Managed Security

One security posture for every partner.

Because your data lives in Sirona's unified cloud, Sirona can carry the security process for you: integration reviews, compliance questionnaires, and the evidence health systems ask for, with a named point of contact.

See Sirona in Action

How Sirona is Different

Sign contracts you couldn't sign before

The conversation with the health system goes well — then the security questionnaire arrives. Hundreds of questions on encryption, incident response, data residency, disaster recovery, SOC controls. Most practices can't answer half of them, and the deal stalls. With Sirona as the data platform, that review shifts to us: we answer the questionnaire, handle the integration review, and show the security posture. You qualify for contracts you couldn't qualify for alone.

Security managed end-to-end

Attestations, encryption, integration handling, monitoring, incident response, and audit support — all owned by Sirona, all inherited by every customer.

Active SOC 2 Type II Program

An active SOC 2 Type II program and HIPAA-aligned posture every customer inherits — a partner's security review runs against Sirona's platform posture, not gaps you have to remediate before a contract closes.

HIPAA BAA Included

HIPAA-compliant by default with a Business Associate Agreement on every contract. The BAA covers every Sirona application and every data flow through the platform.

AES-256 Encryption

AES-256 encryption at rest. TLS 1.2+ with strong ciphers for browser and API traffic; site integrations connect over encrypted VPN tunnels. Key management is handled through AWS KMS.

Integration Reviews Handled

When a health system requests a security review before integrating, Sirona responds directly — questionnaires, architecture diagrams, and security-testing evidence.

Continuous Logging & Monitoring

Changes to clinical information and integration flows are recorded in Sirona's unified event model — the same event stream the platform runs on — and monitored by Sirona, with managed threat detection on the roadmap. Owned by Sirona, not your IT department. Beyond the audit trail, Sirona captures detailed application event data, including session replays of how the application was used. We are making more of that data available through the Dashboard, and over time through the SDK and APIs.

A Named Point of Contact

Every customer gets a named point of contact on the Sirona implementation team — one person to go to for audit support, partner questionnaires, and incident communication.

What Sirona manages on your behalf

Integration Reviews

Health-system security questionnaires answered by Sirona

When you enter negotiations with a large health system, their security team sends a questionnaire — often hundreds of questions spanning encryption standards, access controls, incident response, data residency, disaster recovery, and SOC controls. Sirona's security team answers it directly, with architecture diagrams and security evidence on file. The practice doesn't have to become a compliance expert to close the deal. Sirona is the compliance expert, on your contract.

Sirona security team responds to partner questionnaires directly

Architecture diagrams and security evidence on file

One BAA with Sirona, covering your data across every partner

Practices close enterprise deals they couldn't qualify for alone

Continuous Compliance

A compliance posture maintained continuously

Security compliance isn't a document you file once — it's a posture that has to be demonstrated every day. Sirona runs an active SOC 2 Type II program and keeps HIPAA controls current across every module, so when a health system's compliance team asks for evidence, the answer is ready. Practices don't have to build a compliance program from scratch — they inherit Sirona's security posture the moment they onboard.

Active SOC 2 Type II program, maintained continuously

Attestation details shared with partners under NDA

HIPAA controls built into every module and data flow

Evidence available on demand — no scramble when partners ask

Incident Response

Incident response owned by Sirona, inherited by every customer

Small practices can't afford a dedicated security operations capability. Large practices often can, but duplicating it for every vendor relationship is impractical. Sirona owns incident response for the platform — logging and monitoring the infrastructure, investigating and containing issues, and communicating on HIPAA breach-notification timelines with full forensic detail. A fully staffed 24/7 SOC is part of the security roadmap. You don't staff incident response — you subscribe to it.

Continuous audit logging and monitoring across Sirona infrastructure

Incident triage, containment, and investigation handled by Sirona

HIPAA breach-notification timelines and communications owned by Sirona

Forensic detail and root-cause analysis provided to affected customers

Audit Support

When your customers audit you, Sirona shows up with you

Every health-system partner eventually audits its vendors. The partner sends questions, requests evidence, and sometimes schedules on-site walkthroughs. For traditional PACS deployments, the practice runs that audit alone — often without the information the auditor wants. With Sirona, the audit runs against Sirona's unified posture. Your Sirona point of contact helps prepare responses, supplies the security evidence, and joins the audit call if needed. Compliance review goes from a scramble to a process.

A named Sirona point of contact on every customer account

Partner audit responses coordinated between customer and Sirona

Security evidence supplied on demand

Joint audit calls with Sirona security engineers when customers need them

Security at enterprise scale

Active

SOC 2 Type II program — HIPAA controls platform-wide

1

security posture consolidating every health-system relationship

Continuous

audit logging and monitoring across all Sirona infrastructure

What customers say about working with Sirona

Bringing disparate sites together

“Sirona integrated with our outreach sites, which are very different sites, and they all have different processes. I'm happy to report that Sirona took care of it. I didn't really have to do any boots on the ground or any projects with it. Just their ability to communicate with a variety of different people that look at the world differently was quite remarkable... Since Sirona, I've seen the radiologists' attitudes and appreciation of work improve.”

Linda Masin

Director, Eastern Radiological Associates

How Dr. Luke Roller Built a Practice From Scratch

Dr. Luke Roller built his practice from scratch on Sirona alone — and explains why one unified platform was all he needed to start reading and extend access to care.

FAQs