Compliance that's verifiable, not just promised.
Independently audited. Annually re-tested. Verifiable by your team.
Three credentials, and how to check each one.

Certificate details available on request.
Our information security management system is certified to ISO/IEC 27001:2022 by Intertek, under UKAS accreditation. Certification covers our entire organization - every support and business team, not only revenue cycle operations.
- Issuing body
- Intertek
- Accreditation
- UKAS 014
- Scope
- Entire organization
- Maintained by
- Annual surveillance audits
- Recertification
- Every three years
Compliance logos all look alike. They are not.
For executive leadership, the wrong choice of vendor can snowball into catastrophic downtime, multi-million dollar penalties, and permanent breach of patient trust. Here is what each one connotes, and how you can check it yourself.
ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for an information security management system - the governance structure that determines how risk is identified, who owns each control, and how the system improves.
We're certified to the 2022 revision, which added controls for threat intelligence, cloud services, secure development, and data masking.
Our certificate is issued by Intertek under UKAS accreditation 014 - meaning the body that audited us is itself audited, which is the difference between a certificate and a printout.
SOC 2 Type II
SOC 2 is an independent examination performed under the AICPA's attestation standards.
The Type I versus Type II distinction is the one worth knowing.
- Covers
- A single date
- Answers
- Were the controls suitably designed?
- Tests
- Design only
- Covers
- An extended observation period
- Answers
- Did those controls operate as described, throughout?
- Tests
- Design and operating effectiveness, tested repeatedly
Type II is the harder result, and the one your security team is looking for. It equips your health system board with auditable evidence of continuous operational resilience and HIPAA safeguard enforcement.
HIPAA
Valerion Health operates as a Business Associate - a defined legal status, not a marketing claim.
We are directly liable under HIPAA for the protected health information we handle on a covered entity's behalf, and a Business Associate Agreement governs every engagement before any data moves.
- A signed BAA with every client before the first record is processed, and with any subcontractor that touches PHI.
- Administrative, physical, and technical safeguards under the Security Rule, with a documented risk analysis reviewed annually.
- Minimum-necessary access by role - each team member reaches only what their assigned work requires.
- HIPAA training at onboarding and annually, tracked and auditable.
- A named Privacy Officer and Security Officer accountable for the program.
- Incident response and breach notification aligned to Breach Notification Rule timelines.
Our ISO 27001 certification and SOC 2 Type II examination are what make these claims checkable - the safeguards HIPAA requires are the same ones those audits test.
Certifications describe a system. This is what happens inside it.
Security sits under a documented ISMS with named owners for each control area. We maintain a risk register under regular review, perform an annual risk assessment, and run every policy through a scheduled review cycle. Internal audits run on a set schedule and feed a management review that leadership attends, not delegates.
Less compliance friction during system integrations and audits - and seamless compliance during third-party payer audits, keeping cash flow predictable.
Send it to your security team. We'll answer whatever they ask.
Certificate details, the SOC 2 Type II report under NDA, our BAA template, or a completed security questionnaire - tell us what your diligence process needs.
Contact our compliance team