KaiCare Earns Independent SOC 2 Type 1 Attestation for Security Controls

The KaiCare TeamJuly 21, 2026

KaiCare Earns Independent SOC 2 Type 1 Attestation for Security Controls

We have news to share, and we're proud of it.

On July 15, 2026, KaiCare AI (MyHealth CCM, LLC) received an unqualified SOC 2 Type 1 report from the independent CPA firm Insight Assurance. The examination evaluated the design of our security controls as of June 19, 2026, scoped to the Security trust services category.

If you're a Director of Clinical Operations—or anyone responsible for vetting the technology partners your practice relies on—this post explains what that sentence actually means, why it matters, and what comes next.

What Is SOC 2, in Plain English?

SOC 2 is a framework created by the American Institute of Certified Public Accountants (AICPA) that sets the bar for how technology companies should protect the data entrusted to them. Think of it as an independent, rigorous check on whether a company's security promises are backed by real, well-designed safeguards.

Here's the key part: a SOC 2 report isn't something a company gives itself. An independent CPA firm examines the controls, tests them against established criteria, and issues a formal opinion. You can't spin it. You can't cherry-pick results. The auditor calls it like they see it.

For healthcare SaaS platforms like KaiCare—where we handle patient PHI, RPM device data, care plans, and Medicare billing information on behalf of physician practices—this kind of third-party scrutiny is essential.

Type 1 vs. Type 2: What's the Difference?

SOC 2 comes in two flavors, and the distinction is straightforward:

  • Type 1 examines whether security controls are properly designed at a specific point in time. It answers the question: "Does this company have the right safeguards in place?"

  • Type 2 goes further. It examines whether those controls operated effectively over a period of time—typically six to twelve months. It answers: "Did those safeguards actually work, day in and day out?"

Our Type 1 report confirms that as of June 19, 2026, an independent auditor reviewed our security control design and issued an unqualified opinion—meaning no exceptions, no reservations.

Type 2 is our next milestone. We're committed to demonstrating that our controls don't just look right on paper but perform consistently over time. We won't commit to a specific date here, but it's firmly on our roadmap.

Why This Matters for Your Practice

If you run care management programs—RPM, CCM, TCM, RTM, PCM—you know how much sensitive data flows through your technology stack every single day:

  • Patient PHI from enrollment through ongoing encounters
  • RPM device readings transmitted from patients' homes
  • Care plans built collaboratively between clinical staff and patients
  • Medicare billing data tied to every service delivered

When you choose a technology partner, you're extending your practice's trust to that vendor. Your patients trust you. You need to trust us. And trust should be verifiable.

An independent attestation means you don't have to take our word for it. A qualified, independent CPA firm examined how we protect data and concluded—without qualification—that our security controls are properly designed.

That's not a marketing claim. It's a professional opinion from auditors whose reputation depends on getting it right.

What "Unqualified" Means (It's a Good Thing)

In auditor-speak, "unqualified" is the best possible outcome. It means the auditor found no issues significant enough to note. No exceptions. No carve-outs. A clean opinion.

We know the word sounds counterintuitive—but in this context, unqualified means unconditionally positive.

Our Commitment Going Forward

This report is a milestone, not a finish line. Security isn't a box you check once. It's an ongoing discipline, especially in healthcare where the stakes are personal and the regulatory landscape keeps evolving.

Here's what this attestation reflects about how we operate:

  • Security is embedded in how we build and run our platform, not bolted on afterward
  • We welcome independent scrutiny because it makes us better
  • We believe the practices we serve deserve transparency about how their data is protected

As we work toward our Type 2 attestation, we'll continue investing in the people, processes, and technology that keep your data safe.

Want to See the Report?

SOC 2 reports are detailed, technical documents intended for stakeholders evaluating a service provider's controls. We make ours available under a standard non-disclosure agreement.

👉 Request KaiCare's SOC 2 Type 1 report at trust.kaicare.ai

If you're evaluating care management platforms, conducting a vendor security review, or simply want to understand how we protect the data your practice entrusts to us—we'd be happy to share it.


Questions about our security posture or how KaiCare supports RPM, CCM, TCM, RTM, and PCM programs? Reach out. We're here to help.