INFORMATION SECURITY
An enterprise solution to protect healthcare data
If you have a question or concern or if you would like to request additional documentation regarding these certifications, email security@phreesia.com.
Privacy and Security in Healthcare
At Phreesia, privacy and security are our top priorities–not boxes to be checked during a once-a-year review. At each and every level of our organization, we foster a culture focused on safeguarding patient data. We’re honored to have those efforts recognized with many of the industry’s most well-known certifications.
HITRUST CSF Certification (2024)
Phreesia achieved HITRUST CSF certification, giving our clients peace of mind that we meet trusted security benchmarks.
Payment Card Industry Data Security Standard (PCI-DSS)
As a PCI DSS Level 1 Service Provider, Phreesia is committed to upholding industry security standards for cardholder data.
Security Organization Control (SOC) 2 Type 2
Phreesia has completed the SOC 2 Type 2 certification process to evaluate our security, availability and confidentiality protocols.
PCI Point-to-Point Encryption (P2PE)
Phreesia’s PCI-validated solution enables healthcare organizations to accept P2PE credit and debit card payments.
Find Phreesia listed under Bluefin Payment systems
View our responsible disclosure statement.
Responsible Vulnerability Disclosure Policy
This information is intended for security researchers who are interested in reporting vulnerabilities to Phreesia’s security team. For all other issues and inquiries, including sales and client support questions, please visit our Contact Us page.
Phreesia does not consent to ad-hoc security testing nor authorize active scanning of the Phreesia infrastructure and environment.
If you think you have identified a vulnerability, we ask that you contact us at security@phreesia.com as soon as possible and refrain from disclosing the issue to other parties until we address it. When we receive an issue we will evaluate it and, if we agree it is a vulnerability, we’ll work to fix it and release the fix in a timeframe that matches the severity. Phreesia does not offer a bug bounty program at this time.