Company · Compliance & Certificates

Compliance that's verifiable, not just promised.

Independently audited. Annually re-tested. Verifiable by your team.

Certifications at a glance

Three credentials, and how to check each one.

ISO/IEC 27001:2022 certificate

Certificate details available on request.

Our information security management system is certified to ISO/IEC 27001:2022 by Intertek, under UKAS accreditation. Certification covers our entire organization - every support and business team, not only revenue cycle operations.

Issuing body
Intertek
Accreditation
UKAS 014
Scope
Entire organization
Maintained by
Annual surveillance audits
Recertification
Every three years
What each of these actually means

Compliance logos all look alike. They are not.

For executive leadership, the wrong choice of vendor can snowball into catastrophic downtime, multi-million dollar penalties, and permanent breach of patient trust. Here is what each one connotes, and how you can check it yourself.

ISO/IEC 27001:2022

ISO/IEC 27001 is the international standard for an information security management system - the governance structure that determines how risk is identified, who owns each control, and how the system improves.

We're certified to the 2022 revision, which added controls for threat intelligence, cloud services, secure development, and data masking.

Our certificate is issued by Intertek under UKAS accreditation 014 - meaning the body that audited us is itself audited, which is the difference between a certificate and a printout.

SOC 2 Type II

SOC 2 is an independent examination performed under the AICPA's attestation standards.

The Type I versus Type II distinction is the one worth knowing.

The easier result
Type I
Covers
A single date
Answers
Were the controls suitably designed?
Tests
Design only
What your security team is looking for
Type II
Covers
An extended observation period
Answers
Did those controls operate as described, throughout?
Tests
Design and operating effectiveness, tested repeatedly

Type II is the harder result, and the one your security team is looking for. It equips your health system board with auditable evidence of continuous operational resilience and HIPAA safeguard enforcement.

HIPAA

Valerion Health operates as a Business Associate - a defined legal status, not a marketing claim.

We are directly liable under HIPAA for the protected health information we handle on a covered entity's behalf, and a Business Associate Agreement governs every engagement before any data moves.

In practice
  • A signed BAA with every client before the first record is processed, and with any subcontractor that touches PHI.
  • Administrative, physical, and technical safeguards under the Security Rule, with a documented risk analysis reviewed annually.
  • Minimum-necessary access by role - each team member reaches only what their assigned work requires.
  • HIPAA training at onboarding and annually, tracked and auditable.
  • A named Privacy Officer and Security Officer accountable for the program.
  • Incident response and breach notification aligned to Breach Notification Rule timelines.

Our ISO 27001 certification and SOC 2 Type II examination are what make these claims checkable - the safeguards HIPAA requires are the same ones those audits test.

How we protect your data

Certifications describe a system. This is what happens inside it.

Security sits under a documented ISMS with named owners for each control area. We maintain a risk register under regular review, perform an annual risk assessment, and run every policy through a scheduled review cycle. Internal audits run on a set schedule and feed a management review that leadership attends, not delegates.

Less compliance friction during system integrations and audits - and seamless compliance during third-party payer audits, keeping cash flow predictable.

Contact our compliance team

Send it to your security team. We'll answer whatever they ask.

Certificate details, the SOC 2 Type II report under NDA, our BAA template, or a completed security questionnaire - tell us what your diligence process needs.

Contact our compliance team