Free Network Build Assessment
Score your buildBlueprint is built for health plans that operate in regulated environments. Security isn't an afterthought — it's in the architecture.
Security Architecture
Encryption at Rest & in Transit
All data encrypted with AES-256 at rest. All traffic encrypted with TLS 1.3 in transit. Keys managed via hardware security modules.
Access Controls
Role-based access control (RBAC) at the user and team level. Granular permissions for Build Lead, Contracting, Credentialing, and Observer roles. SSO support.
Audit Logging
Every action in Blueprint is logged with user, timestamp, and IP. Full audit trail for regulatory reviews and internal compliance.
Infrastructure
Hosted on SOC 2 Type II certified cloud infrastructure. That certification belongs to our hosting providers, not to Blueprint — we'll name them and share their reports on request.
Incident Response
We notify affected customers within 72 hours of any confirmed breach. We're a small team, so you reach the people who run the system rather than an on-call rotation.
Data Retention & Deletion
Configurable retention policies. Data deletion upon contract termination within 30 days. Detailed data processing agreements available.
HIPAA
Provider data handled in Blueprint may include PHI. Blueprint is designed to support your organization's HIPAA obligations — with data isolation, access controls, BAA availability, and audit trails that your compliance team can rely on.
What's included
Compliance
| Standard | Status | Details |
|---|---|---|
| HIPAA | BAA Available | Business Associate Agreements available for Enterprise customers |
| SOC 2 Type II | Not yet | Blueprint has not completed its own SOC 2 audit. A Type II requires months of observed operating history, and we're a new product. Our infrastructure providers are certified; we are not going to describe that as ours. If your vendor-risk process requires a Blueprint SOC 2 report today, we will not pass it — ask us on the call and we'll tell you where we are. |
| NIST CSF | Aligned | Security controls mapped to NIST Cybersecurity Framework |
| CCPA | Compliant | California Consumer Privacy Act controls implemented |
| GDPR | Not Applicable | US-only customer base; GDPR controls not required |
Our team is happy to walk through our security documentation, answer your compliance team's questions, and provide a BAA if needed.