Certifications and Accreditations
Independent validation for every layer of trust
In healthcare, trust isn't assumed — it's proven. Every certification and accreditation on this page represents independent, third-party validation that Centauri's people, processes, and technology meet the standards required to protect sensitive health information and exchange it safely across the healthcare ecosystem.
Below is an overview of the certifications and accreditations that govern our platform today.
HITRUST® CSF Certification
Centauri’s entire technology platform and every application on it are HITRUST® CSF Certified (v.11.4).
HITRUST® CSF Certification is widely regarded as the healthcare industry’s most rigorous, independently assessed security framework. It maps our controls to more than 40 authoritative sources — including HIPAA, NIST, ISO, and COBIT — so a single assessment demonstrates compliance across multiple regulatory and industry standards at once. Certified status confirms that Centauri has met key regulatory and industry-defined requirements and is appropriately managing information risk, consistent with the NIST Cybersecurity Framework.
Protecting PHI and other sensitive information is a foundational design principle of our platform, not an afterthought layered on top of it. Our HITRUST CSF and NIST Cybersecurity Framework alignment give customers and partners independent confirmation of that commitment.
DirectTrust Accreditation
Centauri is accredited by DirectTrust as a Health Information Service Provider (HISP), Certificate Authority, and Registration Authority.
DirectTrust accreditation confirms our compliance with the Applicability Statement for Secure Health Transport (45 CFR 170.202) — the standard adopted by the U.S. Department of Health and Human Services for the secure transmission of health data — as well as the industry-adopted standards for trusted, federated exchange of PHI among participants across the U.S. healthcare ecosystem.
Notably, DirectTrust accreditation also includes independent verification of compliance with the HIPAA Privacy and Security Rules. It is the only accreditation in healthcare that explicitly and verifiably attests to HIPAA compliance, rather than relying on self-attestation alone.
SOC 2 Type II Audited Infrastructure
Centauri’s technology platform and all applications run exclusively on infrastructure providers AWS and GCP, both of which meet AICPA SSAE 18 standards and hold SOC 2 Type II reports.
A SOC 2 Type II report differs from a point-in-time review: it evaluates the design and operating effectiveness of controls over an extended period, across the trust principles that matter most for health data — confidentiality, privacy, security, integrity, and availability. Building exclusively on SOC 2 Type II–audited infrastructure gives Centauri a continuously validated security foundation to build on.
ONC-HIT Certification
Our Direct platform is certified by the Office of the National Coordinator for Health Information Technology (ONC-HIT) as compliant with the federal standards established at 45 CFR 170.315 for the secure, encrypted, trusted exchange of PHI among verified healthcare providers, vendors, and health plans.
Through the ONC-Authorized Certification Body (ONC-ACB) program, Centauri regularly attests to continued compliance with the federal data transport standards set by ONC-HIT — an ongoing obligation, not a one-time achievement.
CMS Aligned Network
Centauri participates in a CMS-aligned Qualified Health Information Network® (QHIN™), operating under the Trusted Exchange Framework and Common Agreement (TEFCA®).
QHIN™ participation connects Centauri to a nationwide, federally recognized exchange framework, enabling standardized, trusted data exchange with other QHINs, health systems, and government agencies under a single common set of rules — rather than a patchwork of one-off connections.
Why Independent Validation Matters
Across the health data industry, the organizations trusted to move the most sensitive information — health intelligence networks, data platforms, and analytics providers alike — converge on the same core set of independent validations: HITRUST® certification for enterprise-wide security assurance, DirectTrust and/or EHNAC accreditation for secure health information exchange, and annual SOC 2 Type II audits for infrastructure and operational controls. Some also pursue ONC-HIT certification and QHIN™/TEFCA® participation where their platforms directly support federally regulated data exchange.
Centauri holds all of these simultaneously — HITRUST® CSF, DirectTrust, ONC-HIT, SOC 2 Type II, and QHIN™ participation — because each addresses a different layer of trust: platform-wide security management, secure transport and identity, federal interoperability standards, infrastructure control effectiveness, and nationwide exchange governance. Together, they give our customers and partners independently verified assurance, at every layer of the platform, that their data is being protected and exchanged the way they expect.