SOC2C

Is this your company? Buyers are checking Powerfulmedical here. Claim powerfulmedical.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Powerfulmedical logo

Powerfulmedical

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Powerfulmedical is SOC 2 Type II compliant. Powerfulmedical also holds ISO 27001, HIPAA, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the Powerful Medical Security Trust Center, where you can explore our comprehensive security measures, compliance certifications, and real-time updates. We are dedicated to transparency and upholding the highest security and compliance standards to ensure your data remains protected.

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationPersonal health information

Subprocessors

5
  • A
    Amazon Web Services · Cloud Provider
    EU, US
  • Z
    Zendesk · Customer Support
    EU
  • F
    FusionAuth (Inversoft LLC) · Authentication
    EU, US
  • S
    Sentry · Cloud monitoring
    US
  • S
    Snowflake · Data Analytics
    Ireland

Compliance leadership

The person who leads Powerfulmedical's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Powerfulmedical's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Powerful Medical achieves MDSAP certification!May 2025

We are proud to announce that Powerful Medical has officially achieved MDSAP (Medical Device Single Audit Program) certification. This milestone underscores our unwavering commitment to meeting the highest international standards for quality and regulatory compliance across multiple jurisdictions, including the United States and others. It is a testament to the strength of our quality management systems and our dedication to delivering safe, effective, and innovative AI-powered medical solutions to healthcare providers and patients worldwide.

Powerful Medical has successfully completed an external audit, officially confirming SOC 2 Type II and HIPAA compliance!Sep 2024

We are thrilled to announce that Powerful Medical has successfully completed an external audit, officially confirming our SOC 2 Type II certification and HIPAA compliance! Having adhered to SOC 2 and HIPAA standards for over a year, this milestone represents a key achievement in our commitment to upholding the highest standards of data security and privacy. The audit, covering an observation period of the last 12 months, verifies that Powerful Medical has consistently met all necessary requirements. Our SOC 2 Type II certification highlights our dedication to maintaining robust internal controls, ensuring the integrity, availability, and confidentiality of customer data. Meanwhile, HIPAA compliance affirms our unwavering commitment to safeguarding sensitive healthcare information in line with regulatory expectations. These certifications underscore our ongoing focus on earning and maintaining the trust of our customers and partners, ensuring that data is securely managed across every aspect of our operations. The full external SOC 2 Type II + HIPAA Report is available upon request via our Trust Center.

Powerful Medical is now officially ISO 27001 certified!Apr 2024

Achieving ISO 27001 certification marks a significant milestone for our organization, reinforcing our commitment to robust information security practices. Long compliant with this global standard, we are proud to be officially now recognized for our dedication to safeguarding data and ensuring operational integrity and security. This certification is a testament to our commitment to protecting the data of our customers and partners.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Powerfulmedical SOC 2 compliant?
Powerfulmedical is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Powerfulmedical ISO 27001 certified?
According to Powerfulmedical's public trust center, Powerfulmedical is ISO 27001 certified. On SOC2C this listing is Listed.
Is Powerfulmedical HIPAA compliant?
According to Powerfulmedical's public trust center, Powerfulmedical is HIPAA compliant. On SOC2C this listing is Listed.
Is Powerfulmedical GDPR compliant?
According to Powerfulmedical's public trust center, Powerfulmedical is GDPR compliant. On SOC2C this listing is Listed.
Is Powerfulmedical SOC 2 Type I or Type II?
Powerfulmedical is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Powerfulmedical

Reproduced from Powerfulmedical's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Does Powerful Medical maintain a risk management program?
Powerful Medical has a risk management program and performs annual company-wide risk assessments, conducted by the Powerful Medical security team. Our security team manages and tracks the lifecycle of these risks as they are mitigated and treated.
What data does Powerful Medical process?
The data shared with Powerful Medical varies based on the provided product and its implementation. Given the nature of our products, it is possible that we will process and store PII and PHI within the ECG data gathered through different sources. This may encompass, among other details, essential patient demographic data such as Patient Name, Date of Birth, and any additional information supplied to PMcardio. For details on our handling of customer PII and PHI, please consult the PMcardio privacy policy.
Where are your servers located?
PMcardio customers who are on the Enterprise Plan have the option to host their data in our US or EU data centers. With ownership over your hosting region, you can ensure we meet your data security goals. PMcardio supports Data Residency through our Amazon Web Services-operated data centers in Ireland (Europe Region) and the United States.
Is all data encrypted in transit and at rest?
All data sent to and from Powerful Medical is encrypted. Our API and application endpoints are TLS/SSL-only to ensure secure communication with our clients and partners. All data at rest is encrypted using AES-256.
Is PMcardio and its risk management system compliant with the EU AI Act?
Our risk management system is systematically organized and regularly maintained to ensure continuous compliance with Article 9 of the AI Act. Specifically, our overarching Information Security Management System risk management practices are fully aligned with internationally recognized standards, including ISO 27001 and SOC 2, which address information security and operational controls comprehensively. Importantly, all AI-specific and product/medical device-related risks are identified, evaluated, controlled, and monitored rigorously in accordance with ISO 14971, the internationally recognized gold standard for risk management in medical devices. Importantly, our medical device AI modules are certified against the requirements of the EU Medical Device Regulation (2017/745) which superseed the AI Act requirement for medical devices. This integrated approach ensures that our products maintain the highest standards of safety, security, and regulatory compliance.