Every medical record that moves through Medchart belongs to a person. That is the starting point for everything we do, and it is why we're glad to share that Medchart is SOC 2 Type II compliant, with independent attestation of controls that were already part of how we operate.
Prescient Assurance, an independent auditor, tested our security controls across a three-month observation window from February 17 to May 18, 2026. Their report, issued August 31, confirms those controls were suitably designed and operated effectively throughout the period against the AICPA's Security Trust Services Criteria.
What SOC 2 Type II means
SOC 2 is the standard the American Institute of CPAs uses to evaluate how service organizations protect the data entrusted to them. It is recognized across North America and is typically the first thing an enterprise security or privacy team asks a vendor about.
There are two report types. A Type I report confirms that controls are properly designed at a single point in time. A Type II report goes further: auditors observe the controls operating over a period of months and test whether they actually held.
Medchart chose Type II. It is the more demanding path, and the more meaningful one. Over three months, access controls, changes to production, security monitoring, and employee compliance with policy were subject to testing. The result is independent evidence, not a self-assessment.
Why this matters in Canada
Medchart already operates under PIPEDA and the provincial health privacy laws that govern personal health information across the country, including Ontario's PHIPA and Alberta's HIA. Consent capture, authorization verification, and full audit trails have been built into the platform from the beginning.
SOC 2 Type II adds an independent layer on top of that legal framework. Privacy legislation tells you what an organization is required to do. A SOC 2 Type II report adds third-party testing of the security controls supporting how the organization protects that information.
For the people who rely on Medchart, that translates into practical outcomes:
Law firms can satisfy client and insurer security questionnaires with a single audited report instead of a stack of policy documents.
Insurance companies get independent assurance on the controls behind the medical histories they use for underwriting and claims, which supports their own compliance obligations.
Healthcare providers and clinics releasing records through Medchart can point to audited controls when their privacy officer asks how requester-side data is protected.
Patients whose records are being requested can know that the platform handling their information has been independently tested, not just promised.
Why it matters right now: the tobacco settlement
Earlier this month, Medchart launched a dedicated medical records service for claimants under Canada's tobacco settlement. The Pan-Canadian Claimants' Compensation Plan sets aside $2.521 billion for eligible claimants outside Quebec, and eligibility turns on medical evidence: documentation of a qualifying diagnosis made between March 8, 2015 and March 8, 2019. Claimants have until September 3, 2027 to file.
This is the kind of work that shows why independent security assurance is not an abstraction.
For patients and families. The people filing these claims are living with lung cancer, throat cancer, or severe COPD, or they are the estates of people who have died from them. To make a claim, they have to share some of the most sensitive information a person has, often from a decade ago, often across clinics and hospitals they can barely remember. Many are doing this for the first time, without a lawyer. They deserve to know that the platform collecting those records, with their consent, has been independently tested to protect them. SOC 2 Type II is how we show that, rather than ask them to take our word for it.
For providers. Over the next year, clinics, hospitals, and specialists across Canada will receive a wave of record requests tied to the settlement, many for patients they last saw years ago. Every one of those requests has to be authorized, tracked, and released securely, and every privacy officer has to be comfortable that the requester on the other end handles the information properly. A single audited report answers that question once, so providers can release records with confidence and get back to caring for patients.
Medchart works with the settlement's official claims administrator, Epiq, to gather and facilitate the records claims depend on. Medchart does not provide legal advice and is not affiliated with the administration of the settlement; eligibility is determined by Epiq. Claimants and families can learn more or start a request at medchart.ca/tobacco.
What the auditors tested
The Security criteria cover the full lifecycle of how information is protected. Among the areas examined:
- Encryption of data in transit and at rest
- Role-based access with least-privilege permissions, and how access is granted, reviewed, and removed
- Change management for production systems
- Logging, monitoring, and alerting
- Incident response procedures
- Vendor and subservice organization management
- Employee onboarding, training, and offboarding
Medchart is built on Marble's secure, consent-driven infrastructure for protected information. Marble chose to audit the entire platform rather than a single product because Medchart's clients, from a law firm in Toronto to a life insurer underwriting a policy to a patient filing a tobacco claim, all depend on the same underlying controls. The SOC 2 Type II report covers that shared foundation, so Medchart, Marble, and SettLiT are within scope of the same attestation.
More than a year to earn three months
The observation window lasted three months. The work to reach it took more than a year.
SOC 2 Type II is not a box you check. It is a standard your controls have to stand up to over time. Long before an auditor was engaged, our team mapped every existing control to the Trust Services Criteria and closed the gaps. Practices that had lived in people's heads became documented, reviewable procedures. Infrastructure was hardened, access tightened, and logging extended to everything that touches personal health information.
We connected our systems to Vanta so controls could be monitored continuously rather than checked once a year. Every employee, in every role, completed security and privacy training, acknowledged company policies, and brought their devices into compliance. When something drifted, it was flagged and fixed in days.
Then the window opened on February 17, 2026. For three months, every control had to hold. Prescient Assurance began testing in March and worked through the summer on evidence requests, walkthroughs, and follow-ups. Our compliance lead coordinated each request. Our operations team closed every flagged item. Our engineering team demonstrated that the technical controls were built right and kept right. On August 31, the auditor signed the report.
We share this because anyone who has been through the process knows what it takes, and because the people who trust us with health information deserve to know what stands behind the badge.
What comes next
A Type II report is not a finish line. The next observation window has already begun, our controls remain under continuous monitoring, and we will renew the attestation every year.
.png)





