HatchLink Health
LEGAL

Security Overview

By HatchLink Legal TeamLast Updated July 14, 2026

Last Updated: July 14, 2026

HatchLink takes the security of our customers’ data seriously. This page describes the administrative, physical, and technical safeguards we maintain to protect the HatchLink platform (the “Service”) and the data it processes. This Security Overview is incorporated into the HatchLink Master Terms by reference.

1. Compliance and Certifications

  • HIPAA. HatchLink operates as a Business Associate for HIPAA-covered customers and executes Business Associate Agreements (see hatchlinkhealth.com/baa). Our security program is designed to meet the administrative, physical, and technical safeguard requirements of the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).
  • FERPA and COPPA. HatchLink complies with FERPA and COPPA in its role as a school service provider. Our Student Data Privacy Addendum (see hatchlinkhealth.com/dpa) details our commitments with respect to student data.
  • HITRUST. HatchLink is pursuing HITRUST certification and the security and compliance framework was designed to be HITRUST compliant. Our documentation is available to customers under nondisclosure on reasonable request.
  • State Privacy Laws. HatchLink monitors and complies with applicable state data privacy and student data protection laws, including the Texas Data Privacy and Security Act, the Texas Student Privacy Alliance (TxSPA) commitments, and similar state frameworks applicable to our customers.

2. Infrastructure Security

  • Cloud Hosting. The Service is hosted on Amazon Web Services (AWS) in U.S. regions, with multi-Availability Zone redundancy for production workloads.
  • Network Isolation. Customer environments are isolated through Virtual Private Clouds (VPCs), security groups, and network access control lists. Production networks are segmented from development and corporate networks.
  • Encryption in Transit. All data transmitted between customers and the Service is encrypted using TLS 1.2 or higher. Internal service-to-service communications use encrypted channels.
  • Encryption at Rest. All Customer Data stored in databases, file storage, and backups is encrypted at rest using AES-256 encryption with AWS-managed or customer-managed keys.
  • Centralized Logging and Monitoring. Infrastructure and application events are centrally logged, monitored, and subject to automated alerting for security-relevant events. Logs are retained in accordance with our data retention policies and are protected against tampering.

3. Application Security

  • Access Control. The Service implements role-based access control (RBAC) with least-privilege defaults. Administrative access requires multi-factor authentication (MFA) and is restricted to authorized personnel.
  • Authentication. The Service supports single sign-on (SSO) integration and enforces strong password policies. Administrative and privileged access requires multi-factor authentication.
  • Secure Development. HatchLink follows a secure software development lifecycle (SDLC) that includes threat modeling, peer code review, automated static analysis, dependency vulnerability scanning, and pre-release security testing.
  • Penetration Testing. HatchLink engages qualified third-party security firms to conduct penetration testing at least annually. Findings are triaged, remediated on a risk-prioritized basis, and verified. Executive summaries of penetration test results are available to customers under nondisclosure on reasonable request.
  • Dependency Management. Third-party libraries and dependencies are monitored for known vulnerabilities and updated on a regular cadence. Critical and high-severity vulnerabilities are prioritized for expedited remediation.

4. Operational Security

  • Personnel Security. All employees and contractors with access to Customer Data undergo background checks prior to access being granted. Access is revoked promptly upon role change or departure.
  • Security Training. All personnel complete security awareness training at hire and annually thereafter. Personnel handling Protected Health Information or Student Data receive additional role-specific training on HIPAA, FERPA, and COPPA requirements.
  • Incident Response. HatchLink maintains a documented incident response plan that is reviewed and tested at least annually. The plan covers identification, containment, eradication, recovery, notification, and post-incident review.
  • Vulnerability Management. HatchLink operates a vulnerability management program with defined remediation timelines based on severity. Critical vulnerabilities are addressed within 24 hours of confirmation; high-severity within 7 days; medium within 30 days.
  • Change Management. Changes to production systems follow a documented change management process that includes peer review, testing, approval, and rollback procedures.

5. Data Handling

  • Tenant Isolation. Customer Data is logically segregated by tenant. Access controls enforce strict boundaries between customer environments.
  • Backups. Customer Data is backed up regularly. Backups are encrypted, stored in geographically separate locations, and tested periodically for integrity and recoverability.
  • Data Destruction. Upon termination of the Agreement, Customer Data is made available for export for forty-five (45) days. After that period, Customer Data is securely deleted from production systems using industry-standard methods. Backup copies age out in the ordinary course, consistent with our retention policies and applicable BAA or DPA obligations.
  • Data Minimization. HatchLink collects and retains only the data necessary to provide the Service and comply with legal obligations. Diagnostic and log data is retained for limited periods and does not contain unencrypted Protected Health Information.

6. Business Continuity and Disaster Recovery

  • Redundancy. Production infrastructure is deployed across multiple AWS Availability Zones to ensure continued availability in the event of a single-zone failure.
  • Recovery Objectives. HatchLink maintains recovery time and recovery point objectives appropriate to the criticality of the Service and the sensitivity of Customer Data. Specific objectives are available to enterprise customers on request.
  • Plan Testing. Business continuity and disaster recovery procedures are tested at least annually and updated based on test results and changes to the Service architecture.

7. Incident Response and Notification

HatchLink notifies affected customers of confirmed security incidents in accordance with Section 7.6 of the Master Terms—without unreasonable delay and in no case later than forty-eight (48) hours after confirmation. For incidents involving Protected Health Information, notification complies with the Business Associate Agreement timelines. For incidents involving Student Data, notification complies with the Student Data Privacy Addendum timelines and applicable state law (including any shorter notification periods required by state statute).

8. Reporting Vulnerabilities

If you discover a suspected security vulnerability in the Service, please report it responsibly to support@hatchlinkhealth.com. We acknowledge reports within two (2) business days and work in good faith to investigate and remediate confirmed vulnerabilities. We ask that you not publicly disclose a vulnerability until we have had a reasonable opportunity to address it.

9. Security Documentation Requests

Customers and prospective customers may request HatchLink’s current security documentation, including security questionnaire responses and penetration test executive summaries, by contacting support@hatchlinkhealth.com. Documentation is provided under nondisclosure obligations.

10. Governing Law and Dispute Resolution

This Security Overview is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to this Security Overview that is not resolved through good-faith negotiation will be brought exclusively in the state or federal courts located in Travis County, Texas, and each party consents to the personal jurisdiction and venue of such courts.

Governing Agreement. This Security Overview is part of the HatchLink Master Terms. In the event of any conflict between this Security Overview and the Master Terms, the Master Terms control. For questions about HatchLink’s security program, contact support@hatchlinkhealth.com.