Built to the Standards Government Programs Require

The certifications, security architecture, and documentation your security, legal, and procurement reviewers will ask for, in one place, ready for review.

HIPAA

COMPLIANT

ARC-AMPE

COMPLIANT

SOC 1 & SOC 2

Type 2

PCI DSS

Certified

NIST 800-53

Controls

FIPS 140-2

Validated Encryption

AUDIT TRAILS

Ready

Section 508

Accessible

The Standards We Meet

The security, compliance, and accessibility standards that matter for Medicaid and State-Based Marketplace programs.

Privacy & Security
HIPAA

Administrative, physical, and technical safeguards for protected health information, assessed on an ongoing basis.

Compliant
Independent Audit
ARC-AMPE

CMS's Acceptable Risk Controls for ACA, Medicaid, and Partner Entities — the framework that superseded MARS-E — governing systems that touch federal marketplace and Medicaid data.

Compliant
CMS Standard
SOC 1 & SOC 2

Independent examinations of financial-reporting controls (SOC 1) and security, availability, and confidentiality controls (SOC 2), each assessed over time, not a point-in-time snapshot.

Type 2
Federal Controls
PCI DSS

Payment card data handled to the Payment Card Industry Data Security Standard across processing, transmission, and storage.

Certified
Accessbility
NIST 800-53

Security and privacy control alignment with the federal catalog state agencies already assess against.

Controls
Governance
FIPS 140-2

Cryptographic modules validated under the federal standard for protecting sensitive data in transit and at rest.

Validated encryption
Federal Controls
Audit Trails

Immutable activity logging across the platform, supporting oversight, reporting, and program-integrity review.

Built in
Accessbility
Section 508

Interfaces built to federal accessibility requirements, tested against WCAG success criteria.

Accessible
Security architecture

How the Platform Is Secured

Encryption

Data encrypted in transit and at rest, 
with managed key handling.

Access Control & Identity

Role-based access, least-privilege, and 
strong authentication for administrators.

Audit Logging & Monitoring

Comprehensive, tamper-evident logs with 
monitoring and alerting.

Secure Hosting & Data Segregation

Hardened hosting with environment and 
tenant data segregation.

The platform behind the platform

Backed by 25+ Years of Government Health Experience

CITIZ3N is a Softheon brand, backed by the scale, security, and experience of a healthcare technology company that has supported government health programs for more than 25 years. Every CITIZ3N deployment builds on that proven infrastructure.


Established

Security & compliance operations

GSA Approved

Pre-approved pricing

and streamlined procurement

Established

Government health experience

Ready for Your Security Review

Get the capability statement, or talk with our team about your specific compliance requirements.

Compliance Questions

Is CITIZ3N HIPAA compliant?

Yes. The platform applies administrative, physical, and technical safeguards for protected health information across its systems.

Yes — a SOC 2 Type 2 report covering security, availability, and confidentiality controls, available to review under NDA.

Yes — the platform aligns to ARC-AMPE, the CMS minimum acceptable risk standards for exchanges and connected systems.

Yes — member and administrator experiences are built to Section 508 accessibility requirements.

Yes — capability statements and reference architectures are available here, and the full security documentation set is shared during procurement.