// field log — medical billing saas
Audit-ready: clean PCI and SOC 2 for a national billing platform.
A national medical billing SaaS platform serving major hospital systems — sensitive financial and patient data, and two of the toughest compliance frameworks in the industry.
// the situation
We managed the private cloud infrastructure and remote office environments behind the platform. PCI DSS and SOC 2 Type II both had to hold up to auditor scrutiny — and Type II doesn't accept a snapshot; it demands proof the controls operate consistently over time.
// what we did
Ran a gap assessment mapping where the two frameworks overlap, hardened the private cloud, implemented centralized logging and formal change management, standardized security across the remote offices, and prepared the complete audit evidence packages.
// results
> PCI DSS audit passed — zero findings.
> SOC 2 Type II audit passed — zero findings.
> Continuous compliance posture, not a yearly scramble.