Shasta HealthTrust Center

Trust Center

Security and compliance information, all in one place.

HIPAA powered by Vanta

HIPAA

HIPAA compliance monitored by Vanta.

Controls

Selected HIPAA controls with passing evidence in Vanta

View all controls →
  • Data backup plan implemented✓ Passing
  • Access controls applied✓ Passing
  • Security incident procedures implemented✓ Passing
  • Audit controls implemented✓ Passing

Subprocessors

Amazon Web ServicesCloud infrastructure and storage.
Google CloudCloud services and Gemini AI models.
Microsoft AzureCloud-hosted AI services.
OpenAIAI model processing.
VapiAI-powered voice calls.
TwilioPhone and text messaging.
Twilio SendGridEmail delivery.
StediInsurance eligibility checks.
PostHogProduct analytics.
StripePayment processing.

Frequently asked questions

How do I request a document?

Select the documents in the section below and submit the request form. Our team will follow up by email.

How do I get a Business Associate Agreement?

We provide a Business Associate Agreement directly to each customer. Contact your Shasta Health representative if you need another copy.

Where can I find information about data retention and deletion?

Request the Data Management Policy, or contact privacy@shasta.health with questions about your agreement.

How does Shasta handle security incidents?

You can request our Incident Response Plan and HIPAA Breach Notification Procedures in the Documents section below.

How do I report a security concern?

Email privacy@shasta.health so our team can review it.

Documents

Select the documents you would like to access. Business Associate Agreements are provided directly to each customer.

Data Management Policy

Policies

Access Control Policy

Policies

Incident Response Plan

Policies

HIPAA Breach Notification Procedures

Policies

Third-Party Management Policy

Policies

Access request

Select documents above, then tell us where to follow up.

Select at least one document.

Please don't include patient information.