
Managed Security
One security posture for every partner.
Because your data lives in Sirona's unified cloud, Sirona can carry the security process for you: integration reviews, compliance questionnaires, and the evidence health systems ask for, with a named point of contact.
How Sirona is Different
Sign contracts you couldn't sign before
The conversation with the health system goes well — then the security questionnaire arrives. Hundreds of questions on encryption, incident response, data residency, disaster recovery, SOC controls. Most practices can't answer half of them, and the deal stalls. With Sirona as the data platform, that review shifts to us: we answer the questionnaire, handle the integration review, and show the security posture. You qualify for contracts you couldn't qualify for alone.
Security managed end-to-end
Attestations, encryption, integration handling, monitoring, incident response, and audit support — all owned by Sirona, all inherited by every customer.
Active SOC 2 Type II Program
An active SOC 2 Type II program and HIPAA-aligned posture every customer inherits — a partner's security review runs against Sirona's platform posture, not gaps you have to remediate before a contract closes.
HIPAA BAA Included
HIPAA-compliant by default with a Business Associate Agreement on every contract. The BAA covers every Sirona application and every data flow through the platform.
AES-256 Encryption
AES-256 encryption at rest. TLS 1.2+ with strong ciphers for browser and API traffic; site integrations connect over encrypted VPN tunnels. Key management is handled through AWS KMS.
Integration Reviews Handled
When a health system requests a security review before integrating, Sirona responds directly — questionnaires, architecture diagrams, and security-testing evidence.
Continuous Logging & Monitoring
Changes to clinical information and integration flows are recorded in Sirona's unified event model — the same event stream the platform runs on — and monitored by Sirona, with managed threat detection on the roadmap. Owned by Sirona, not your IT department. Beyond the audit trail, Sirona captures detailed application event data, including session replays of how the application was used. We are making more of that data available through the Dashboard, and over time through the SDK and APIs.
A Named Point of Contact
Every customer gets a named point of contact on the Sirona implementation team — one person to go to for audit support, partner questionnaires, and incident communication.
What Sirona manages on your behalf
Integration Reviews
Health-system security questionnaires answered by Sirona
When you enter negotiations with a large health system, their security team sends a questionnaire — often hundreds of questions spanning encryption standards, access controls, incident response, data residency, disaster recovery, and SOC controls. Sirona's security team answers it directly, with architecture diagrams and security evidence on file. The practice doesn't have to become a compliance expert to close the deal. Sirona is the compliance expert, on your contract.
Sirona security team responds to partner questionnaires directly
Architecture diagrams and security evidence on file
One BAA with Sirona, covering your data across every partner
Practices close enterprise deals they couldn't qualify for alone
Continuous Compliance
A compliance posture maintained continuously
Security compliance isn't a document you file once — it's a posture that has to be demonstrated every day. Sirona runs an active SOC 2 Type II program and keeps HIPAA controls current across every module, so when a health system's compliance team asks for evidence, the answer is ready. Practices don't have to build a compliance program from scratch — they inherit Sirona's security posture the moment they onboard.
Active SOC 2 Type II program, maintained continuously
Attestation details shared with partners under NDA
HIPAA controls built into every module and data flow
Evidence available on demand — no scramble when partners ask
Incident Response
Incident response owned by Sirona, inherited by every customer
Small practices can't afford a dedicated security operations capability. Large practices often can, but duplicating it for every vendor relationship is impractical. Sirona owns incident response for the platform — logging and monitoring the infrastructure, investigating and containing issues, and communicating on HIPAA breach-notification timelines with full forensic detail. A fully staffed 24/7 SOC is part of the security roadmap. You don't staff incident response — you subscribe to it.
Continuous audit logging and monitoring across Sirona infrastructure
Incident triage, containment, and investigation handled by Sirona
HIPAA breach-notification timelines and communications owned by Sirona
Forensic detail and root-cause analysis provided to affected customers
Audit Support
When your customers audit you, Sirona shows up with you
Every health-system partner eventually audits its vendors. The partner sends questions, requests evidence, and sometimes schedules on-site walkthroughs. For traditional PACS deployments, the practice runs that audit alone — often without the information the auditor wants. With Sirona, the audit runs against Sirona's unified posture. Your Sirona point of contact helps prepare responses, supplies the security evidence, and joins the audit call if needed. Compliance review goes from a scramble to a process.
A named Sirona point of contact on every customer account
Partner audit responses coordinated between customer and Sirona
Security evidence supplied on demand
Joint audit calls with Sirona security engineers when customers need them
Security at enterprise scale
Active
SOC 2 Type II program — HIPAA controls platform-wide
1
security posture consolidating every health-system relationship
Continuous
audit logging and monitoring across all Sirona infrastructure
What customers say about working with Sirona
Bringing disparate sites together
“Sirona integrated with our outreach sites, which are very different sites, and they all have different processes. I'm happy to report that Sirona took care of it. I didn't really have to do any boots on the ground or any projects with it. Just their ability to communicate with a variety of different people that look at the world differently was quite remarkable... Since Sirona, I've seen the radiologists' attitudes and appreciation of work improve.”
Linda Masin
Director, Eastern Radiological Associates
How Dr. Luke Roller Built a Practice From Scratch
Dr. Luke Roller built his practice from scratch on Sirona alone — and explains why one unified platform was all he needed to start reading and extend access to care.
FAQs
What does Sirona actually manage under Managed Security?
How does Sirona help me close deals with large health systems?
What security attestations does Sirona maintain?
What do I remain responsible for as a Sirona customer?
What happens if there's a security incident?
What if we need additional certifications or international compliance coverage?