2023 amwell hitrust certification letter.pdf
6175 Main Street Suite 400 Frisco, TX 75034
September 1, 2023
American Well, Inc. 75 State Street Floor 26 Boston, MA 02310
Based upon representation from management as to the accuracy and completeness of information provided, the procedures performed by an Authorized External Assessor to validate such information, and HITRUST's independent confirmation that the work was performed in accordance with the HITRUST® Assurance Program requirements, the following platforms, facilities, and supporting infrastructure of the Organization ("Scope") meet the HITRUST CSF® v9.6.2 Risk-based, 2-year (r2) certification criteria:
Platforms:
- Converge Platform residing at Amazon Web Services (AWS)
- Conversa application residing at Amazon Web Services (AWS)
- Home module residing at Evocative (fka INAP) and Navisite
- Hospital module residing at Amazon Web Services (AWS)
- SilverCloud platform residing at Amazon Web Services (AWS)
Facilities:
- Evocative (fka INAP) (Data Center) managed by INAP located in Santa Clara, California, United States of America
- Navisite (Data Center) managed by Navsite, LLC located in Andover, Massachusetts, United States of America
- Amazon Web Services (AWS) (Data Center) managed by AWS located in Oregon, Virginia, United States of America
The certification is valid for a period of two years assuming the following occurs. If any of these criteria are not met, HITRUST will perform an investigation to determine ongoing validity of the certification and reserves the right to revoke the Organization's certification.
- Annual progress is being made on areas identified in the Corrective Action Plan(s) (CAPs),
- No data security breach reportable to a federal or state agency by law or regulation has occurred within or affecting the assessed environment,
- No significant changes in the business or security policies, practices, controls, and processes have occurred that might impact its ability to meet the HITRUST Risk-based, 2-year (r2) certification criteria,
- Timely completion of the HITRUST Interim Assessment for r2 Certification as defined in the HITRUST Assurance Program Requirements.
HITRUST has developed the HITRUST CSF, a certifiable framework that provides organizations with the needed structure, detail and clarity relating to information protection. With input from leading organizations, HITRUST identified a subset of the HITRUST CSF controls that an organization must meet to be HITRUST Risk-based, 2-year (r2) Certified. For certain HITRUST CSF controls that were not being met, the Organization developed a CAP that outlined its plans.
HITRUST performed a quality assurance review to ensure that the control maturity scores were consistent with the results of testing performed by the Authorized External Assessor. Users of this letter can refer to the document Leveraging HITRUST Assessment Reports: A Guide for questions on interpreting this letter and can contact HITRUST customer support support@hitrustalliance.net. Users of this letter are assumed to be familiar with and understand the services provided by the organization listed above, and what specific services are being used by the user organization. A version of this letter with a more detailed scope description has also been issued by HITRUST which can also be requested from the organization listed above directly. A full HITRUST Validated Assessment Report has also been issued by HITRUST which can also be requested from the organization listed above directly. Additional information on the HITRUST Assurance Program can be found at the HITRUST website at https://hitrustalliance.net.