SOC 2 Type II — audited accountability
PriMedical has completed a SOC 2 Type II examination — an independent CPA firm’s report on whether the controls protecting your claims data were designed well and operated effectively over time.
Why SOC 2 matters for the work we do
Every workers' compensation claim we manage carries sensitive information: protected health information (PHI), injury and treatment records, and personal details about injured workers. Payers, TPAs, carriers, and employers trust us to handle that data responsibly at every step of the case.
SOC 2 is the standard that holds us accountable to that trust. Developed by the American Institute of Certified Public Accountants (AICPA), it defines how service organizations should manage customer data across security, availability, processing integrity, confidentiality, and privacy.
A SOC 2 report is not a self-assessment or a badge we award ourselves — it is the result of an examination by an independent auditor who tests our controls against those standards.
What “Type II” means
There are two kinds of SOC 2 reports, and the difference matters for anyone evaluating a case management partner.
Type I
Point-in-time design
Confirms that the right controls exist at a single point in time — a snapshot of how the system is designed.
Type II
Operating effectiveness over time
Verifies that those controls actually operated effectively across an extended review period — day after day, not just on audit day.
PriMedical completed a SOC 2 Type II examination covering both of our operating entities — proof the safeguards were working throughout the period the auditor examined.
How we meet the SOC 2 criteria
A Type II examination evaluates controls across five criteria — the same framework partners use to decide whether a vendor can be trusted with claims data.
Security
We protect our systems and the data they hold against unauthorized access — including encryption in transit and at rest, multi-factor authentication, network and endpoint monitoring, formal access controls, and continuous security monitoring.
Availability
Partners who depend on us need our systems when a claim is active. We maintain reliable uptime through infrastructure redundancy, performance monitoring, and documented incident response and recovery procedures.
Processing integrity
Case decisions depend on accurate information. Our controls help ensure data is processed completely, accurately, and only when authorized — so information stays trustworthy from intake to resolution.
Confidentiality
Information designated as confidential is protected accordingly. We classify data by sensitivity and apply access restrictions, encryption, and handling rules so confidential information reaches only those with a legitimate need.
Privacy
We collect, use, retain, and dispose of personal information in line with our commitments and applicable requirements. With health information at the center of our work, privacy is fundamental to how we operate — not a checkbox.
SOC 2 alongside HIPAA
Because we handle PHI, HIPAA alignment is a baseline — not optional. SOC 2 Type II sits on top of that foundation.
Together, they give partners two independent lines of assurance: HIPAA’s specific requirements for protected health information, and SOC 2’s audited evaluation of controls across our operating environment. For vendor due diligence, that combination answers most security and privacy questions before they’re asked.
An ongoing commitment — not a one-time event
SOC 2 Type II is a continuing discipline. Our controls are monitored year-round. We conduct regular access reviews and maintain the documentation, training, and testing that keep our security posture current as our environment and the threat landscape evolve. Maintaining compliance is part of how we run the business — not a project we complete and set aside.
Request our SOC 2 report
Our full SOC 2 Type II report is available to current and prospective clients and partners under a mutual non-disclosure agreement. One request covers the report and any security or vendor-risk questionnaire you need completed.
Questions about our security program
For security, privacy, or compliance inquiries, reach out and our team will follow up.