
SOC 2 Type 2
Attested by a CPA firm, 2026
Our controls for security, availability, and confidentiality were examined in operation over time and attested by an independent CPA firm under the AICPA SOC for Service Organizations program.
Trust Center
Medical coding runs on protected health information, so trust is not a claim we make - it is a set of certifications we hold and controls we operate, independently examined. All of it is on this page.

Attested by a CPA firm, 2026
Our controls for security, availability, and confidentiality were examined in operation over time and attested by an independent CPA firm under the AICPA SOC for Service Organizations program.
Certified July 2024
Our information security management system is certified against the current international standard, covering how security is governed, operated, and improved.
Compliant
Protected health information is processed, maintained, and stored in accordance with HIPAA, with encrypted PHI exchange and access limited to the roles that need it.
Certified October 2025
Certified for direct EHR integration, so charts move between your system and ours through a vetted, supported connection rather than an ad hoc export.
How we operate
Certifications prove the system was examined. These are the practices the examinations found in operation.
Protected health information is encrypted in exchange between your systems and ours.
Access to systems and data is granted by role, kept to the minimum the role needs, and reviewed.
Actions on charts and codes are logged, so who did what, and when, is a record rather than a memory.
Third-party security assessments and penetration testing probe the platform from the outside, on a recurring basis.
Documented protocols define how incidents are reported and handled, with named roles responsible for the response.
Team members are trained on security protocols and HIPAA compliance, so the people handling PHI know what handling it safely requires.
Beyond the perimeter
Every assigned code is returned with the documentation passage and the compliance rule that justified it, and every change to a chart is logged with who made it. When a payer or an auditor asks why a code was billed, the answer is a lookup, not a reconstruction.
MediCodio is ISO/IEC 27001:2022 certified, SOC 2 Type 2 attested, and fully HIPAA compliant, with encrypted PHI exchange, role-based access controls, comprehensive audit logging, and regular third-party security assessments to safeguard all client data.
Yes. Our SOC 2 Type 2 report is available under NDA to organizations evaluating MediCodio. Ask for it through the contact form or during your discovery call.
Yes. Every assigned code is returned with the supporting documentation passage and the compliance rule that justified it, and every change to a chart is logged with who made it. An audit is a lookup, not a reconstruction.
Charts arrive through encrypted, vetted connections - API, RPA, or the Veradigm Connect certified integration - and finished coding is returned the same way. PHI is handled under HIPAA across the entire path.
Need our SOC 2 report or a security questionnaire completed? Ask through the contact form and it goes to a real person.
Whether you're curious about our products, features, or a free trial - we're happy to answer all your questions.
No pressure, no spam - just a clear path from hello to pilot.
We read every message
A real person replies within 1–2 business days - no ticket queues, no canned answers.
30-min discovery call
You talk directly with a coding specialist about your workflow, volumes, and pain points.
Pilot scoped to you
A pilot program tailored to your specialty mix, so you see real results on real charts.
Independently audited, not self-declared.
HIPAA compliant
Encrypted PHI exchange, role-based access control, and full audit logging.
ISO/IEC 27001:2022 certified
Information security management, certified July 2024.
SOC 2 Type 2 attested
Independently examined and attested by a CPA firm.