Protected infrastructure
Application and data workloads use segmented cloud networks, encrypted transport and storage, and centrally managed secrets.
A factual overview of the safeguards used to protect Cognimark applications and authorized clinical data.
Last reviewed August 5, 2026
Security controls are applied across infrastructure, identity, software delivery, monitoring, and recovery instead of relying on a single product or boundary.
Application and data workloads use segmented cloud networks, encrypted transport and storage, and centrally managed secrets.
Managed authentication, application-specific authorization, organization boundaries, and explicit EHR identity links limit access.
Central audit records, threat detection, vulnerability scanning, and retained security evidence support investigation and response.
Infrastructure as code, short-lived deployment credentials, automated validation, and recovery testing govern production changes.
Cognimark maintains security and privacy controls intended to support its HIPAA Business Associate obligations and the SOC 2 Security criteria. Exact service scope, permitted uses, customer responsibilities, and contractual commitments are defined in the applicable agreements.
Use the anonymous reporting channel for suspected security, privacy, compliance, ethics, fraud, or workplace concerns. Use the business contact channel for product access and support. Do not place PHI, credentials, private keys, or exploit details in either public form; Cognimark will arrange a suitable channel for sensitive follow-up.