Orion Health
Certifications, security and compliance
Orion Health maintains a range of certifications, attestations and security practices that support the security, quality and compliance of our solutions and operations globally.
Orion Health
Orion Health maintains a range of certifications, attestations and security practices that support the security, quality and compliance of our solutions and operations globally.
DirectTrust is a non-profit association that establishes and promotes security and trust standards for the exchange of healthcare information. Our Communicate platform holds this robust, independent certification.
Orion Health holds SOC 2 Type 2 attestation for our healthcare platforms deployed in AWS and in a private data center in Alberta. All five Trust Service Criteria are in scope.
Our global Information Security Management System (ISMS) is based on ISO 27001. Our UK & Ireland operations hold the ISO 27001 certification
Our US-based Amadeus Healthcare platform holds the HITRUST R2 validated certification – one of the most stringent global frameworks demonstrating our compliance with HIPAA.
Our Spanish operations are certified under the Esquema Nacional de Seguridad (ENS) at the High Level.
Additional independent certifications reinforce our commitment to security.
Orion Health Communicate is ONC Health IT 2015 Edition compliant and has been certified by Drummond Group in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services.
Explore Orion Health’s certifications in Spain, ensuring compliance and quality in healthcare solutions across the region
Orion Health (UK) have conducted a comprehensive measurement of their GHG emissions for the calendar year of 2023, encompassing Scope 1, Scope 2, and Scope 3 emissions. This report follows the internationally recognised GHG Protocol methodology for calculating and reporting greenhouse gas emissions.
Cybersecurity is integral to how we design, operate and support our applications and platforms. Our approach combines modern security tooling, regulatory compliance and continuous investment in system resilience.
We work with leading cybersecurity vendors to provide 24/7 breach detection and response across our cloud-hosted solutions and corporate IT environment.
Our security and privacy team proactively manages risk and follows rehearsed incident response plans, supported by digital forensics expertise when required.
We also support responsible security disclosure, providing a clear process for reporting potential vulnerabilities so they can be investigated and addressed.