generated: '2026-08-22' method: searched probe: true url: https://policy.holmusk.com/ title: Holmusk HIPAA Compliance Policies source: https://policy.holmusk.com/ note: >- Holmusk does not run a conventional "trust center" (trust.holmusk.com does not resolve; holmusk.com/trust, /security and /compliance all return 404). What it does publish — openly, with no login — is its full HIPAA compliance policy set at policy.holmusk.com: ~176,000 characters covering policy management, risk management, roles, data management, system access, incident response, breach notification, business continuity, configuration management and vulnerability management, each section mapped to the HITRUST Common Security Framework control and the HIPAA Security Rule citation it satisfies. That is a stronger public compliance artifact than most trust pages, so it is recorded here. certifications: - name: HITRUST CSF status: claimed evidence: >- "current production systems on this platform are included in Holmusk's third-party audits and HITRUST compliance" — policy.holmusk.com §1.2 Compliance Inheritance. Every policy section lists "Applicable Standards from the HITRUST Common Security Framework". - name: HIPAA / HITECH status: claimed evidence: >- Policy set is structured as HIPAA Security Rule + HITECH Act control mappings (e.g. 164.316(b)(1)(i), 13402(a)/(b)); Holmusk operates as a HIPAA business associate for customer ePHI. not_claimed: - name: SOC 2 note: >- SOC 2 appears on policy.holmusk.com only as something Holmusk REVIEWS in its vendors ("annual assessment of SOC2 reports for all Holmusk infrastructure partners"). Holmusk does not claim a SOC 2 report of its own anywhere public, and it is not recorded as one here. - name: ISO 27001 note: Not mentioned on any public Holmusk surface probed on 2026-08-22. audit_reports: public: false detail: >- "Holmusk, at its sole discretion, shares audit reports, including its HITRUST reports and Corrective Action Plans (CAPs), with customers on a case by case basis. All audit reports are shared under explicit NDA." — policy.holmusk.com §1.4 hosting: provider: Amazon Web Services detail: Production infrastructure hosted on AWS; nginx web servers with Haskell, Java and NodeJS application servers (policy.holmusk.com §1.3). evidence: - source: https://policy.holmusk.com/ status: 200 keywords: [hipaa, hitrust, hitech, penetration testing, incident response, breach] - source: https://trust.holmusk.com/ status: DNS NXDOMAIN - source: https://www.holmusk.com/security status: 404 - source: https://www.holmusk.com/trust status: 404