Trust & Compliance

Short version: Web Tonic is a digital marketing agency that will sign a Business Associate Agreement before handling protected health information, runs a PHI-free measurement architecture for healthcare clients, and operates an information security program aligned with ISO/IEC 27001 and SOC 2 control objectives. We are not third-party certified under ISO 27001 or SOC 2, and we do not claim to be. This page exists so your security, privacy and procurement reviewers can verify that in two minutes instead of two weeks.

Why this page says “aligned” and not “certified”

Compliance badges are easy to display and impossible to verify, so we publish evidence instead. The U.S. Department of Health and Human Services certifies no one and endorses no product, and the Federal Trade Commission has already treated a site-wide HIPAA compliance seal as a deceptive claim. ISO/IEC 27001 certification is issued to an organization by an accredited certification body after an audit — and even certified organizations are not permitted to use the ISO logo in marketing.

So we make claims a reviewer can actually check: what we contractually commit to, what controls we operate, which vendors touch your data, and exactly how far our assurance extends. Everything on this page is written to be verified, questioned, and held against us.

What we commit to

  • A signed BAA before PHI. On your paper or ours, executed before any protected health information reaches our people or our tools.
  • PHI-free advertising. No condition-revealing events, patient identifiers, or appointment-level data sent to Meta, Google, or any ad platform.
  • Least-privilege access. Named users, MFA everywhere, provisioned per engagement, revoked within one business day of offboarding.
  • Disclosed subprocessors. A public list, with 30 days’ notice before we add one.
  • A 48-hour incident clock. Notification to the affected client within 48 hours of confirming an incident, or faster where a BAA or law requires it.
  • Annual privacy and security training for every team member with client data access, plus role-specific HIPAA training for anyone on a healthcare account.
  • Data minimization by default. We work inside your platform accounts rather than exporting your data whenever the platform allows it.

How far our assurance extends

Being explicit about the limits is the point of a trust page:

  • We hold no ISO/IEC 27001 certificate and no SOC 2 Type I or Type II report as of this page’s last update.
  • We are not a HIPAA covered entity; we act only as a business associate, and only when contracted as one.
  • Some advertising platforms will not sign a BAA at all. Where that is true, the answer is architectural — we keep PHI out of that platform — not contractual.
  • Nothing on this page is legal advice, and it does not replace your own vendor risk assessment. Ask us for evidence; we will give it to you.

Frameworks we work to

  • HIPAA (Privacy, Security and Breach Notification Rules) — as a business associate under a BAA. See HIPAA & healthcare data.
  • ISO/IEC 27001 and SOC 2 Trust Services Criteria — as the reference model for our controls. See Security program.
  • GDPR and UK GDPR — as a processor, under an Article 28 DPA with SCCs. See Data processing & GDPR.
  • PIPEDA and Quebec Law 25 — for our Canadian client base.
  • CCPA/CPRA — as a service provider, with no sale or sharing of client personal information.

The four pages under this one

  • HIPAA & healthcare data — BAA scope, PHI-free tracking architecture, what we will and will not do on a patient-facing site.
  • Security program — the control matrix mapped to ISO/IEC 27001 Annex A themes and SOC 2 criteria.
  • Subprocessors — every vendor that can touch client data, what it is used for, and where it processes.
  • Data processing & GDPR — our DPA terms, transfer mechanism, retention and deletion.

Frequently asked by procurement

Is Web Tonic HIPAA compliant?

Web Tonic operates as a business associate under HIPAA when an engagement involves protected health information (PHI). We will execute a Business Associate Agreement (BAA) before any PHI reaches our team or our tooling. No organization can be “HIPAA certified” — HHS does not certify anyone, and we do not display HIPAA seals. What we offer instead is a signed BAA, a PHI-free measurement architecture, and documented controls you can audit.

Will you sign a Business Associate Agreement?

Yes. We will sign your BAA on your paper, or provide ours. Our standing rule is simple: no engagement touching PHI begins at Web Tonic until a BAA is in place first, reviewed by both sides.

Are you ISO 27001 or SOC 2 certified?

No. Our information security program is built and operated in alignment with ISO/IEC 27001 and SOC 2 Trust Services Criteria, and our team is experienced working inside client environments governed by those frameworks — but Web Tonic does not hold a third-party certification, and we will never say otherwise. If your procurement process requires a certificate rather than evidence of controls, tell us on the first call — in that situation we scope the work so it runs inside your certified environment, using your systems and your controls.

How do you run paid media for healthcare without leaking PHI to ad platforms?

By keeping identifiable health information out of the ad stack entirely. Standard client-side pixels on a patient-facing page can transmit information that OCR treats as PHI — including IP address combined with a page that reveals a condition or provider. Our healthcare measurement pattern uses server-side event collection under our control, conversion events stripped of condition-revealing context, consent gating before any marketing tag fires, and offline/CRM-side conversion import in place of pixel-based patient journeys.

Who has access to our accounts and data?

Named individuals only, on least-privilege roles, with MFA enforced on every platform account and SSO where the platform supports it. Access is provisioned per engagement, reviewed when staffing changes, and revoked within one business day of offboarding. We do not share logins, and we ask clients never to send credentials over email or chat.

What happens if there is a security incident?

We notify the affected client without unreasonable delay and no later than 48 hours from confirming an incident involving their data, with what we know, what we have contained, and what we need from them. Where a BAA is in force, HIPAA breach-notification timelines and the terms of that BAA govern and take precedence.

Do you sign a GDPR Data Processing Agreement?

Yes. We act as a processor for client personal data, sign an Article 28 DPA with Standard Contractual Clauses for transfers, and disclose our subprocessors publicly with 30 days’ notice before adding a new one. For Canadian clients we work to PIPEDA and Quebec’s Law 25 requirements, including consent and de-indexing obligations.

Where is our data stored, and for how long?

Client data lives in the client’s own platform accounts wherever possible — we prefer delegated access over copying data out. Working files sit in access-controlled cloud storage. We retain deliverables for the life of the engagement plus 12 months unless your contract says otherwise, and we return or destroy client data on request within 30 days.

Ask us for the evidence

Send your security questionnaire, your BAA, or your DPA to [email protected] and we will complete it. If anything on this page is out of date or reads as overstated, tell us and we will correct it — we review this page quarterly.