Skip to main content

Author: Medicat

Why is SOC 2 Important to You?

Imagine your students’ personal health data ending up in the wrong hands—all because your EHR vendor didn’t meet the same compliance standards as your cloud hosting provider. It’s a chilling thought, but one that’s entirely preventable.

Most college IT teams and health administrators understand that their SaaS hosting providers must meet strict federal and industry standards. But far fewer apply the same scrutiny to their EHR vendors, even though both parties access the same electronic Protected Health Information (ePHI).

To truly safeguard student data, your EHR partner must be held to the same compliance standards as your infrastructure providers. Anything less introduces serious risk.

Cloud Providers Aren’t the Only Ones Who Need Oversight

As more student health services migrate to cloud-based platforms, colleges are becoming increasingly reliant on third-party vendors to manage sensitive health information. That reliance comes with responsibility.

A common pitfall? Institutions often focus solely on the security certifications of the cloud hosting provider—while overlooking the software vendor that actually builds, manages, and supports the EHR platform handling this data daily.

Both partners—hosting facility and EHR vendor—must meet industry-leading compliance standards. And one of the most critical standards to look for is SOC 2, particularly Type 2 SOC 2.

Why EHR Vendors Must Meet the Same Security Standards as Hosting Providers

SOC 2 is a widely recognized, third-party audit that evaluates how service organizations manage data related to security, availability, confidentiality, processing integrity, and privacy.

Furthermore, a hosting provider that stores ePHI typically undergoes a SOC 2 audit to demonstrate secure infrastructure. But if the EHR vendor that controls access, workflows, and interfaces with this data hasn’t also been audited, the system as a whole remains vulnerable.

Security is only as strong as the weakest link. Colleges must hold both their hosting and application vendors to the same level of trust and transparency.

How SOX Compliance Principles Apply to Higher Education

The Sarbanes-Oxley Act (SOX) was originally passed to reduce financial fraud in publicly traded companies. It requires these companies—and their third-party service providers—to implement strict controls and undergo regular audits.

While SOX specifically applies to corporate finance, its underlying principle—that third-party vendors must be independently audited when they impact critical systems—is just as relevant in higher education.

Colleges and universities rely on vendors for EHRs, payment systems, learning platforms, and more. If those vendors mishandle sensitive student data, the reputational and regulatory fallout can be just as serious.

Understanding SOC 2: Type 1 vs. Type 2

When evaluating whether a vendor has adequate SOC 2 coverage, it’s important to understand the two types:

  • SOC 2 Type 1 examines whether security controls are properly designed at a single point in time.
  • SOC 2 Type 2 assesses whether those controls are consistently followed and effective over a longer period (typically 6+ months).

For campus health centers, Type 2 is the stronger and more meaningful standard. It demonstrates not just good intentions, but a proven track record of secure operations.

For EHR vendors serving college campuses, SOC 2 is the audit that matters most.

What to Look for in an EHR Vendor

When assessing EHR vendors for your college or university, here are key questions to ask:

  • Have you completed a Type 2 SOC 2 audit within the past 12 months?
  • Can you provide documentation or attestations from your independent auditor?
  • Are both your infrastructure partner (hosting) and your software platform (EHR) covered by SOC 2?
  • How do your controls address each of the five Trust Service Criteria?

As regulatory expectations rise—and cyberattacks on student systems increase—it’s no longer enough to assume your partners are secure. Documentation matters!

Key Takeaways

Student health data is among the most sensitive information managed on campus. From immunizations and therapy notes to medication history and diagnoses, this data deserves the same level of protection as financial aid or academic records.

If your EHR vendor hasn’t undergone a Type 2 SOC 2 audit, your institution may be exposed to unnecessary risk—from data breaches to compliance violations.

SOC 2 isn’t just about passing an audit. It’s about proving—through independent validation—that your vendor is serious about protecting student privacy, supporting compliance, and earning your institution’s trust.

Medicat’s Commitment to Compliance

We believe your student health data deserves the highest level of protection. That’s why Medicat undergoes independent Type 2 SOC 2 audits, covering both our application and our infrastructure.

Learn more about our cloud-based EHR platform.

Industry Articles

Recent Medicat News

Continue reading

Medicat becomes only college health EHR with Type 2 SOC 2

To ensure storage, handling, and protection of clients’ electronic Patient Health Information (ePHI) meets and exceeds all government and industry standards, Medicat has made significant investments in its infrastructure and security framework. To substantiate that investment, Medicat has gone through the same third-party audit process as leading data centers in the country and has received Type 1 SOC 2 and Type 2 SOC 2 Examinations.

A company that has performed Type 2 SOC 2 Examination has proven its system is designed to keep clients’ sensitive data secure over time. When it comes to the cloud and related IT services, such performance and reliability are essential and required more often by regulators, examiners, and auditors.

Service Organization Control (SOC) reports—created by the American Institute of Certified Public Accountants (AICPA)—are internal control reports on the offerings furnished by a service organization and provide vital information to appraise the risks involved with an outsourced service. Performed by an independent third party, these reports provide peace of mind that the service provider you choose can and will deliver the security it promises.

“When asked if they are HIPAA compliant, EHR vendors may answer yes. But the only way to prove compliance is for the vendor to successfully complete an external audit, preferably one conducted by a reputable audit firm with HIPAA experience,” said Daryl Rolley, Medicat CEO. “The rigorous requirements of a Type 2 SOC 2 Examination provide an unmatchable level of confidence and security when considering a move to the cloud. It is critical to ensure your EHR partner has achieved external audits to meet these standards.”

Medicat, LLC is the market leader in providing Patient Health Management solutions and services to over 430 education clients. By living its mission of “Best Product, Superb Implementation, Unsurpassed Support,” Medicat’s client community continues to grow, while maintaining high client satisfaction.

Latest News & Press

Recent Industry Articles

Continue reading

Medicat donates $2,000 to American Red Cross & Watsi

American Red Cross Watsi

In honor of our clients, Medicat is pleased to donate $2,000 to the America Red Cross and Watsi.

Red Cross volunteers and staff work to deliver vital services – from providing relief and support to those in crisis, to helping you be prepared to respond in emergencies.Learn more

Watsi is a small team building technology to make universal health coverage possible. Learn more

Latest News & Press

Recent Industry Articles

Continue reading

IBM Recognizes Medicat as a Technology Leader

IBM recognizes Medicat for “maintaining market leadership with college healthcare solutions that never fail to deliver.”

Medicat is the leading provider of healthcare information technology (HIT) to colleges and universities in support of student health, counseling and sports medicine. Serving customers in 47 states and three countries, the company delivers highly available, secure and compliant cloud services.

Explore the IBM Case Study

Latest News & Press

Recent Industry Articles

Continue reading

Medicat Chooses Wolters Kluwer Clinical Content & Terminology

The Health division of Wolters Kluwer, a leading global provider of information and point-of-care solutions for the healthcare industry is pleased to announce that Medicat has chosen its suite of clinical content and terminology management solutions to enhance functionality in its Patient Health Management offering.

Specifically, the comprehensive health solution for colleges and universities will now feature the Workflow Enhancing Search offering from Health Language® and the Integrated Patient Education solutions.

Through the Integrated Patient Education solution, providers using Medicat gain access to more than 6,000 educational leaflets in up to 19 languages to share with patients. Developed using the background and deep industry experience of Wolters Kluwer with trusted clinical content from UpToDate®, the Integrated Patient Education solution provides the latest information and industry evidence on over 3,100 adult and pediatric medications and more than 3,500 diseases, conditions, natural products, discharge instructions, and healthy living topics.

The Health Language Enterprise Terminology Platform enhances search functionality, enabling providers using Medicat to look up and record problems and diagnoses through a comprehensive library of commonly-used synonyms. Familiar terms are then mapped to industry terminology standards such as ICD-10 – effectively solving the disconnect between billing and administrative standards, Meaningful Use requirements, and the clinician’s preferred way of documenting clinical care.

“Extending the value of EHR investments is critical in today’s quality-driven climate, and Wolters Kluwer terminology management solutions and integrated patient education tools provide leading functionality designed to equip EHR vendors with sustainable platforms,” said David A. Del Toro, President & CEO of Clinical Software Solutions at Wolters Kluwer. “We are pleased to partner with a leading EHR solution like Medicat and believe it is a testament to our continued commitment to arm healthcare organizations with comprehensive content and clinical knowledge that drives improved care quality, patient safety and clinical productivity.”

About Wolters Kluwer – Wolters Kluwer is a global leader in professional information services. Professionals in the areas of legal, business, tax, accounting, finance, audit, risk, compliance, and healthcare rely on Wolters Kluwer’s market-leading information-enabled tools and software solutions to manage their business efficiently, deliver results to their clients, and succeed in an ever more dynamic world. The group serves customers in over 170 countries and employs over 19,000 people worldwide.

Latest News & Press

Recent Industry Articles

Continue reading

Medicat Donates $2,900 to the American Cancer Society

Medicat, LLC is pleased to announce enthusiastic attendees at the American College Health Association national conference raised $2,900 for the American Cancer Society.

At the recent American College Health Association national meeting, Medicat, LLC pledged to donate $10 to the American Cancer Society on behalf of every person who attended our client workshop or visited the Medicat booth and completed a survey. The outcome was a $2,900 donation by Medicat on behalf of the college health community.

“We are grateful for everyone’s enthusiastic participation in supporting advances against a disease that has touched nearly everyone in some way and are proud to make this donation on behalf of the college health community.” said Stacy Kottman, Medicat CEO.

Latest News & Press

Recent Industry Articles

Continue reading