Summary
As of May 2024, SOC 2 Type II certification is being actively pursued. It is not expected to be ready until early 2025. This article explains the level of cybersecurity applied to HealthPro.
SOC 2 Type II
Service Organization Control 2 (SOC 2) focuses on non-financial controls at an organization as they relate to security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Type II Certification consists of a thorough examination by a third-party firm over a specified period of time–typically six months to one year–that reviews an organization’s systems, policies, and operational procedures for managing data and ensuring that principles standards are followed.
Achieving SOC 2 Type II Security ensures that an organization has established processes with necessary levels of oversight across its various departments. These include expectations that it has procedures and tools for monitoring unusual system activities, unauthorized and authorized configuration changes, user access levels, and many more internal controls (over 120+). By putting a continuous security monitoring process in place, organizations are in a better position to detect any potential threats, whereas other compliance mandates simply require you to pass an audit test, SOC 2 Type II Security requires long-term, dedicated internal practices that ensures the security of customer data.