Trust Center

Your charts carry PHI. Here is exactly how we protect it.

Medical coding runs on protected health information, so trust is not a claim we make - it is a set of certifications we hold and controls we operate, independently examined. All of it is on this page.

SOC 2 Type 2 badge

SOC 2 Type 2

Attested by a CPA firm, 2026

Our controls for security, availability, and confidentiality were examined in operation over time and attested by an independent CPA firm under the AICPA SOC for Service Organizations program.

ISO/IEC 27001:2022

Certified July 2024

Our information security management system is certified against the current international standard, covering how security is governed, operated, and improved.

HIPAA

Compliant

Protected health information is processed, maintained, and stored in accordance with HIPAA, with encrypted PHI exchange and access limited to the roles that need it.

Veradigm Connect

Certified October 2025

Certified for direct EHR integration, so charts move between your system and ours through a vetted, supported connection rather than an ad hoc export.

How we operate

Controls that run every day, not once a year

Certifications prove the system was examined. These are the practices the examinations found in operation.

  • Encryption of PHI

    Protected health information is encrypted in exchange between your systems and ours.

  • Role-based access control

    Access to systems and data is granted by role, kept to the minimum the role needs, and reviewed.

  • Comprehensive audit logging

    Actions on charts and codes are logged, so who did what, and when, is a record rather than a memory.

  • Independent security assessments

    Third-party security assessments and penetration testing probe the platform from the outside, on a recurring basis.

  • Incident response

    Documented protocols define how incidents are reported and handled, with named roles responsible for the response.

  • Workforce security training

    Team members are trained on security protocols and HIPAA compliance, so the people handling PHI know what handling it safely requires.

Beyond the perimeter

Security guards the data. The audit trail defends the coding.

Every assigned code is returned with the documentation passage and the compliance rule that justified it, and every change to a chart is logged with who made it. When a payer or an auditor asks why a code was billed, the answer is a lookup, not a reconstruction.

  • Every code traceable to the note passage behind it
  • Every chart change logged, with who and when
  • NCCI, MUE and LCD/NCD checks recorded per claim

The questions compliance teams ask

How do you ensure HIPAA compliance and data security?

MediCodio is ISO/IEC 27001:2022 certified, SOC 2 Type 2 attested, and fully HIPAA compliant, with encrypted PHI exchange, role-based access controls, comprehensive audit logging, and regular third-party security assessments to safeguard all client data.

Is your SOC 2 report available to prospects?

Yes. Our SOC 2 Type 2 report is available under NDA to organizations evaluating MediCodio. Ask for it through the contact form or during your discovery call.

Can auditors trace how a code was assigned?

Yes. Every assigned code is returned with the supporting documentation passage and the compliance rule that justified it, and every change to a chart is logged with who made it. An audit is a lookup, not a reconstruction.

Does patient data leave the platform?

Charts arrive through encrypted, vetted connections - API, RPA, or the Veradigm Connect certified integration - and finished coding is returned the same way. PHI is handled under HIPAA across the entire path.

Need our SOC 2 report or a security questionnaire completed? Ask through the contact form and it goes to a real person.

Contact Us

Let's talk about your coding workflow.

Whether you're curious about our products, features, or a free trial - we're happy to answer all your questions.

What happens next

No pressure, no spam - just a clear path from hello to pilot.

We read every message

A real person replies within 1–2 business days - no ticket queues, no canned answers.

30-min discovery call

You talk directly with a coding specialist about your workflow, volumes, and pain points.

Pilot scoped to you

A pilot program tailored to your specialty mix, so you see real results on real charts.

Security and compliance

Independently audited, not self-declared.

HIPAA compliant

Encrypted PHI exchange, role-based access control, and full audit logging.

ISO/IEC 27001:2022 certified

Information security management, certified July 2024.

SOC 2 Type 2 attested

Independently examined and attested by a CPA firm.

0/1000