Is this your company?Buyers are checking MDI - Health Technologies here. Claim mdihealth.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is MDI - Health Technologies SOC 2 compliant?
MDI - Health Technologies is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is MDI - Health Technologies HIPAA compliant?
According to MDI - Health Technologies's public trust center, MDI - Health Technologies is HIPAA compliant. On SOC2C this listing is Listed.
Is MDI - Health Technologies SOC 2 Type I or Type II?
MDI - Health Technologies is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use MDI - Health Technologies's SOC 2 for a vendor risk assessment?
Yes. MDI - Health Technologies's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is MDI - Health Technologies penetration tested?
MDI - Health Technologies hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is MDI - Health Technologies secure?
Security isn't a single yes/no, but MDI - Health Technologies is SOC 2 Type II compliant and holds SOC 2 Type II, HIPAA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does MDI - Health Technologies have a bug bounty or vulnerability disclosure program?
MDI - Health Technologies hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@mdihealth.com or via a /security page (MDI - Health Technologies lists a security contact).
Who are MDI - Health Technologies's subprocessors?
MDI - Health Technologies lists 1 subprocessor on its trust center, including Amazon Web Services. Buyers use this for fourth-party risk review.
Where does MDI - Health Technologies host or store data?
MDI - Health Technologies hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is MDI - Health Technologies's trust center or security page?
MDI - Health Technologies's trust center is at https://trust.mdihealth.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What compliance protocols is MDI Health certified in?
We are SOC2 Type II and HIPAA compliant.
What platform do you use to manage your compliance controls and Trust Center?
MDI uses the Vanta Trust Management Platform.
What sensitive data does MDI collect?
We collect customer Personally Identifiable Information (PII) and Personal Health Information (PHI). We do not collect any credit card information.
Do you encrypt data?
All data is encrypted at rest and in transit.
What subprocessors interact with MDI data?
Amazon Web Services
In what region is data stored?
MDI's data resides in North Virginia.
Does MDI undergo penetration tests?
We conduct annual penetration tests which can be accessed by sending a request to security@mdihealth.com.
Do you maintain cybersecurity insurance?
Yes, MDI holds cybersecurity insurance.
What Security and Privacy controls do you have in place to protect data?
MDI has established controls to protect data; these include: - A clear Privacy Policy has been established and is available for review. - Data Classification and Data Retention policies have been set up. - All sensitive customer data is purged upon the customer leaving the service. - Documented processes and procedures in place to ensure that any privacy-related complaints are addressed. - All sensitive data is encrypted.
What Infrastructure and Organizational Security controls do you have in place?
MDI has established controls to protect its infrastructure and promote organizational security, these include: - An Intrusion Detection System (IDS) monitors the network. - Routinely updated and logged anti-malware technology is utilized. - The network is segmented; access is restricted based on business need; logs are maintained and managed.
Has MDI established Internal Security Procedures?
MDI has created and follows Internal Security Procedures, that include: - Vulnerability scanning and remediation. - Vendor and third party security management. - A formal systems development life cycle (SDLC) methodology. - Clear Incident Management and Continuity and Disaster Recovery plans.