generated: '2026-08-27' method: searched source: https://www.oracle.com/corporate/cloud-compliance/ docs: https://www.oracle.com/corporate/cloud-compliance/ description: >- Trust and compliance surface available to an Oracle Health Data Intelligence buyer. Oracle publishes a corporate cloud-compliance registry naming the attestations it holds. There is no product-scoped trust center for Health Data Intelligence, and no artifact request portal is linked from the developer documentation. trust_center: published: true scope: corporate url: https://www.oracle.com/corporate/cloud-compliance/ probed_status: 200 observed: '2026-08-27' secondary_url: https://www.oracle.com/trust/ secondary_probed_status: 200 secondary_note: >- oracle.com/trust renders client-side; no certification name is present in the served HTML, so the compliance registry above is the readable source. certifications: - name: HIPAA scope: Oracle cloud services evidence: named in the Oracle cloud-compliance registry - name: HITRUST CSF scope: Oracle cloud services evidence: named in the Oracle cloud-compliance registry - name: SOC 2 scope: Oracle cloud services evidence: named in the Oracle cloud-compliance registry - name: ISO/IEC 27001 scope: Oracle cloud services evidence: named in the Oracle cloud-compliance registry - name: FedRAMP scope: Oracle US government cloud regions evidence: named in the Oracle cloud-compliance registry - name: PCI DSS scope: Oracle cloud services evidence: named in the Oracle cloud-compliance registry gaps: - >- No Health Data Intelligence-specific attestation scope statement. A buyer cannot tell from public material which of the corporate certifications cover this platform's regions and services. - No self-serve artifact request portal (no Whistic, Vanta, Drata or equivalent). - No subprocessor list or data-residency page linked from the developer portal. - >- Data residency is nonetheless material here: the platform is deployed as Oracle Cerner Cloud Regions (us-1, emea-1, emea-2, ca-1, ap-1) and the region is part of the API hostname, so residency is observable from the base URL even though it is not documented as a compliance control.