How we protect your clients’ data
Resonia is designed to meet healthcare privacy regulations in the United States, Canada, and the European Union. Here is what that means in practice.
Resonia meets HIPAA, PIPEDA, and GDPR compliance requirements with end-to-end AES-256 encryption, role-based access controls, audit logging, and signed Business Associate Agreements with all subprocessors.
Current Compliance Status
Resonia has implemented the security measures and compliance frameworks described on this page, and we continue to improve our security posture. We are not SOC 2 or ISO 27001 certified, and no certification audit is currently underway. Our infrastructure provider, Google Cloud, holds those certifications; Resonia itself does not. If your organisation requires a certified vendor, please talk to us before you sign up.
United States
HIPAA Compliant
HIPAA Compliance
Administrative Safeguards
- • Security Officer designation
- • Workforce training programs
- • Access management procedures
- • Incident response plan
Physical Safeguards
- • Facility access controls
- • Device & media controls
- • Workstation security
Technical Safeguards
- • Access control systems
- • Audit logs & monitoring
- • Integrity controls
- • Transmission security (TLS 1.3)
Business Associate Agreements available for covered entities
Canada
PIPEDA Compliant
PIPEDA Compliance
Privacy Principles
- • Accountability framework
- • Consent management system
- • Limited collection & use
- • Data accuracy measures
Provincial Compliance
- • Ontario PHIPA ready
- • Alberta HIA compliant
- • BC PIPA aligned
- • Quebec privacy laws
Data Residency
- • Canadian data centers available
- • Data sovereignty options
- • Cross-border transfer controls
Keep patient data within Canadian borders
Global
GDPR Ready
International Standards
GDPR Compliance
- • Lawful basis for processing
- • Data subject rights
- • Privacy by design
- • DPO consultation available
Global Best Practices
- • OWASP security standards
- • NIST framework aligned
- • Internal security reviews
Compliant operations across jurisdictions
Technical Security Measures
Multiple layers of security protect your data at every level
Encryption
- • AES-256 encryption at rest
- • TLS 1.3 in transit
- • End-to-end encryption for PHI
- • Encrypted backups
Access Control
- • Multi-factor authentication
- • Role-based permissions
- • Session management
- • IP allowlisting available
Monitoring
- • 24/7 security monitoring
- • Intrusion detection
- • Anomaly detection
- • Real-time alerts
Infrastructure
- • Hosted on Google Cloud, which is SOC 2 certified
- • Redundant systems
- • Automated backups
- • Disaster recovery plan
Audit & Logs
- • Audit trails on every PHI access
- • Immutable log storage
- • Regular compliance audits
- • Exportable reports
Key Management
- • Hardware security modules
- • Key rotation policies
- • Secure key storage
- • Cryptographic controls
Compliance Roadmap
Our commitment to continuous improvement
- • HIPAA technical safeguards implementation
- • End-to-end encryption deployment
- • Audit logging system
- • Consent management framework
- • Data retention policies
- • Advanced threat detection
- • SOC 2 Type II certification
- • Third-party penetration testing
- • HITRUST framework alignment
- • FedRAMP authorization
- • CJIS compliance
- • Additional regional certifications
- • AI/ML governance framework
Questions about compliance
Write to us and we’ll walk you through how Resonia meets your specific regulatory requirements.
Last updated: August 2026