Security controls tested over time.

VitalCheck Wellness completed a SOC 2 Type II examination of controls relevant to Security for the period November 15, 2025 through March 15, 2026. A-LIGN concluded that the controls were suitably designed and operated effectively throughout the examination period. The reported control tests recorded no exceptions.

Verify ClearToStart — every independent checkpoint on one page

A-LIGN SOC 2 Type II examination badge
SOC 2 Type II · Security
Examination period
November 15, 2025 – March 15, 2026
Independent examination by A-LIGN Assurance of VitalCheck Wellness's medical scheduling, electronic medical records and related software systems.
The SOC 2 Type II examination
Examined entity
VitalCheck Wellness, Inc.
Independent auditor
A-LIGN Assurance
Category examined
Security (Trust Services)
Auditor conclusion
Controls suitably designed and operating effectively; no exceptions in the reported control tests.

The SOC 2 report is restricted-use. Agencies evaluating ClearToStart request it through the security-documentation process above.

How the systems are protected

Controls within the examined systems

Encryption

Within the systems covered by the SOC 2 examination, VitalCheck encrypts data at rest and in transit using strong cryptographic methods.

Access control

VitalCheck restricts system and data access to people whose jobs require it and applies least-privilege access controls.

Logging and monitoring

VitalCheck logs system activity, monitors production systems and sends automated alerts when suspicious activity is detected.

Vulnerability management

VitalCheck conducts annual vulnerability scanning and independent third-party penetration testing. During the examination period, those tests identified no critical or high-risk vulnerabilities.

Incident response

VitalCheck maintains procedures for identifying, escalating and responding to security events.

Business continuity

VitalCheck maintains and tests business-continuity and disaster-recovery plans.

Vendor oversight

VitalCheck performs due diligence before engaging service providers and reviews compliance evidence for critical vendors at least annually.

HIPAA

VitalCheck maintains a HIPAA compliance program for ClearToStart and the systems that support it. VitalCheck provides the administrative and technology platform. Licensed healthcare providers make clinical decisions. VitalCheck operates as a business associate where applicable.

Privacy practices

What we do — and do not do — with information

We do not sell personal information.
We do not use health information for behavioral advertising.
We do not use protected health information to train general-purpose AI models without written authorization.
A requesting organization receives clinical information only under the individual's authorization.
We do not collect genetic information or family medical history for a requesting organization.
Sensitive information is encrypted during transmission.
Information is processed on systems located in the United States.

Read the Privacy Policy, Notice of Privacy Practices and Terms of Use.

Privacy contact

privacy.office@getvitalcheck.com

VitalCheck Wellness, Inc.
Attn: Privacy Office / Compliance
241 West 37th Street, Suite 402
New York, New York 10018

Licensed providers make clinical decisions. Your agency decides whether to accept the file and hire the worker.

Clinical results stay inside the dashboard.

When a file is ready, authorized agency users receive an email notification and sign in to view and download the result and signed paperwork. The clinical result is not placed in the notification email. Multiple authorized users can access the records their agency designates.

The dashboard operates under VitalCheck's HIPAA compliance program and SOC 2 Type II-examined security controls.