Solutions · Healthcare

HIPAA-grade PKI for clinical and connected care.

Electronic health records, medical devices, telehealth platforms, and clinical partner integrations all encrypt PHI in flight. TigerTrust automates the certificates that protect it — and generates the HIPAA §164.312 evidence continuously.

The problem

A HIPAA breach averages $11 million and 279 days.

Health systems run thousands of endpoints — infusion pumps, MRIs, telehealth kiosks, EHR gateways — each needing valid certificates. One expired cert on a clinical channel is either an outage that delays care or a PHI exposure that lands on the OCR breach portal.

Without healthcare PKI
  • Legacy medical devices ship with default certs that never rotate
  • Expired HL7/FHIR gateway certs sever EHR interop mid-treatment
  • Telehealth platforms serve stale TLS — one JAMA article away from a lawsuit
  • HIPAA §164.312 evidence gathered by hand every audit cycle
  • BAA-scoped systems mixed with commercial workloads on the same CA
With TigerTrust healthcare PKI
  • Device-class policies for medical equipment with long refresh cycles
  • Zero-downtime HL7/FHIR gateway rotation with pre-flight validation
  • TLS 1.3 enforced across telehealth and patient-portal channels
  • HIPAA §164.312(a)(2)(iv) and (e)(1) evidence generated continuously
  • PHI-scoped CAs and audit logs; BAA covers the platform operations
PHI protection

Encryption of PHI everywhere it travels

Enforce TLS 1.3 with approved ciphers across EHR gateways, HIE connections, and patient portals. Block anything that could carry ePHI over a weak channel.

How it works
  • HIPAA Security Rule §164.312 aligned
  • TLS 1.3, strong-cipher-only policies
  • PHI-scoped issuance profiles
  • DirectTrust interop for HIE traffic
Clinical staff reviewing secure patient records
Medical devices

Certificates for the fleet in the ward

Infusion pumps, imaging systems, monitors, and pacemakers each get an identity. Device-class policies respect long clinical refresh cycles without leaving weak crypto in the field.

How it works
  • Device-class issuance templates
  • FDA 21 CFR 820 / IEC 62304 aligned
  • Long-lived leaf certs with short rotation on trust anchors
  • Air-gapped signing for legacy device onboarding
Clinical staff working with connected medical equipment
Interoperability

HL7, FHIR, and DirectTrust without cert drama

Automated rotation and monitoring across EHR interop endpoints. HIE partners, DirectTrust accreditation, and cross-BAA connections all covered.

How it works
  • HL7 v2 and FHIR gateway rotation
  • DirectTrust anchor bundle management
  • HIE partner cert lifecycle
  • Pre-flight validation before deploy
Healthcare data interoperability across systems
Audit & compliance

HIPAA and HITRUST evidence, continuously

Auditors ask for encryption controls, access logs, and rotation history. TigerTrust ships them as signed evidence packs mapped to HIPAA §164.312 and HITRUST CSF domains.

How it works
  • HIPAA §164.312 evidence bundle
  • HITRUST CSF domain mapping
  • Access-and-audit logs for PHI paths
  • BAA-covered platform operations
Healthcare compliance team preparing an audit package
For clinical environments

The controls a CISO in healthcare needs. Without touching clinical workflow.

Deploy without asking clinicians to change how they work.

HIPAA §164.312
Technical safeguards for PHI at rest and in transit.
  • Access control mapping
  • Transmission security
  • Audit log evidence
Medical device fleet
Certificates for the entire connected-device estate.
  • Device-class policies
  • Legacy-friendly onboarding
  • Long refresh cycles
BAA-covered operations
Business Associate Agreement covers our platform.
  • PHI-scoped tenancy
  • Encrypted at rest
  • US-region only
HL7 / FHIR interop
Zero-downtime rotation on EHR and HIE gateways.
  • Pre-flight checks
  • Partner cert tracking
  • Rollback on failure
HITRUST CSF
Framework mapping for accreditation and renewal.
  • Domain 09 controls
  • Assessor evidence
  • Continuous posture
Breach avoidance
Anomaly detection on issuance and revocation.
  • SIEM integration
  • PHI-path monitoring
  • OCR-ready incident logs

From healthcare deployments

$11M
Average HIPAA breach avoided
164.312
HIPAA controls automated
0
Clinical outages from cert expiry
100%
BAA-covered operations
Case study
Top-100 · Hospital system

Zero clinical outages from cert expiry across 42 hospitals.

Our infusion pumps and imaging systems ship with certs that live 10 years. TigerTrust device-class policies gave us a way to bring them under management without a rip-and-replace we could not fund.
Deputy Chief Information Security Officer
42
Hospitals under management
0
Clinical outages from expiry
100%
BAA-covered operations
Integrations

Fits your existing stack

EHR platforms, interop standards, HSMs, and clinical device toolchains healthcare providers already run on.

Epic
EHR
Cerner Oracle Health
EHR
MEDITECH
EHR
HL7 v2 / FHIR
Interop
DirectTrust
HIE
CommonWell
HIE
Thales Luna
HSM
AWS CloudHSM
HSM
Okta / Azure AD
IdP
ServiceNow HRSD
ITSM
Splunk
SIEM
Medigate / Claroty xDome
Medical device inv
FAQ

Frequently asked questions

HIPAA §164.312(a)(2)(iv) (encryption of ePHI) is covered by PHI-scoped issuance profiles requiring HSM-backed keys and approved cipher suites. §164.312(e)(1) (transmission security) is enforced through mTLS policy across HIE, HL7, and FHIR channels. Access-and-audit logs meet §164.312(b) requirements. Evidence packs export in the format your OCR audit workpapers expect.
Yes. Device-class policies distinguish clinical equipment (infusion pumps, MRIs, monitors, ventilators) from IT systems. Leaf certificates can live longer to match device refresh windows, while trust anchors rotate on your policy. Air-gapped signing supports legacy device onboarding where the device itself cannot participate in a modern CSR flow. FDA 21 CFR 820 and IEC 62304 documentation practices are respected.
Yes. TigerTrust signs a Business Associate Agreement covering platform operations. PHI-scoped tenancy, US-region-only deployment options, encryption at rest, and access controls satisfy the covered-entity requirements. The vendor risk questionnaire packet is pre-built and includes HITRUST-inherited controls from the underlying cloud infrastructure.
Pre-flight validation confirms the new certificate parses, chains, and would be accepted by the peer. Rotation happens with a canary target that mirrors real gateway traffic. If validation fails, the previous cert stays live and on-call is notified. If it passes, cutover proceeds and rollback is armed for the next 24 hours. HIE partners do not see a broken TLS session mid-treatment.
TigerTrust ships pre-mapped for HITRUST CSF domains, including Domain 09 (Transmission Protection) and Domain 06 (Configuration Management). Continuous posture reports feed the CSF assessment cycle. Underlying platform controls are HITRUST-inherited from FedRAMP-authorised cloud infrastructure so covered entities can reduce their own assessment scope.
Yes. TigerTrust integrates with Medigate, Claroty xDome, Armis, and other clinical asset inventory platforms so device metadata flows into cert ownership. Alerts route to the biomed engineering team owning the specific device, not a generic IT queue. Discovery agents also passively identify uninventoried devices before they cause an audit finding.

Protect PHI without interrupting care.