Current status
Approva is pursuing a SOC 2 Type II report and has not started the audit. Readiness work is underway, no audit firm is engaged, and no report — Type I or Type II — has been issued. Approva treats readiness as an ongoing program and publishes status here as milestones are reached, rather than naming a date it does not control. In the meantime, we can share our security posture and controls documentation under NDA — contact prashanth@approva.health.
Controls in scope
Security is the common criteria every SOC 2 engagement includes. On top of it, the program is designed to cover availability (uptime SLAs, incident response), confidentiality (PHI access controls, encryption), and processing integrity (change management, data validation). Logical access, vendor management, and risk assessment policies are documented as part of the same program. The privacy criterion is not in the current scope.
Supporting compliance
SOC 2 controls complement our HIPAA program. For a full overview of our security posture, including encryption standards and audit logging, see the security and compliance page.