generated: '2026-07-19' method: searched source: https://hellopatient.com/blog docs: https://hellopatient.com/privacy-policy standards: - id: soc2-type2 conforms: true evidence: 'Blog post "Hello Patient is now SOC 2 Type 2 certified" (2026-07-16); SOC 2 Type 2 stated on homepage and product pages.' - id: hipaa conforms: true evidence: 'Privacy policy states HIPAA compliance and Business Associate Agreements (BAAs) with healthcare partners and vendors to protect PHI.' - id: gdpr conforms: true evidence: 'Privacy policy names an EU/UK data-subject representative (Euverify Ltd) with a secure DSAR portal.' - id: ccpa conforms: true evidence: 'Privacy policy documents CCPA rights (know, delete, opt-out) and states personal information is not sold.' - id: iso27001 conforms: false evidence: 'No published ISO 27001 certification found.' - id: pci-dss conforms: false evidence: 'No published PCI DSS certification found; not a card acquirer.'