Quick answer
Handl Health has successfully completed its SOC 2 Type II examination, conducted by A-LIGN. The certification affirms that Handl's infrastructure, software, people, data, policies, and operations meet the AICPA's rigorous security standards—and that protecting customer data is treated as an ongoing undertaking, not a one-time effort.
Key takeaways
- Handl Health completed its SOC 2 Type II examination, audited by A-LIGN, the industry's top SOC 2 issuer
- SOC 2 Type II reviews infrastructure, software, people, data, policies, procedures, and operations—not just technology
- CTO Scott Geye: data security is a bedrock principle and an ongoing undertaking, not a one-time effort
- The AICPA-established standard is recognized globally, giving customers confidence that required safeguards are in place
LOS ANGELES March 9 —
Handl Health, a technology platform powering the design of employer-sponsored health insurance that reduces costs while improving patient care, has successfully completed its SOC 2 Type II examination.
A-LIGN conducted the audit.
“At Handl, data security is a bedrock principle, and that’s why it’s so important for us to be recognized as SOC 2 compliant. This award shows that we have strict and evolving security protocols in place for customer data,” said Scott Geye, Handl’s chief technology officer. “SOC 2 compliance also recognizes that data security is not a one-time effort but an ongoing undertaking with the goal of protecting data now and in the future.”
What does SOC 2 Type II certification mean?
Established by the American Institute of Certified Public Accountants (AICPA), the SOC 2 Type II examination is designed for organizations of any size, regardless of industry and scope, to ensure the personal assets of their potential and existing customers are protected. SOC 2 reports are recognized globally and affirm that a company’s infrastructure, software, people, data, policies, procedures and operations have been formally reviewed.
“Congratulations to Handl Health for completing their SOC 2 audit, a widely recognized signal of trust and security," said Steve Simmons, COO of A-LIGN. "It's great to work with organizations like Handl Health, who understand the value of expertise in driving an efficient audit and the importance of a high-quality final report."
This certification demonstrates Handl Health’s continued commitment to compliance and ensures customers have confidence that required safeguards are in place to protect company data.
About Handl Health
Handl Health is a technology platform transforming how health plans are evaluated, designed and managed. By unifying healthcare pricing, utilization, benefit and quality data into a single analytical and operational layer, Handl empowers employers, brokers and payers to build flexible, cost-effective health benefits that perform. Handl’s technology delivers the infrastructure, analytics and insights needed to power the next generation of alternative health plans.
ABOUT A-LIGN
A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and a leading HITRUST and FedRAMP assessor. To learn more, visit a-lign.com.
Frequently asked questions
What is a SOC 2 Type II examination?
An audit standard established by the AICPA that formally reviews an organization's infrastructure, software, people, data, policies, procedures, and operations to verify customer data is protected—over a sustained period, not just at a point in time.
Who audited Handl Health's SOC 2 compliance?
A-LIGN, the number one issuer of SOC 2 reports and a leading HITRUST and FedRAMP assessor.
Why does SOC 2 compliance matter for healthcare data platforms?
Health plan analytics platforms handle sensitive pricing, claims, and member data. SOC 2 Type II gives brokers, carriers, and TPAs independent assurance that required safeguards are in place and continuously maintained.
Is SOC 2 a one-time certification?
No. As Handl CTO Scott Geye notes, SOC 2 compliance recognizes that data security is an ongoing undertaking with evolving protocols—Type II specifically examines controls operating over time.
Are SOC 2 reports recognized outside the U.S.?
Yes. SOC 2 reports are recognized globally and apply to organizations of any size, regardless of industry and scope.


_1787590719858-BUGq-DQ2.png)

