Orion Health

Certifications, security and compliance

Orion Health maintains a range of certifications, attestations and security practices that support the security, quality and compliance of our solutions and operations globally.

Certifications and attestations

Direct Trust Certification

DirectTrust is a non-profit association that establishes and promotes security and trust standards for the exchange of healthcare information. Our Communicate platform holds this robust, independent certification.

SOC 2 Type 2 Attestation

Orion Health holds SOC 2 Type 2 attestation for our healthcare platforms deployed in AWS and in a private data center in Alberta. All five Trust Service Criteria are in scope.

ISO 27001 Certification

Our global Information Security Management System (ISMS) is based on ISO 27001. Our UK & Ireland operations hold the ISO 27001 certification

HITRUST Certification

Our US-based Amadeus Healthcare platform holds the HITRUST R2 validated certification – one of the most stringent global frameworks demonstrating our compliance with HIPAA.

ENS Certification

Our Spanish operations are certified under the Esquema Nacional de Seguridad (ENS) at the High Level.

Cyber Essentials and Cyber Essentials Plus

Additional independent certifications reinforce our commitment to security.

Regional and additional compliance

Communicate ONC Health IT Certificate (2015 Edition)

Orion Health Communicate is ONC Health IT 2015 Edition compliant and has been certified by Drummond Group in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services.

Spain offices achieve ISO 14001, ISO 9001 and ENS – Esquema nacional de Seguridad certifications.

Explore Orion Health’s certifications in Spain, ensuring compliance and quality in healthcare solutions across the region

Carbon Reduction Plan - Orion Health (UK)

Orion Health (UK) have conducted a comprehensive measurement of their GHG emissions for the calendar year of 2023, encompassing Scope 1, Scope 2, and Scope 3 emissions. This report follows the internationally recognised GHG Protocol methodology for calculating and reporting greenhouse gas emissions.

Our approach to cybersecurity

Cybersecurity is integral to how we design, operate and support our applications and platforms. Our approach combines modern security tooling, regulatory compliance and continuous investment in system resilience.

We work with leading cybersecurity vendors to provide 24/7 breach detection and response across our cloud-hosted solutions and corporate IT environment.

Our security and privacy team proactively manages risk and follows rehearsed incident response plans, supported by digital forensics expertise when required.

We also support responsible security disclosure, providing a clear process for reporting potential vulnerabilities so they can be investigated and addressed.