Building Trust Through Security: PlanStreet Completes Its SOC 2

Go Back Publish Date: July 27, 2026

Key Takeaways:

  • PlanStreet has completed its SOC 2 audit, confirming strong security controls protect the sensitive information used by healthcare providers and community agencies.
  • This milestone took a company-wide effort, with teams strengthening policies across areas like access management, monitoring, and incident response.
  • SOC 2 compliance is ongoing, not a one-time achievement, and PlanStreet will keep investing in security to earn customer trust.

At PlanStreet, trust is the cornerstone of every customer relationship.

Public service organizations rely on our platform to manage sensitive information, coordinate life-saving services, track client outcomes, streamline billing workflows, and most importantly, serve people across their communities. We understand the responsibility that comes with that trust, which is why protecting customer information remains a core priority for our team.

We are proud to share that PlanStreet has successfully completed its SOC 2 audit, marking an important milestone in our continued commitment to security and responsible data management. This process took about six months, including four months to implement and validate the security controls, followed by a two-month independent audit period.

PlanStreet logo with a completed checkmark beside the AICPA SOC seal

Exceeding an Industry Standard: What SOC 2 Means

SOC 2 is one of the most stringent reporting frameworks developed by the American Institute of Certified Public Accountants. It allows an independent auditor to evaluate the controls a service organization has in place to protect customer information and support secure operations.

This SOC 2 Type II audit was conducted against the Security Services Trust Criteria, which includes:

  • Security: Information and systems are protected against unauthorized access, unauthorized disclosure of information, and damage to systems that could compromise the availability, integrity, confidentiality, and privacy of information or systems and affect the entity's ability to meet its objectives.
  • Availability: Information and systems are available for use and accessible to the entity's authorized users to meet the entity's objectives.
  • Processing integrity: System processing is complete, valid, accurate, timely, and authorized to meet the entity's objectives.
  • Confidentiality: Information designated as confidential is protected to meet the entity's objectives.
  • Privacy: Personal information is collected, used, retained, disclosed, and disposed of to meet the entity's objectives.

For PlanStreet, completing the SOC 2 audit is more than checking a compliance box. It reflects the work we have done to build thoughtful policies, dependable processes, and strong internal controls around the way we operate.

We Did This For You: Better Security for Our Customers

PlanStreet supports community-based organizations, nonprofits, healthcare providers, behavioral health teams, public agencies, and human services organizations.

Many of these teams work with sensitive client, program, clinical, billing, and operational information. They need technology partners that take security seriously and can demonstrate that commitment through independent review.

The completion of our SOC 2 audit gives customers and partners added confidence that PlanStreet has established controls designed to support:

  • Responsible handling of sensitive information
  • Secure access to systems and data
  • Reliable business operations
  • Strong risk-management practices
  • Greater transparency during vendor and procurement reviews

Most importantly, it helps reinforce the trust our customers place in us every day.

A Team Effort Across PlanStreet

Achieving this milestone was not the work of one department. It required collaboration across PlanStreet.

Teams worked together to review policies, strengthen processes, document procedures, and demonstrate how security controls are applied throughout the organization. During this audit, PlanStreet reviewed:

  • Access management: the process of controlling who can log into a system and what information they're allowed to see or change.
  • System monitoring: the ongoing practice of watching systems and networks in real time to catch unusual activity or problems before they cause harm.
  • Change management: a structured process for reviewing and approving updates to systems or software so changes don't accidentally create security gaps.
  • Backups: copies of important data stored securely so information can be recovered if it's lost, corrupted, or compromised.
  • Business continuity: a plan that keeps essential operations running during and after a disruption, like a natural disaster or cyberattack.
  • Disaster recovery: the specific steps an organization takes to restore its systems and data after a major disruption knocks them offline.
  • Incident response: the organized approach a company follows to detect, contain, and resolve a security issue when one occurs.

This company-wide effort reflects a shared belief: security is everyone's responsibility.

Supporting Secure Community-Based Care

As a Community-Based Care Platform, PlanStreet helps organizations manage intake, assessments, service delivery, reporting, outcomes, billing, and care coordination.

Behind every workflow is sensitive information connected to real people and real communities. Protecting that information is essential to helping our customers do their work with confidence.

Completing the SOC 2 audit strengthens the foundation of our platform and supports our broader goal of delivering dependable technology for organizations making a meaningful impact.

Our Work Continues

The completion of our SOC 2 audit is an important achievement, but security is never a one-time project.

PlanStreet will continue reviewing and improving its security practices through ongoing monitoring, employee training, access reviews, risk assessments, policy updates, vulnerability management, and incident-response planning.

SOC 2 is one part of a broader security program that must continue to evolve as technology, customer needs, and potential risks change. PlanStreet has worked to stay abreast of security best practices, also becoming FED-RAMP certified and approved by NYC CoC and HUD as a compliant and validated software vendor.

Our commitment is not only to meet today's expectations, but to keep strengthening the way we protect and support our customers in the future.

Requesting the PlanStreet SOC 2 Report

SOC 2 reports may contain sensitive information about an organization's systems and security controls. For that reason, PlanStreet's full report will not be made publicly available.

Current customers, prospective customers, and authorized partners may contact the PlanStreet team to request access. The report may be shared through an approved review process and may require a signed nondisclosure agreement.

Continuing to Earn Your Trust

We are proud of this milestone and grateful to the teams who helped make it possible.

More importantly, we remain focused on what it represents: a continued commitment to security, transparency, and the trust our customers place in PlanStreet.

As organizations use our platform to coordinate care, manage services, support billing, track outcomes, and serve their communities, we will continue investing in the people, processes, and technology needed to protect the information entrusted to us.

To learn more about PlanStreet's security practices or request access to our SOC 2 report, contact the PlanStreet team.

SOC 2 Frequently Asked Questions

It means an independent auditor has verified that PlanStreet has strong, consistently applied controls in place to protect sensitive client, program, and clinical information.

SOC 2 and HIPAA are separate frameworks, but they overlap in areas like access control and data protection, so SOC 2 compliance supports, rather than replaces, HIPAA compliance efforts. PlanStreet is also a HIPAA-compliant software.

SOC 2 audits are typically conducted annually, so PlanStreet's controls are reviewed on an ongoing basis rather than being a one-time achievement. This is part of our ongoing commitment to maintaining a strong security posture, continuously improving our security controls, and providing our customers and partners with continued assurance regarding the security of our platform.

Yes, current customers, prospective customers, and authorized partners can contact the PlanStreet team to request the report, which may require a signed nondisclosure agreement due to its sensitive contents.

It shouldn't change daily workflows at all; instead, it means the systems staff already use for intake, care coordination, and reporting are backed by independently verified security practices.

Latest Blogs