Submit a Referral Refer a case
Security & compliance

Security you can verify

Transparent visibility into PriMedical's security, compliance, and governance posture for procurement and security teams.

Live posture

Trust Center

This Trust Center provides transparent visibility into PriMedical Inc.'s security, compliance, governance, and trust documentation — giving your procurement and security teams what they need to evaluate us as a partner.

SOC 2 Type II continuously monitored by CompAI
SOC 2 Type 2
Controls in place
HIPAA continuously monitored by CompAI
HIPAA
Controls in place

Continuously monitored · Verified primedicalinc.com · Powered by CompAI

Current SOC 2 Type II report covering PriMedical and PriMed Solutions. Available on request under a mutual NDA.
  • 2
    Frameworks monitored
  • 26
    Published policies
  • 44
    Monitored controls
  • 4
    Named subprocessors
Governance

Documented, monitored, and available to review

Our policies define how we operate; our controls are the safeguards monitored against them year-round. Both inventories are published in full — open either one to read every item.

Policies 26 published

Internal policies that govern how we operate and protect customer data.

  • Acceptable Use & Workstation Security
  • Access Control & Least Privilege
  • AI Systems and Governance
  • Authentication & Password
  • Background Screening & On/Off-boarding
  • Backup, Business Continuity & Disaster Recovery
  • Change & Release Management
  • Company Handbook
  • Compliance & Regulatory Monitoring
  • Data Classification & Handling
  • Encryption & Crypto Controls
  • Incident Response & Breach Notification
  • Information Security & Privacy Governance
  • Information Sharing & Transfer
  • Logging, Monitoring & Audit
  • Policy Management & Exception Handling
  • Privacy & Data-Subject Rights
  • Remote Access & BYOD
  • Retention & Secure Disposal
  • Risk Management
  • Sanctions & Disciplinary
  • Secure Configuration & Hardening
  • Secure Software Development Lifecycle
  • Security & Privacy Awareness Training
  • Vendor & Third-Party Risk
  • Vulnerability & Patch Management
Security controls 44 monitored

Safeguards continuously monitored across our infrastructure and processes.

  • Acceptable Use
  • Access Rights
  • Asset Inventory
  • Business Associate Management
  • Change management
  • Configuration & Patch Management
  • Contingency Plan Operations
  • Credential Management
  • Data Encryption
  • Data Privacy
  • Data Retention & Destruction
  • Device & Media Controls
  • Disaster Recovery Planning
  • Disciplinary process
  • Encrypted Data at Rest
  • Encryption Key Management
  • Endpoint Protection
  • Endpoint Security
  • HIPAA Security Program Governance
  • Information Classification
  • Management Security Accountability
  • Network Security
  • Organization Structure & Reporting Lines
  • Personnel Security
  • Physical Access Control
  • Physical Facility Security
  • Policy Compliance
  • Regulatory Liaison
  • Remote-Work Security
  • Resource Capacity Management
  • Risk Analysis & Management
  • Risk Management
  • Secure Data Transfer
  • Secure SDLC Integration
  • Security Awareness & Training
  • Security Governance Roles
  • Security Incident Management
  • Security Logging
  • Security Monitoring & Detection
  • Segregation of duties
  • Standard Operating Procedures (SOPs)
  • Supplier Security
  • Vulnerability Management
  • Workforce Security & Sanctions
Third parties

Every subprocessor, named

These are the third parties that process client and claim data on our behalf, each under contractual safeguards. CompAI, which runs this Trust Center, also receives the security questionnaire requests submitted on this page.

  • AWS (Amazon Web Services)

    Trust center (opens in a new tab)

    Amazon Web Services offers reliable, scalable, and inexpensive cloud computing services. Free to join, pay only for what you use.

    • PCI DSS
    • HIPAA
    • GDPR
  • caseanyplace.com is a case management software platform used primarily in healthcare and social services to manage cases and client data.

    • HIPAA
  • Learn how the suite of secure, online tools from Google Workspace empowers teams of all sizes to do their best work.

    • HIPAA
    • ISO 27001
  • Salesforce is a cloud-based customer relationship management (CRM) platform that provides applications for sales, service, marketing, and more.

    • GDPR
    • HIPAA
    • ISO 27001
    • ISO 42001
    • ISO 9001
    • NEN 7510
    • PCI DSS
    • SOC 2
    • SOC 3
Answers

Common security questions

The questions procurement and security teams ask us most often.

Can we get a copy of your SOC 2 Type II report?

Yes. The signed report is available to current and prospective clients and partners under a mutual non-disclosure agreement (MNDA). Use Request SOC 2 report & questionnaire on this page and our team will route the MNDA and the report to you.

Do you meet HIPAA requirements as well as SOC 2?

Yes. Because we handle protected health information on every case, HIPAA-aligned safeguards are a baseline rather than an option, and our SOC 2 Type II examination sits on top of that foundation. Both are continuously monitored by CompAI.

Will you complete our vendor security questionnaire?

Yes. Include it in the same request as the SOC 2 report, using Request SOC 2 report & questionnaire on this page. Most standard questionnaires are already answered by the policies, controls, and subprocessor detail published here.

How current is the information on this page?

The frameworks, policies, controls, and subprocessors listed here are drawn from our compliance monitoring platform rather than maintained by hand, so this page reflects our posture as it is monitored day to day.

Which third parties can access our data?

Every subprocessor that processes data on our behalf is listed in the Subprocessors section below, along with what it is used for and its own compliance posture. Each operates under contractual safeguards.

Does your SOC 2 report cover both PriMedical and PriMed Solutions?

Yes. Our SOC 2 Type II examination covered both operating entities, so the same audited controls apply regardless of which entity is named on your agreement.

Ready to submit a referral?

Immediate acknowledgement. Assignment in hours, not days.

Access request

SOC 2 report & security questionnaire

Request our SOC 2 Type II report, completed security questionnaires, and other gated trust documentation in one request.

Purpose

Helpful context speeds up approval. 500 characters remaining.

A mutual NDA is required. After submitting, you'll receive an email with a short electronic signature link. Documents unlock as soon as you sign.