HippoHandover

Compliance Statement

Version 2026.05.02 · Effective 2026

Plain-English statement: HippoHandover is not currently SOC 2 certified. SOC 2 is an external audit performed by a CPA firm and is on our roadmap. PHIA is not a certification anyone can buy — it is a regulatory framework we comply with through documented controls. Compliance with your institution's privacy policy remains your responsibility and your institution's.

1. Controls in place today

2. SOC 2 Trust Service Criteria — current self-assessment

This is a self-assessment, not an audited opinion. We map current controls to SOC 2 criteria so an institution's privacy/security team can quickly gauge fit:

3. PHIA alignment

4. Your institution's responsibility

5. Roadmap

6. Reporting a vulnerability

Email security@hippomedicine.com with reproduction steps. Acknowledged within 48 hours.