BridgeInteract, a healthcare technology company that unifies patient portal, intake, payments, scheduling, clinical and social-needs screening, and communication inside the electronic health record (EHR), has completed a SOC 2 Type 2 examination. The examination, conducted by an independent licensed CPA firm, tested the effectiveness of the company's controls over a recent reporting period, providing a comprehensive view of its security posture.
The SOC 2 examination, developed by the American Institute of CPAs, measures a service organization against trust services criteria including security, availability, processing integrity, confidentiality, and privacy. BridgeInteract's report addresses the criteria most relevant to its platform, ensuring that its security measures meet industry standards.
The distinction between Type 1 and Type 2 reports is crucial for healthcare organizations evaluating vendors. A Type 1 report assesses whether controls are designed properly at a single point in time, while a Type 2 report tests whether those controls operated effectively over an entire period. For a provider organization, this difference is the difference between a snapshot and a track record. BridgeInteract's completion of a Type 2 examination demonstrates that its controls have been consistently effective over months, not just on one day.
"Our customers entrust us with sensitive information and we take this very seriously," said John Deutsch, CEO of BridgeInteract. "We built BridgeInteract to protect that information at every step. A Type 2 examination means an independent firm watched our controls work over months, not on one convenient day. That is the standard our customers deserve, and it is the standard we hold ourselves to."
The examination reflects how Bridge approaches security across its platform. BridgeInteract replaces multiple fragmented systems with a unified patient intake and payments platform built on discrete EHR integration, meaning patient information flows into structured chart fields rather than sitting in disconnected PDFs or flat files. Fewer systems handling patient data means fewer points of exposure for the organizations that rely on it.
That standard matters more, not less, as BridgeInteract's footprint grows. The platform now spans patient portal and mobile access, intake, appointment scheduling, insurance eligibility and payment processing, clinical and social-needs screening, and secure two-way messaging, all connected directly to the EHR. Consolidating that much of the patient journey into one platform is exactly why its security cannot be taken on faith, and why an independent, multi-month examination matters more here than it would for a single-purpose tool.
BridgeInteract is also compliant with the ONC Certification Criteria for Health IT and maintains a HIPAA-compliant environment, and meets the requirements of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) for the organizations it serves there. The company's full SOC 2 report is available to prospective clients under NDA.
Security is not a one-time achievement at Bridge. Every capability added to the platform, from payments to screening to messaging, is built and tested against the same standard validated in this examination. Beyond this examination, Bridge also engages independent security firms throughout the year for additional third-party testing and auditing, an ongoing practice rather than a once-a-year event.


