1. Audit scope
Our SOC 2 Type II audit covers the operating effectiveness of controls over the trailing twelve-month period for the Medonix platform: the customer-facing dashboard, the AI Suite, the EHR / PMS modules where deployed, the integrations layer, and the underlying production infrastructure. The audit covers four Trust Services Criteria categories:
- Security: protection against unauthorized access (logical and physical).
- Availability: system uptime and operational availability.
- Confidentiality: protection of information designated as confidential.
- Privacy: collection, use, retention, and disclosure of personal information.
2. Auditor and cadence
The audit is performed annually by an independent Big Four CPA firm. The audit period runs July 1 through June 30, with the report issued in Q3 of the same calendar year. The full twelve-month operating-effectiveness period means the auditor evaluates whether controls operated as designed every day of the period, not a point-in-time snapshot.
3. Control areas covered
- Logical and physical access controls (CC6.x criteria).
- System operations, change management, and risk mitigation (CC7.x, CC8.x).
- Vendor and business-partner management (CC9.x).
- Logical security around encryption, secrets management, and key rotation.
- Availability monitoring, capacity planning, and incident response.
- Confidentiality controls aligned with our customer data-handling commitments.
- Privacy controls aligned with HIPAA, CCPA, and GDPR commitments.
4. How to request the report
The full SOC 2 Type II report is available under a mutual NDA. Customers and qualified prospects can request it from [email protected] with the subject "SOC 2 request." Sales engineers and security-review teams can typically receive the report within one business day after NDA execution.
Public summary information (auditor identity, audit-period dates, and the categories covered) is available without NDA for procurement teams and journalists.