Care Evolution Logo Care Evolution

Regulatory standards

HITRUST e1 Certification

The Orchestrate™ data engine and Discover ecosystem (including MyDataHelps™) hold active HITRUST e1 certifications, standardizing data protection controls across global health regulations.

NIST SP 800-53 Rev. 5

Our core system architecture maps directly to federal privacy and security controls. Compliance is continuously verified through independent assessments by a certified Third-Party Assessment Organization (3PAO).

Digital Medicine Society (DiMe) Seal

MyDataHelps carries independent validation confirming the highest standards of evidence, usability, privacy, and safety.

HIPAA & Global Privacy Frameworks

We safeguard Protected Health Information (PHI) under the same strict security baselines required by enterprise EHR systems, maintaining full compliance with HIPAA, GDPR, and the EU-U.S. Data Privacy Framework.

NIH Authorization to Operate (ATO)

Formally authorized by the National Institutes of Health to securely ingest and manage large-scale digital phenotypes for national research initiatives.

FDA 21 CFR Part 11

Our platform enforces the necessary technical controls for electronic records, audit trails, and signatures, taking backend compliance friction out of digital clinical trials.

Privacy policies

We maintain absolute transparency regarding how data is managed, shared, and protected across our ecosystem. Review our specific privacy policies to see how we safeguard data and keep individuals in control of their information:

Applies to study participants volunteering health data and individuals managing records through our consumer applications.

Applies to clinical research teams, PIs, and coordinators configuring and managing trials through our no-code builder.

Applies to developers, architects, and data scientists utilizing our data ingestion and standardization tools.

Applies specifically to user interactions and data privacy across our primary website.

Security research program

We minimize systemic risk by collaborating with independent security experts to identify vulnerabilities and manage threats. We welcome proactive testing conducted under our established guidelines.

Learn more