Third Party Index

Phreesia

phreesia.com

Subprocessors

None extracted.

ComplianceCSVof Phreesia's compliance · Atomfeed of Phreesia's compliance

Security program

How Phreesia says it manages cybersecurity risk, in its annual report to the SEC.

Led by
Chief Information Security Officer reporting to the Chief Technology Officer · 15+ years of experience
quote The Board’s oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the “Audit Committee”), which regularly interacts with the Company’s ERM function, the Company’s Chief Technology Officer, along with other members of management including the Chief Information Security Officer and the Chief Privacy Officer.The Company’s Chief Information Security Officer is principally responsible for day-to-day management of the Company’s cybersecurity risk management program and reports to the Chief Technology Officer.The Chief Information Security Officer has more than 15 years of cybersecurity experience, including leadership roles at four publicly traded companies.
Board oversight
Audit Committee
quote The results of such assessments, audits and reviews are reported to leadership, the Audit Committee, and/or the Board, as appropriate, and the Company adjusts its cybersecurity policies, standards, processes and practices as appropriate based on the information provided by the assessments, audits and reviews.
Frameworks named
  • NIST CSF
  • PCI DSS
  • HITRUST
quote Our cybersecurity risk management program is informed by recognized industry standards and frameworks and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework and The Health Information Trust Alliance (HITRUST) Common Security Framework.Additionally, we are certified as a PCI-DSS Level 1 Service Provider.
Outside review
Engages outside assessors or consultants
quote For example, the Company regularly engages third parties to perform and facilitate assessments on our cybersecurity measures, including information security maturity assessments, audits, tabletop exercises, threat modeling and independent reviews of our information security control environment and operating effectiveness.
Its own suppliers
Reviews their security
quote The security team’s functions include identity and access management; security operations and incident response; governance, risk, and compliance; security architecture; third-party risk management, and application security.
Practices named
  • Incident response plan
  • Tabletop exercises
  • Vulnerability management
  • Threat intelligence
  • Security training
Material incidents
None so far, it says
quote We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
Read Item 1C in full

As a healthcare-focused company, we understand the importance of managing cybersecurity risks that we face and have established a cybersecurity risk management program as part of our enterprise risk management program.

Cyber Risk Management and Strategy

Our cybersecurity risk management program is informed by recognized industry standards and frameworks and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework and The Health Information Trust Alliance (HITRUST) Common Security Framework. Additionally, we are certified as a PCI-DSS Level 1 Service Provider. The Company’s cybersecurity program utilizes a cross functional, multilayered defense-in-depth approach designed to: (i) identify, prevent and mitigate cybersecurity threats to the Company; (ii) preserve the confidentiality, security and availability of the information that we collect and store; (iii) protect the Company’s intellectual property; (iv) maintain the confidence of our customers, clients and business partners; and (v) provide appropriate public disclosure and required notices of cybersecurity risks and incidents when required.

Our cybersecurity program includes safeguards that are designed to protect the Company’s information systems from cybersecurity threats. Such safeguards include firewalls, automated intrusion detection systems, anti-malware functionality and access controls, which are evaluated and improved through periodic vulnerability assessments and ongoing cybersecurity threat intelligence. We have established and maintain an incident response plan that addresses the Company’s response to and recovery from a cybersecurity incident. The incident response plan is tested and evaluated on an annual basis.

The Company’s cybersecurity program is supported by engagement of third-party service providers who help identify, assess and respond to cybersecurity risks. For example, the Company regularly engages third parties to perform and facilitate assessments on our cybersecurity measures, including information security maturity assessments, audits, tabletop exercises, threat modeling and independent reviews of our information security control environment and operating effectiveness. The results of such assessments, audits and reviews are reported to leadership, the Audit Committee, and/or the Board, as appropriate, and the Company adjusts its cybersecurity policies, standards, processes and practices as appropriate based on the information provided by the assessments, audits and reviews.

As part of our cybersecurity risk management program, we maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business. Further, all personnel are required to undergo cybersecurity training during onboarding and, thereafter, on an annual basis to reinforce the Company’s information security policies, standards and practices. Additionally, we conduct extensive cybersecurity assessments of potential acquisition targets to understand potential threats and mitigate risks, and the acquisition integration process includes alignment with relevant information security policies and procedures following completion of the transaction. We maintain cyber liability insurance to help mitigate potential liabilities resulting from cybersecurity issues, although our insurance may not cover all types of cybersecurity incidents or all losses that we incur.

We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, like other companies in our industry, we and our third-party vendors have experienced and will likely experience threats and security incidents that could affect our information or systems. See Item 1A “Risk Factors” in this Annual Report on Form 10-K for more information.

Governance

Phreesia takes a cross-functional approach to address the risks from cybersecurity threats. The Company’s Board of Directors (the “Board”) maintains oversight responsibility over the Company’s enterprise risk management (“ERM”) program, which incorporates the Company’s cybersecurity risk management program. The Board’s oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the “Audit Committee”), which regularly interacts with the Company’s ERM function, the Company’s Chief Technology Officer, along with other members of management including the Chief Information Security Officer and the Chief Privacy Officer.

The Company’s Chief Information Security Officer is principally responsible for day-to-day management of the Company’s cybersecurity risk management program and reports to the Chief Technology Officer. The Chief Information Security Officer has more than 15 years of cybersecurity experience, including leadership roles at four publicly traded companies. He is a Certified Information Systems Security Professional, holds a M.S. in Security Technologies from the University of Minnesota and is an alumnus of the FBI Citizen’s Academy. The Chief Technology Officer has served in various leadership roles in information technology and information security at the Company for over 15 years and holds a B.S. in computer science from Worcester Polytechnic Institute. The Chief Technology Officer reports directly to the Chief Executive Officer and works in coordination with the other members of the leadership team, which includes our General Counsel, President, Provider Solutions, President, Network Solutions and Chief Financial Officer. The Chief Technology Officer oversees a team of security professionals, which is led by the Chief Information Security Officer. The security team includes approximately 40 security professionals, 30 of whom are security engineers or analysts. The security team’s functions include identity and access management; security operations and incident response; governance, risk, and compliance; security architecture; third-party risk management, and application security.

The Board and the Audit Committee each receive quarterly presentations and reports from the Company’s Chief Technology Officer and/or General Counsel on cybersecurity risks, which address a wide range of topics including, among others, recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to the Company’s peers and third party service providers. The Board and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds under the Company’s incident response plan.

Security program from Phreesia, Inc.'s Form 10-K for fiscal 2026, filed Mar 31, 2026, Item 1C, in its words (evidence)

ChangesCSVof Phreesia's changes · Atomfeed of Phreesia's changes

None since tracking began.

Rating badge for Phreesia's site

Phreesia transparency rating

It updates with the rating.

<a href="https://thirdpartyindex.com/vendors/phreesia"><img src="https://thirdpartyindex.com/badge/phreesia.svg" alt="Phreesia transparency rating on Third Party Index" height="20"></a>
[![Phreesia transparency rating on Third Party Index](https://thirdpartyindex.com/badge/phreesia.svg)](https://thirdpartyindex.com/vendors/phreesia)