GLOSSARY · TRUST AND COVERAGE

SOC 2 Type II, an outside audit of security controls.

SOC 2 Type II is an independent audit report that tests whether a company's security controls worked as designed over a review period of several months.

01

What it means

SOC 2 is a framework from the American Institute of Certified Public Accountants (AICPA). A licensed CPA firm audits a company against criteria for security and, optionally, availability, processing integrity, confidentiality, and privacy. A Type I report describes the controls at a single point in time. A Type II report tests them across a review period, commonly three to twelve months, and lists any exceptions the auditor found.

SOC 2 is separate from HIPAA. HIPAA sets the rules for health data; a SOC 2 Type II report is independent evidence that a company's controls are working.

02

Why it matters to a brand operator

Larger buyers ask for it. Employers, health systems, retailers, and investors routinely send a security questionnaire, and a current SOC 2 Type II report answers most of it in one document. Without one, a deal can sit in security review for weeks.

The question also runs the other way. A brand should ask its telehealth partner for a current report, because the partner's systems hold the clinic's patient records and the report is the brand's proof, to its own buyers, that those records are protected.

[  03  ]

How Tessic Health handles it

Tessic Health's infrastructure is SOC 2 Type II and HIPAA compliant. SOC 2 Type II, SSO, and an uptime SLA come with the Scale program, and audit reports are available to clients and qualified prospects under NDA.

See the published terms