Trust & Security
Independently examined. Continuously monitored.
IMSAI handles Protected Health Information every day, so our controls are examined by independent third parties rather than simply asserted by us: a SOC 2 Type 2 examination by a licensed CPA firm, and a HIPAA Security Rule assessment.
SOC 2® Type 2
Integrity Med Solutions has received a SOC 2 Type 2 report on the organization's controls relevant to Security, Availability, and Confidentiality. A Type 2 examination assesses not only whether controls are suitably designed, but whether they operated effectively across an extended observation period — not a single point in time.
- Report type
- SOC 2 Type 2
- Observation period
- December 1, 2025 – May 31, 2026
- Trust Services Criteria
- Security, Availability, and Confidentiality
- Service auditor
- Constellation GRC CPA P.C.
Requesting the report
Use of a SOC 2 report is restricted to user entities, their auditors, and other parties with sufficient understanding of the service organization and its controls. We share the complete report package with qualified prospects and customers under NDA — get in touch and we will arrange it.
HIPAA Security Rule assessment
IMSAI acts as a HIPAA Business Associate to the practices it serves. Our safeguards for electronic Protected Health Information were assessed by Aegisra Assurance LLP, an independent firm, against the HIPAA Security Rule using the NIST SP 800-66 Rev. 2 implementation framework. Every applicable control was found compliant. HIPAA has no government certification programme, so this assessment, rather than a certificate, is our evidence.
- Assessment type
- HIPAA Security Rule compliance assessment
- Assessment date
- August 14, 2026
- Framework
- NIST SP 800-66 Rev. 2
- Assessor
- Aegisra Assurance LLP
Scope: Administrative, Physical and Technical Safeguards, Organizational Requirements, and Policies, Procedures and Documentation Requirements.
Administrative safeguards
Risk analysis and management, workforce security, information access management, security awareness training, incident procedures and contingency planning.
Physical safeguards
Facility access controls, workstation use and security, and device and media controls.
Technical safeguards
Unique user identification, emergency access, automatic logoff, encryption, audit controls, integrity controls and transmission security.
Organizational requirements
Business Associate contracts and the obligations we take on as a Business Associate to every covered entity we serve.
Policies, procedures and documentation
Written HIPAA policies maintained, made available to those responsible for them, reviewed periodically and retained for six years.
Requesting the report
The assessment report is classified confidential with restricted distribution. We share it with customers and qualified prospects under NDA alongside the SOC 2 package — get in touch.
Security controls
Encryption in transit and at rest
TLS 1.3 for everything on the wire, AES-256 for everything at rest, including database storage of customer data.
Role-based access control
Granular permissions scoped per organization, so users reach only the records their role requires.
Multi-factor authentication
Required across all user accounts, with idle session locking on the platform.
Comprehensive audit trails
Every access and privileged action is logged and reviewable by your organization's administrators.
Dedicated infrastructure per organization
An isolated server environment and dedicated encryption keys per customer. Your data is never commingled with another practice's.
Continuous control monitoring
Controls are monitored continuously rather than checked once a year, with formal management review on a recurring cadence.
How we handle your data
PHI deleted after 3 days
All Protected Health Information is automatically and permanently deleted 3 days after creation. You can also delete any record manually at any time; manual deletions are purged within 24 hours.
Never used for AI training
Your PHI is processed only to produce the clinical documentation you asked for. It is never used to train models, improve algorithms, or for any other purpose — contractually guaranteed with every AI provider we use.
Zero retention with AI providers
Our agreements with AI vendors prohibit retention outright. PHI is processed in real time and discarded; it is not stored or logged on their side.
Business Associate Agreements
Signed BAAs are in place with our cloud infrastructure provider and every AI vendor that may process healthcare data on our behalf.
Full detail lives in our Privacy Policy and Terms of Service.
Infrastructure
The IMSAI production environment runs on enterprise cloud infrastructure from a major provider, under a signed Business Associate Agreement, inside an isolated private network with firewall rules reviewed on a recurring basis. Each customer organization receives a dedicated environment with independent backup and disaster recovery.
We identify our infrastructure provider and subprocessors to customers and qualified prospects under NDA, alongside the SOC 2 report package.
Questions about security?
Need our SOC 2 or HIPAA report, or answers for a security review? Get in touch and we'll get back to you.
Contact Us