Security you can verify
Transparent visibility into PriMedical's security, compliance, and governance posture for procurement and security teams.
Trust Center
This Trust Center provides transparent visibility into PriMedical Inc.'s security, compliance, governance, and trust documentation — giving your procurement and security teams what they need to evaluate us as a partner.
Continuously monitored · Verified primedicalinc.com · Powered by CompAI
- 2Frameworks monitored
- 26Published policies
- 44Monitored controls
- 4Named subprocessors
Documented, monitored, and available to review
Our policies define how we operate; our controls are the safeguards monitored against them year-round. Both inventories are published in full — open either one to read every item.
Policies
Internal policies that govern how we operate and protect customer data.
- Acceptable Use & Workstation Security
- Access Control & Least Privilege
- AI Systems and Governance
- Authentication & Password
- Background Screening & On/Off-boarding
- Backup, Business Continuity & Disaster Recovery
- Change & Release Management
- Company Handbook
- Compliance & Regulatory Monitoring
- Data Classification & Handling
- Encryption & Crypto Controls
- Incident Response & Breach Notification
- Information Security & Privacy Governance
- Information Sharing & Transfer
- Logging, Monitoring & Audit
- Policy Management & Exception Handling
- Privacy & Data-Subject Rights
- Remote Access & BYOD
- Retention & Secure Disposal
- Risk Management
- Sanctions & Disciplinary
- Secure Configuration & Hardening
- Secure Software Development Lifecycle
- Security & Privacy Awareness Training
- Vendor & Third-Party Risk
- Vulnerability & Patch Management
Security controls
Safeguards continuously monitored across our infrastructure and processes.
- Acceptable Use
- Access Rights
- Asset Inventory
- Business Associate Management
- Change management
- Configuration & Patch Management
- Contingency Plan Operations
- Credential Management
- Data Encryption
- Data Privacy
- Data Retention & Destruction
- Device & Media Controls
- Disaster Recovery Planning
- Disciplinary process
- Encrypted Data at Rest
- Encryption Key Management
- Endpoint Protection
- Endpoint Security
- HIPAA Security Program Governance
- Information Classification
- Management Security Accountability
- Network Security
- Organization Structure & Reporting Lines
- Personnel Security
- Physical Access Control
- Physical Facility Security
- Policy Compliance
- Regulatory Liaison
- Remote-Work Security
- Resource Capacity Management
- Risk Analysis & Management
- Risk Management
- Secure Data Transfer
- Secure SDLC Integration
- Security Awareness & Training
- Security Governance Roles
- Security Incident Management
- Security Logging
- Security Monitoring & Detection
- Segregation of duties
- Standard Operating Procedures (SOPs)
- Supplier Security
- Vulnerability Management
- Workforce Security & Sanctions
Every subprocessor, named
These are the third parties that process client and claim data on our behalf, each under contractual safeguards. CompAI, which runs this Trust Center, also receives the security questionnaire requests submitted on this page.
-
AWS (Amazon Web Services)
Trust center (opens in a new tab)Amazon Web Services offers reliable, scalable, and inexpensive cloud computing services. Free to join, pay only for what you use.
- PCI DSS
- HIPAA
- GDPR
-
caseanyplace.com
Trust center (opens in a new tab)caseanyplace.com is a case management software platform used primarily in healthcare and social services to manage cases and client data.
- HIPAA
-
Google Workspace
Trust center (opens in a new tab)Learn how the suite of secure, online tools from Google Workspace empowers teams of all sizes to do their best work.
- HIPAA
- ISO 27001
-
Salesforce
Trust center (opens in a new tab)Salesforce is a cloud-based customer relationship management (CRM) platform that provides applications for sales, service, marketing, and more.
- GDPR
- HIPAA
- ISO 27001
- ISO 42001
- ISO 9001
- NEN 7510
- PCI DSS
- SOC 2
- SOC 3
Common security questions
The questions procurement and security teams ask us most often.
Can we get a copy of your SOC 2 Type II report?
Yes. The signed report is available to current and prospective clients and partners under a mutual non-disclosure agreement (MNDA). Use Request SOC 2 report & questionnaire on this page and our team will route the MNDA and the report to you.
Do you meet HIPAA requirements as well as SOC 2?
Yes. Because we handle protected health information on every case, HIPAA-aligned safeguards are a baseline rather than an option, and our SOC 2 Type II examination sits on top of that foundation. Both are continuously monitored by CompAI.
Will you complete our vendor security questionnaire?
Yes. Include it in the same request as the SOC 2 report, using Request SOC 2 report & questionnaire on this page. Most standard questionnaires are already answered by the policies, controls, and subprocessor detail published here.
How current is the information on this page?
The frameworks, policies, controls, and subprocessors listed here are drawn from our compliance monitoring platform rather than maintained by hand, so this page reflects our posture as it is monitored day to day.
Which third parties can access our data?
Every subprocessor that processes data on our behalf is listed in the Subprocessors section below, along with what it is used for and its own compliance posture. Each operates under contractual safeguards.
Does your SOC 2 report cover both PriMedical and PriMed Solutions?
Yes. Our SOC 2 Type II examination covered both operating entities, so the same audited controls apply regardless of which entity is named on your agreement.
Ready to submit a referral?
Immediate acknowledgement. Assignment in hours, not days.