What Equiti's SOC 2 Type II and HIPAA/HITECH Attestations Mean for Healthcare Organizations

Learn how Equiti's new attestations give healthcare organizations another layer of independently verified assurance when evaluating Martti as a technology partner.

Equiti has completed two independent examinations of the Martti platform's security and compliance program: a SOC 2 Type II examination and a HIPAA/HITECH attestation examination, both performed by A-LIGN. Together with Martti's existing HITRUST e1 certification, these results give healthcare organizations another layer of independently verified assurance when evaluating Martti as a technology partner.

What Is a SOC 2 Type II Examination?

SOC 2 is a widely recognized attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates an organization's controls against the AICPA's Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy — and every SOC 2 report addresses Security at a minimum.

A "Type II" examination is meaningfully different from a Type I: rather than reviewing whether controls are designed appropriately at a single point in time, a Type II examination tests whether those controls actually operated effectively over an extended review period. Equiti's SOC 2 Type II examination, covering the Security category, evaluated the design and operating effectiveness of Martti's controls over the period of November 1, 2025 through April 30, 2026.

What Is the HIPAA/HITECH Attestation?

Separately, Equiti also completed a HIPAA/HITECH attestation examination. This engagement evaluated whether Martti's health information security program, as of April 30, 2026, includes the essential elements required under the HIPAA Security Rule and the HITECH Act — spanning administrative, physical, and technical safeguards, and organizational and breach-notification requirements. This examination assessed the design of the program as of a single date, which is a distinct scope from the SOC 2 Type II review of operating effectiveness over time.

Why Two Separate Examinations Matter

HIPAA compliance and SOC 2 attestation address related but different questions. HIPAA is a federal regulatory requirement specific to protected health information; SOC 2 is a voluntary, broader security framework recognized across industries. Completing both gives healthcare partners independently verified evidence across two distinct lenses: general information security practices, and safeguards specific to health information.

How This Builds on Martti's HITRUST e1 Certification

Earlier in 2026, Martti achieved HITRUST e1 certification, which integrates multiple regulatory and security frameworks into a single assessment. The SOC 2 Type II and HIPAA/HITECH examinations complement that certification by providing additional, independently verified detail on Martti's security practices and health information safeguards — reinforcing a layered approach to assurance rather than a one-time claim.

What This Means for Healthcare Organizations

For CIOs, CISOs, compliance officers, and procurement teams evaluating vendor risk, these results can help:

  • Streamline vendor security reviews with independently verified evidence
  • Support documentation required for internal compliance and audit processes
  • Provide confidence that Martti's safeguards for protected health information have been independently examined
  • Complement existing due diligence built around Martti's HITRUST e1 certification

Learn More

Visit Martti's Security & Trust page to learn more about our security program, or talk to your account team about requesting a copy of the full reports.

About the Author

Samantha Leanillo is the Chief Information Security & Privacy Officer at Equiti, where she leads the organization’s information security, privacy, and compliance programs. With over a decade of experience spanning security, risk management, and regulatory compliance, Samantha is responsible for developing and maintaining the controls and frameworks that protect data across Equiti. She brings deep technical expertise and a hands-on approach to safeguarding systems, ensuring compliance with industry standards, and strengthening security awareness across the organization.

Get Expert Guidance

Talk to our team of language access experts.
Book a demo and see why thousands of care teams love Martti

Trusted by over 4,000 healthcare facilities and organizations.

Book a demo

Meet the New Martti

Voyce and Martti have joined forces to build the future of integrated medical interpretation.