Back to Home

Trust & Security

Independently examined. Continuously monitored.

IMSAI handles Protected Health Information every day, so our controls are examined by independent third parties rather than simply asserted by us: a SOC 2 Type 2 examination by a licensed CPA firm, and a HIPAA Security Rule assessment.

AICPA SOC 2 seal

SOC 2® Type 2 report
Controls relevant to Security, Availability, and Confidentiality, examined by an independent licensed CPA firm.

HIPAA compliant
Security Rule safeguards independently assessed by Aegisra Assurance LLP.

SOC 2® Type 2

Integrity Med Solutions has received a SOC 2 Type 2 report on the organization's controls relevant to Security, Availability, and Confidentiality. A Type 2 examination assesses not only whether controls are suitably designed, but whether they operated effectively across an extended observation period — not a single point in time.

Report type
SOC 2 Type 2
Observation period
December 1, 2025 – May 31, 2026
Trust Services Criteria
Security, Availability, and Confidentiality
Service auditor
Constellation GRC CPA P.C.

Requesting the report

Use of a SOC 2 report is restricted to user entities, their auditors, and other parties with sufficient understanding of the service organization and its controls. We share the complete report package with qualified prospects and customers under NDA — get in touch and we will arrange it.

HIPAA Security Rule assessment

IMSAI acts as a HIPAA Business Associate to the practices it serves. Our safeguards for electronic Protected Health Information were assessed by Aegisra Assurance LLP, an independent firm, against the HIPAA Security Rule using the NIST SP 800-66 Rev. 2 implementation framework. Every applicable control was found compliant. HIPAA has no government certification programme, so this assessment, rather than a certificate, is our evidence.

Assessment type
HIPAA Security Rule compliance assessment
Assessment date
August 14, 2026
Framework
NIST SP 800-66 Rev. 2
Assessor
Aegisra Assurance LLP

Scope: Administrative, Physical and Technical Safeguards, Organizational Requirements, and Policies, Procedures and Documentation Requirements.

Administrative safeguards

Risk analysis and management, workforce security, information access management, security awareness training, incident procedures and contingency planning.

Physical safeguards

Facility access controls, workstation use and security, and device and media controls.

Technical safeguards

Unique user identification, emergency access, automatic logoff, encryption, audit controls, integrity controls and transmission security.

Organizational requirements

Business Associate contracts and the obligations we take on as a Business Associate to every covered entity we serve.

Policies, procedures and documentation

Written HIPAA policies maintained, made available to those responsible for them, reviewed periodically and retained for six years.

Requesting the report

The assessment report is classified confidential with restricted distribution. We share it with customers and qualified prospects under NDA alongside the SOC 2 package — get in touch.

Security controls

Encryption in transit and at rest

TLS 1.3 for everything on the wire, AES-256 for everything at rest, including database storage of customer data.

Role-based access control

Granular permissions scoped per organization, so users reach only the records their role requires.

Multi-factor authentication

Required across all user accounts, with idle session locking on the platform.

Comprehensive audit trails

Every access and privileged action is logged and reviewable by your organization's administrators.

Dedicated infrastructure per organization

An isolated server environment and dedicated encryption keys per customer. Your data is never commingled with another practice's.

Continuous control monitoring

Controls are monitored continuously rather than checked once a year, with formal management review on a recurring cadence.

How we handle your data

PHI deleted after 3 days

All Protected Health Information is automatically and permanently deleted 3 days after creation. You can also delete any record manually at any time; manual deletions are purged within 24 hours.

Never used for AI training

Your PHI is processed only to produce the clinical documentation you asked for. It is never used to train models, improve algorithms, or for any other purpose — contractually guaranteed with every AI provider we use.

Zero retention with AI providers

Our agreements with AI vendors prohibit retention outright. PHI is processed in real time and discarded; it is not stored or logged on their side.

Business Associate Agreements

Signed BAAs are in place with our cloud infrastructure provider and every AI vendor that may process healthcare data on our behalf.

Full detail lives in our Privacy Policy and Terms of Service.

Infrastructure

The IMSAI production environment runs on enterprise cloud infrastructure from a major provider, under a signed Business Associate Agreement, inside an isolated private network with firewall rules reviewed on a recurring basis. Each customer organization receives a dedicated environment with independent backup and disaster recovery.

We identify our infrastructure provider and subprocessors to customers and qualified prospects under NDA, alongside the SOC 2 report package.

Questions about security?

Need our SOC 2 or HIPAA report, or answers for a security review? Get in touch and we'll get back to you.

Contact Us