BridgeInteract, a healthcare technology company that consolidates patient portal, intake, payments, scheduling, and communication within the electronic health record (EHR), announced today that it has successfully completed a SOC 2 Type 2 examination. Conducted by an independent, licensed CPA firm, the examination covered a recent reporting period, focusing on the effectiveness of controls over time rather than at a single point.
The SOC 2 framework, developed by the American Institute of CPAs, evaluates service organizations against trust services criteria including security, availability, processing integrity, confidentiality, and privacy. BridgeInteract’s report addresses the criteria most relevant to its platform, which handles a significant volume of sensitive patient information.
The distinction between Type 1 and Type 2 reports is critical for healthcare organizations evaluating vendors. A Type 1 report assesses whether controls are designed properly at a specific date, while a Type 2 report tests whether those controls operated effectively throughout the entire reporting period. For providers, this difference is the difference between a snapshot and a track record.
“Our customers entrust us with sensitive information and we take this very seriously,” said John Deutsch, CEO of BridgeInteract. “We built BridgeInteract to protect that information at every step. A Type 2 examination means an independent firm watched our controls work over months, not on one convenient day. That is the standard our customers deserve, and it is the standard we hold ourselves to.”
The examination reflects BridgeInteract’s approach to security across its platform. By replacing multiple fragmented systems with a unified patient intake and payments platform built on discrete EHR integration, patient information flows into structured chart fields rather than sitting in disconnected PDFs or flat files. Fewer systems handling patient data means fewer points of exposure for the organizations that rely on it.
This standard becomes even more critical as BridgeInteract’s footprint expands. The platform now includes patient portal and mobile access, intake, appointment scheduling, insurance eligibility and payment processing, clinical and social-needs screening, and secure two-way messaging, all integrated directly with the EHR. Consolidating that much of the patient journey into one platform is exactly why its security cannot be taken on faith, and why an independent, multi-month examination matters more here than it would for a single-purpose tool.
In addition to SOC 2 Type 2, BridgeInteract is compliant with the ONC Certification Criteria for Health IT and maintains a HIPAA-compliant environment. It also meets the requirements of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) for organizations it serves there. The company’s full SOC 2 report is available to prospective clients under NDA.
Security is not a one-time achievement at BridgeInteract. Every capability added to the platform, from payments to screening to messaging, is built and tested against the same standard validated in this examination. Beyond this examination, BridgeInteract also engages independent security firms throughout the year for additional third-party testing and auditing, an ongoing practice rather than a once-a-year event.
