SECURITY & TRUST

Built to handle patient records

Hubble retrieves patients' medical records, so security and compliance are built in from day one.

HIPAA-compliant from day one

Scoped permissions and full audit trails are built in, so compliance teams have what they need without extra work. We sign a BAA on request.

Verified patient identity

Every request is tied to a verified individual. Patients prove their identity to NIST IAL2 through Persona, a government ID plus a liveness check, before any record is released.

Patient-authorized consent

Retrieval runs on the HIPAA individual right of access. Consent is scoped to what the patient approves and can be revoked at any time.

Encrypted end to end

Records are encrypted in transit and at rest, with least-privilege access controls across the platform.

Full audit trail

Every retrieval and agent action is logged, so there is a complete, reviewable trail of who accessed what and when.

SOC 2 Type II in progress

We are actively pursuing SOC 2 Type II. Reach out for the current status and our security package.

Get in touch

Reach our team at privacy@hubble.ai. For how patient data is handled, see our Privacy Policy.

Want the security package?

Book a demo and we will walk through security, compliance, and how retrieval works on your use case.