generated: '2026-08-15' method: searched source: >- Beacon Health homepage (https://www.beaconhealth.ai/), Privacy Policy (https://www.beaconhealth.ai/privacy, last updated 2026-08-04), Terms of Service (https://www.beaconhealth.ai/terms, last updated 2026-04-01), SMS Terms (https://www.beaconhealth.ai/sms-terms, last updated 2026-07-30), the Beacon Health trust center (https://trust.beaconhealth.ai/), the live OIDC discovery document at api.beaconhealth.ai, and DNS records for beaconhealth.ai. description: >- Beacon Health publishes no OpenAPI definition and no public API, so nothing here is derived from a spec. Every entry below is grounded in a claim the company publishes on its own site or in a record observed live. Absence of a claim is recorded as conforms:false with the reason, not as a failure. standards: - id: hipaa conforms: true evidence: >- Beacon Health states it processes Protected Health Information as a Business Associate under HIPAA and maintains administrative, physical and technical safeguards in accordance with the HIPAA Security Rule, with obligations governed by a Business Associate Agreement executed with each covered entity (Privacy Policy §4; Terms of Service §5). "HIPAA Compliant" is also asserted on the homepage. - id: hipaa-baa conforms: true evidence: >- "Our obligations regarding PHI are detailed in the Business Associate Agreement (BAA) executed with each covered entity." — Privacy Policy §4. Subprocessors handling PHI are also placed under BAAs (Privacy Policy §5). As of 2026-08-15 the trust center names the subprocessors: 8 in total, of which 2 are declared to process PII — Amazon Web Services (Patient Documents) and Convex (Application Data, Patient Data, Audit Logs). See security/beacon-health-trust-center.yml. - id: hipaa-security-rule-controls conforms: partial evidence: >- ADDED 2026-08-15. The trust center publishes a monitored control set mapped to a HIPAA Business Associate framework (declared IN_PROGRESS): 56 controls across 10 categories, 55 PASSING and 1 NEEDS_CHANGES. The one control not passing is "Adequate audit log storage maintained" (Monitoring & Incident Response), which is mapped to the HIPAA framework specifically. Encryption at rest and in transit, MFA on critical services, incident response policy, and annual penetration testing are all reported PASSING. This is the company's own self-attested control monitoring, not an audited result. source: security/beacon-health-trust-center.yml - id: pentest-annual conforms: true evidence: >- ADDED 2026-08-15. Trust center reports "Penetration testing performed within the last 12 months" and "Penetration testing findings remediated" both PASSING, mapped to SOC 2 and HIPAA. No pentest report or letter is published, so this is an assertion rather than reviewable evidence. source: security/beacon-health-trust-center.yml - id: subprocessor-disclosure conforms: true evidence: >- ADDED 2026-08-15. A named subprocessor list with per-vendor PII flags and service scope is published on the trust center — the disclosure a covered entity needs for HIPAA vendor diligence. Processing locations are left empty for every entry. source: security/beacon-health-trust-center.yml - id: oidc conforms: partial evidence: >- api.beaconhealth.ai serves a valid /.well-known/openid-configuration with an issuer and a working RSA JWKS, but the advertised authorization_endpoint returns 404 and no token endpoint is published — it is first-party application JWT metadata, not a usable OIDC provider for third parties. - id: oauth2 conforms: false evidence: >- No reachable /oauth/authorize or /oauth/token, no /.well-known/oauth-authorization-server, and no published client registration or developer credentials. - id: soc2 conforms: false status: in-progress evidence: >- UPGRADED 2026-08-15. Beacon Health now publishes a trust center at https://trust.beaconhealth.ai/ (its own subdomain, CNAMEd to trust.oneleet.com — the live counterpart of the "oneleet-domain-verification" TXT record recorded in the previous pass). The trust center lists SOC 2 with status IN_PROGRESS and soc2type UNSET. That is the company declaring an audit under way, not a certification: no Type I or Type II report, auditor name, or attestation letter is published, and the trust center offers no downloadable documents. conforms stays false; the program is recorded separately under compliance_program. source: security/beacon-health-trust-center.yml - id: iso-27001 conforms: false evidence: No ISO 27001 certification published. - id: pci-dss conforms: false evidence: Not applicable — Beacon Health does not process card payments. - id: fhir conforms: false evidence: >- Beacon Health explicitly does not integrate via healthcare data standards. Its agents drive EHR user interfaces directly ("Beacon navigates and operates real EHR systems, just like a human"), so there is no FHIR, HL7v2 or DICOM surface. - id: hl7v2 conforms: false evidence: See fhir — the integration model is UI automation, not data exchange. - id: rfc9457-problem-details conforms: false evidence: No public API and no published error contract. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on both www.beaconhealth.ai and api.beaconhealth.ai. trust.beaconhealth.ai answers 200 to that path but with its 604-byte single-page-app HTML shell, which it returns for every path — a soft 200, not a security.txt. Re-verified 2026-08-15. Note that a security CONTACT does now exist (security@beaconhealth.ai, published on the trust center); it is simply not advertised at the RFC 9116 location. - id: tcpa-sms-consent conforms: true evidence: >- ADDED 2026-08-15. Beacon Health publishes an SMS Terms & Messaging Policy (https://www.beaconhealth.ai/sms-terms, last updated 2026-07-30) and a patient opt-in page (https://www.beaconhealth.ai/sms-opt-in). The policy states practices must obtain written or electronic consent compliant with the Telephone Consumer Protection Act before messaging, documents STOP/HELP keywords, states consent is not a condition of care, and commits that mobile opt-in data is never shared with third parties (Privacy Policy §6). Beacon Health operates messaging on the practice's behalf; the practice remains the consent holder. - id: dmarc conforms: true evidence: >- _dmarc.beaconhealth.ai publishes "v=DMARC1; p=none; rua=mailto: dmarc-reports@beaconhealth.healthcare; pct=100" — present but in monitor-only mode (p=none), not enforcing. - id: spf conforms: false evidence: No SPF record on beaconhealth.ai. - id: dnssec conforms: false evidence: No DS record for beaconhealth.ai. - id: caa conforms: false evidence: No CAA record for beaconhealth.ai. - id: hsts conforms: true evidence: >- www.beaconhealth.ai returns Strict-Transport-Security with max-age=63072000 (2 years) over TLSv1.3. compliance_program: published: true posture: >- HIPAA Business Associate. Beacon Health publicly commits to HIPAA Security Rule safeguards and executes a BAA with each covered entity. As of 2026-08-15 it also runs a public trust center at https://trust.beaconhealth.ai/ carrying a 56-control monitored control set, a named 8-vendor subprocessor list, and a security contact. Both frameworks it tracks — SOC 2 and HIPAA Business Associate — are declared IN_PROGRESS. It still publishes NO completed third-party audit attestation: no SOC 2 report, no ISO 27001, no HITRUST, and no downloadable documents of any kind. url: https://trust.beaconhealth.ai/ trust_center: https://trust.beaconhealth.ai/ trust_center_artifact: security/beacon-health-trust-center.yml secondary_trust_center: url: https://trust.delve.co/beacon-health reached_via: https://www.beaconhealth.ai/security status: 429 note: >- The site's own /security route 307-redirects here, but the page is behind a Vercel bot challenge and could not be read. Two trust surfaces exist and we can read only the Oneleet one. certifications: [] frameworks_in_progress: [SOC 2, HIPAA Business Associate] controls_monitored: 56 controls_passing: 55 subprocessors_disclosed: 8 contacts: privacy: privacy@beaconhealth.ai legal: legal@beaconhealth.ai security: security@beaconhealth.ai support: support@beaconhealth.ai