Trust & Compliance

Security at Lillia

How we protect patient information, who we share it with, and where we are on independent validation.
Last updated 16 August 2026
Lillia is built around health-data privacy from the ground up. Patient information is encrypted, access-controlled and audited; client data is hosted in the region agreed with each client; and we sign a data processing agreement — including a HIPAA Business Associate Agreement where US law applies — before any patient data moves. Our independent validation programme is underway and dated below.
Live control status and documents Our Trust Center shows the current state of our security controls, monitored continuously, and lets you request documentation directly.
Open Trust Center

How we protect patient data

The controls below are in place today.

Regional data residency

Client data is hosted and processed in the region agreed with each client — currently the United States and Qatar. Deployments are region-specific, so data stays in its agreed region.

Encryption

Patient information is encrypted in transit and at rest.

Access control

Role-based access with least privilege, and multi-factor authentication enforced for access to systems handling patient information.

Auditability

Clinical and administrative actions are recorded in an audit trail.

Continuous monitoring

Our control environment is monitored continuously through Sprinto — a living programme rather than a point-in-time exercise.

Testing

Vulnerability scanning and internal penetration testing run on an ongoing basis, with an independent third-party test scheduled.

Our privacy and security programme

Regional legal frameworks

Our agreements are structured as a single data processing agreement with the annex that applies to your jurisdiction.

United States

HIPAA and the HITECH Act. We execute a Business Associate Agreement containing the provisions required by 45 CFR §164.504(e), and we hold a HIPAA Business Associate Agreement with our cloud provider.

State of Qatar

Law No. 13 of 2016 on Personal Data Privacy Protection. We act as a processor on the controller's instructions, with data held in-region and additional protection for health data.

Our data processing agreement Read our standard agreement, including the HIPAA Business Associate Agreement for US clients, before you request it. We are equally happy to work from your paper.
View agreement

Artificial intelligence and patient data

We are an AI platform, so we think this deserves a direct answer rather than a footnote.

Independent validation

We believe in saying plainly what is complete and what is scheduled.

In place
HIPAA security programme with continuous control monitoring
Documented risk assessment, policies, incident response and evidence maintained in Sprinto.
In place
Business Associate Agreements across the data path
Executed with our cloud and AI providers, and with every client before patient data moves.
October 2026
External HIPAA attestation
Independent examination performed by a CPA firm.
October 2026
Independent penetration test
Third-party assessment, with an attestation letter available to clients afterwards.
November 2026
SOC 2 Type II audit
Audit fieldwork in late November, following a three-month control observation period.
December 2026
SOC 2 Type II report issued
Available to clients and prospective clients under NDA once issued.

Working with us

Data processing agreement

We sign a data processing agreement before any patient information is exchanged — with a HIPAA Business Associate Agreement annexed where US law applies, and the equivalent annex for Qatar. We are happy to use our template or yours.

Security questionnaires

We complete client and network vendor security assessments, including standard formats. We acknowledge within one business day and return completed assessments within ten business days.

Documentation available under NDA

Our security overview, HIPAA control mapping, architecture and data-flow documentation, sub-processor register and — as each is issued — our attestation letters and SOC 2 report. Requests can be made through our Trust Center.

Reporting a security concern

If you believe you have found a security issue affecting Lillia, please contact us at security@lilliacare.ai. We investigate every report and will acknowledge receipt.

Request our security documentation

See our live control status and request documents through the Trust Center, or tell us what your review needs and we will send the relevant material under NDA — usually within one business day.