Policy
  • Terms of Service
  • Vulnerability Report

For Clinicians

  • Clinical Solutions
  • Pricing
  • Integration
  • Schedule Discovery Call

Resources

  • Blog
  • Elderwise Information Hub
  • FAQ
  • Contact

Company

  • About Us
  • Our Values
  • Impact
  • Careers
  • Legal, Risk & Compliance

Compliance & Security

  • Compliance Overview
  • Cookie Policy
  • HIPAA & Security

Patient & Data Rights

  • Request Medical Records
  • Report a Data Breach
  • Delete Account
  • Delete Data
Elderwise Logo
Elderwise

© 2026 Elderwise. All Rights Reserved.

    Legal, Risk & Compliance

    Information about our compliance standards, certifications, controls, and data protection practices

    Security & Compliance Standards

    Elderwise documents security and privacy controls aligned with applicable healthcare requirements. Current assurance scope and supporting documentation are available to qualified organizations.

    Assurance Status

    HIPAA Controls

    Current scope and documentation available for qualified review

    ISO 27001 Controls

    ISMS documentation available for qualified review

    SOC 2 Controls

    Trust Services Criteria control mapping available for qualified review

    Healthcare Standards & Control Mapping

    Last Updated: 2026-04-13
    HIPAA

    Health Insurance Portability and Accountability Act (HIPAA)

    U.S. healthcare privacy and security law governing PHI.

    Healthcare Relevance:

    U.S. healthcare privacy and security requirements governing PHI handling by covered entities and business associates.

    Key Requirements:

    • Business Associate Agreements (BAAs)
    • Role-based access and MFA
    • Audit logging and monitoring
    • Minimum necessary access
    • Encryption in transit and at rest
    • Breach notification procedures
    • Periodic risk assessments and workforce training

    Elderwise Control Approach:

    BAAs in place with processors, enforced RBAC/MFA/SSO, centralized audit logs, least-privilege defaults, AES-256/TLS 1.3 encryption, incident response runbooks, and recurring HIPAA training.

    GDPR

    EU General Data Protection Regulation (GDPR)

    EU data protection regulation covering lawful processing and rights.

    Healthcare Relevance:

    EU/EEA framework for data protection, lawful processing, and data subject rights.

    Key Requirements:

    • Lawful basis and consent management
    • Data subject rights (access, erasure, portability)
    • Data Processing Agreements
    • Data Protection by Design and Default
    • Records of processing activities
    • International transfer safeguards

    Elderwise Control Approach:

    Consent capture and audit trails, DPA addenda with vendors, privacy by design reviews, DSR workflows, and transfer impact assessments where applicable.

    PDPA

    Personal Data Protection Act (PDPA, Singapore)

    Singapore data protection law emphasizing consent and purpose limitation.

    Healthcare Relevance:

    Singapore data protection obligations for consent, purpose limitation, notification, and access/correction.

    Key Requirements:

    • Consent and notification
    • Purpose limitation
    • Access and correction rights
    • Protection and retention limits
    • Data breach notification

    Elderwise Control Approach:

    Localized consent statements, retention schedules, access/correction channels, and breach notification procedures aligned with PDPC guidance.

    ISO27001

    ISO/IEC 27001 Information Security Management System

    International ISMS standard for managing information security risks.

    Healthcare Relevance:

    International standard for establishing, implementing, maintaining, and continuously improving an ISMS.

    Key Requirements:

    • Risk management program
    • ISMS governance and documentation
    • Security controls per Annex A
    • Continuous improvement cycle

    Elderwise Control Approach:

    ISMS control materials and current assurance scope are available through qualified review.

    SOC2

    SOC 2 Type II (Security, Availability, Confidentiality)

    Attestation of security controls effectiveness over a period (Type II).

    Healthcare Relevance:

    Attestation of control effectiveness over a review period per AICPA Trust Services Criteria.

    Key Requirements:

    • Documented policies and procedures
    • Security monitoring and alerting
    • Change and incident management
    • Vendor risk management

    Elderwise Control Approach:

    TSC control materials and current assurance scope are available through qualified review.

    HITRUST

    HITRUST CSF

    Healthcare-centric certifiable security framework harmonizing multiple standards.

    Healthcare Relevance:

    Healthcare-focused certifiable framework harmonizing HIPAA, ISO, NIST, and other requirements.

    Key Requirements:

    • Risk-based control selection
    • Policy/procedure implementation
    • Validation and scoring
    • External assessment

    Elderwise Control Approach:

    HITRUST scope and applicable control-mapping materials available through qualified review.

    HITECH

    HITECH Act (Breach Notification)

    U.S. breach notification and enforcement enhancements to HIPAA.

    Healthcare Relevance:

    U.S. breach notification and enforcement enhancements to HIPAA.

    Key Requirements:

    • Breach risk assessment
    • Timely notifications
    • Media and HHS reporting thresholds

    Elderwise Control Approach:

    Incident response runbooks, evidence preservation, decision trees for materiality and reporting timelines.

    FHIR

    HL7 FHIR (Interoperability)

    Modern interoperability standard for structured clinical data exchange.

    Healthcare Relevance:

    Modern healthcare interoperability standard for structured clinical data exchange.

    Key Requirements:

    • FHIR resources and profiles
    • RESTful APIs and conformance
    • Security and authorization (SMART on FHIR)

    Elderwise Control Approach:

    FHIR-first data modeling for core entities, versioned profiles, and OAuth2/OpenID Connect for secure access.

    HL7

    HL7 v2/v3 Messaging

    Healthcare messaging standards used by EHRs and labs.

    Healthcare Relevance:

    Legacy and current healthcare messaging standards widely used by EHRs and labs.

    Key Requirements:

    • Message formats and segments
    • Ack/error handling
    • Transport and security

    Elderwise Control Approach:

    Adapters for HL7 v2.x integration where required, normalization to internal schemas, and secure transport.

    ISO42001

    ISO/IEC 42001 AI Management System

    AI management system standard for responsible AI governance.

    Healthcare Relevance:

    Framework for governing responsible AI systems across lifecycle.

    Key Requirements:

    • AI risk management and controls
    • Data governance and transparency
    • Monitoring and continuous improvement

    Elderwise Control Approach:

    Map existing controls to AI risks, define KPIs and documentation for transparency, and institute model governance workflows.

    Security & Compliance Standards

    Elderwise documents security and privacy controls aligned with applicable healthcare requirements. Current assurance scope and supporting documentation are available to qualified organizations.

    Legal Documents & Compliance Materials

    • Request Business Associate Agreement (BAA)
    • Request Data Processing Agreement (DPA)
    • Request Security & Privacy Documentation
    • Request Compliance Attestation
    • Request Penetration Test Executive Summary

    Data Protection & Security Contacts

    Data Protection Officer:dpo@elderwise.ai

    EU Representative (Art. 27 GDPR):eu-rep@elderwise.ai

    APAC Representative:apac-rep@elderwise.ai

    Security Team:security@elderwise.ai

    Vulnerability Reporting:security-alerts@elderwise.ai

    Assurance Status

    Elderwise documents security and privacy controls aligned with applicable healthcare requirements. Current assurance scope and supporting documentation are available to qualified organizations.

    • HIPAA Controls: Controls designed to support applicable HIPAA obligations
    • GDPR Controls: Privacy controls reviewed against applicable requirements
    • ISO 27001 Controls: ISMS documentation available for qualified review
    • SOC 2 Controls: Trust Services Criteria control mapping available for qualified review

    Healthcare-Specific Security Features

    • for all sensitive health information
    • for healthcare provider access
    • aligned with clinical workflows
    • for all actions on protected health information
    • Secure API design for healthcare system integrations
    • Context-aware access controls for different care settings
    • Session timeout controls for clinical environments
    • Secure offline caching for emergency care scenarios

    Healthcare Infrastructure Security

    • Hosting in data centers with industry-standard security controls
    • Region-specific data residency options for regulatory compliance
    • Regular vulnerability scanning and penetration testing
    • Disaster recovery with high-availability architecture
    • Infrastructure as Code (IaC) for secure, consistent deployments
    • Network segmentation for data isolation
    • Infrastructure monitoring with automated alerting
    • Continuous security control validation using automated tools

    Ongoing Security & Privacy Practices

    • Documented security monitoring and incident-response procedures
    • Periodic review of security and privacy controls
    • Vendor security reviews for applicable third parties
    • Security and privacy training for staff
    • Security governance reviews with relevant stakeholders
    • Operational visibility for security and privacy controls
    • Review materials maintained for qualified organizations

    Healthcare Data Governance Framework

    Data Collection in Healthcare Context
    • Explicit consent mechanisms for patient data with healthcare-specific language
    • Transparent data collection purposes aligned with clinical needs
    • Minimized data collection following principles of medical necessity
    • Special handling procedures for sensitive medical categories
    • Patient-centric approach to data ownership and control
    Healthcare Data Retention
    • Retention policies aligned with medical record requirements by jurisdiction
    • Secure, compliant data archiving for long-term medical records
    • Automated data deletion when retention periods expire
    • Special provisions for pediatric and geriatric record retention
    • Data lifecycle management specific to clinical documentation standards
    Clinical Data Processing
    • Processing limited to intended healthcare purposes
    • Secure analytics for population health insights
    • De-identified data use for research and development
    • Quality checks on AI-generated summaries before they reach clinicians
    • Secure federated learning techniques for model improvements
    Patient Data Rights
    • Patient access to personal health information
    • Correction mechanisms for inaccurate health data
    • Data portability between healthcare providers
    • Special handling for vulnerable populations and proxy access
    • Transparent record of all third-party data sharing

    Elderwise Healthcare Compliance Commitment:

    Our compliance strategy follows industry-standard "security by design" principles, embedding healthcare compliance requirements into our development process from inception to deployment. We recognize that healthcare data security directly impacts patient outcomes and provider efficiency, so our approach integrates technical safeguards with clinical workflow considerations to create a secure environment that enhances rather than impedes care delivery. Our compliance program emphasizes both regulatory adherence and the ethical responsibility we have to protect sensitive health information.