CirrusMD Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Services

CirrusMD provides a telemedicine platform that connects patients with healthcare providers in real-time, through web and mobile applications. Their service allows seamless interaction between patients and doctors, enabling users to consult on medical issues, receive guidance, and manage healthcare concerns without the need for in-person visits. This platform facilitates on-demand, text-based communication, ensuring accessible healthcare for employees and patients of CirrusMD's partners, such as employers, health insurers, and healthcare systems. These services also extend to healthcare professionals who use the system for tracking and managing patient care​​.

Security Program

CirrusMD protects its stakeholders and company assets through a comprehensive security program of policies, standards, and controls. Our HIPAA-compliant platform utilizes physical, technical, and administrative safeguards to ensure full adherence to federal and state privacy laws across the entire provider network. Moreover, CirrusMD maintains its security and privacy programs in alignment with industry standards, evidenced by certifications such as ISO27001 and SOC2 Type II. These certifications attest to the thoroughness in the design and implementation of the company's policies and safeguards, ensuring they meet or surpass industry norms and are adaptable to evolving threats.

Documents

REPORTSNetwork Diagram

Completed Security Questionnaires

We are working on our security compliance. We can provide completed questionnaires upon request.

Knowledge Base (FAQ)
  • Does your company's security awareness and training program document and ensure that all employees and contract workers have completed program requirements?
  • Does your company restrict access to buildings or areas where data is stored, transmitted, or processed based on role and only to authorized personnel (e.g., call centers, warehouses, loading docks, shredding facilities, data centers)?
  • Do you have a policy or procedure requiring at minimum weekly reviews of production systems' security event logs?
  • Has an onsite risk assessment of all locations providing services to Customers been conducted by an independent external third party within the past 24 months (e.g., SOC II Type 2, EHNAC, ISO 27001, HITRUST)?
  • Does your company manage mobile computing devices via a Mobile Device Management (MDM) tool or similar program? If yes, indicate whether the solution is internally or vendor managed in the comments section. Inclusive of company owned devices and BYOD if applicable.
View more
If you need help using this Trust Center, please contact us.
Contact support