What SOC 2 Type II Means for Your Clinical AI Tools
Around Notes achieved SOC 2 Type II. Learn what Type II certification means for HIPAA-aware clinicians and IT teams evaluating AI documentation software.
Choosing an AI documentation tool isn't just about speed or note quality anymore. It's about whether the platform can be trusted with protected health information. Around Notes has now achieved SOC 2 Type II certification—here's what that means in plain language.
If you missed our announcement, read how we earned SOC 2 Type II and why it matters to us as a company built by a hospitalist.
SOC 2 in 60 Seconds
SOC 2 is a framework developed by the American Institute of CPAs (AICPA) for evaluating how companies handle data—especially security, availability, and confidentiality.
- Type I — Controls exist at a point in time.
- Type II — Controls work consistently over months of real operations.
Type II is the standard serious healthcare vendors pursue. Around Notes has completed it.
Why Physicians Should Care
You don't need to become a compliance officer. You do need to know:
- Your chart data deserves the same protection as your patients
- "We're HIPAA compliant" on a website isn't the same as independent audit evidence
- Tools built for consumer AI often aren't built for clinical workflows
When you paste labs, vitals, and clinical notes into an app, you're handing over protected health information. The question isn't whether the AI is impressive—it's whether the company behind it is governed like it belongs in a hospital.
"Finally achieving SOC 2 Type II shows our dedication to patient and user privacy and protection. We built Around Notes for hospital medicine—not for a demo video. That means security isn't an afterthought."
— Dr. Micheal Massoud, Founder & CEO
What Type II Validates (Practically)
- Access management — Who can reach what data, and how that's enforced over time
- Encryption & data handling — How information is stored, transmitted, and protected
- Monitoring & incident response — What happens when something goes wrong
- Vendor governance — How third-party tools in our stack are evaluated and controlled
These aren't abstract policies. An independent auditor tested them across months of real operations.
For Your Compliance Team
If your hospital or group requires vendor security reviews, SOC 2 Type II reports are designed to be shared under NDA. We're happy to support your evaluation process—because in healthcare, trust should be earned, not assumed.
Ask your IT team what they need. We'll provide it.
Our Position
We said it when we started our audit: SOC 2 doesn't magically make a company good. But it forces rigor. It forces accountability. And for a company like ours—handling clinical data every day—that matters.
Healthcare AI should be fast, impressive, and governed like it belongs there. SOC 2 Type II is one way we prove we're serious about all three.
Tags
About the Author
Dr. Micheal Massoud
Founder & Hospitalist | Wharton EMBA
Physician, founder, and Wharton Executive MBA candidate with roots in military medicine and a mission to make healthcare human again. Former Air Force officer who practiced hospital medicine across the globe and founded Around Notes—an AI-driven platform that helps hospitalists write better notes, faster. At Wharton, I'm bridging healthcare, technology, and leadership to create tools that amplify clinicians, not replace them.