How Jiro Health ran a dual SOC 2 and HIPAA audit on one control set
Jiro turns real-world practice data into personalized clinical, operational, and financial intelligence for clinicians, benchmarked against peers and updated continuously. Jiro is HIPAA compliant, holds a SOC 2 Type II report, and offers accredited CME. For more information, visit jirohealth.com.
Jiro Health is a Practice Intelligence platform that turns real-world practice data into personalized clinical, operational, and financial intelligence for clinicians. Because the platform handles protected health information at scale, rigorous security and regulatory compliance are essential to earning and maintaining clinicians' trust.
The challenge
Jiro Health's CEO, Greg Field, is no stranger to the audit process; he navigated compliance in a past venture with a turnkey tool and knew a pre-written control library would be a mismatch for a complex, data-intensive healthcare technology business. When the controls arrive already written, the business either changes its operations to match them or explains the gap at every audit.
What I remember [about previous tools] was it was very turnkey… like ordering from McDonald's… exactly what's on the menu. I'm not sure that model would have been able to support the dual SOC 2 plus HIPAA audit with the level of complexity in our business.
The solution
Jiro used Openlane to write controls based on how the business operates, not adopted from a vendor's menu. The distinction is practical: a stock control library reads like a list of requirements, and teams treat it that way. The control says endpoint monitoring or device management tools, so someone procures endpoint monitoring or a device management platform, assuming the framework requires it. Usually it doesn't. The framework asks you to manage a risk, and the pre-written control is one vendor's opinion of how, an opinion you often can't edit without breaking the other assumptions attached to it. It's the same pattern that keeps password rotation policies alive long after the security guidance behind them shifted.
Openlane works the other way around: the platform bends to the way the customer works. Jiro wrote control language that represents what the business does and collected evidence against that, so the audit reviewed the company as it runs.
Pricing followed the same shape. The Compliance module includes unlimited frameworks with no per-framework charge, and the price is published, so adding HIPAA beside SOC 2 did not raise the bill or require a sales call.
The experience
Bergdis Magnusdottir, Jiro Health's Head of Operations, ran the audit program day to day. Task assignment in Openlane gave Jiro's CTO and Ops departments clear ownership: every control had an owner and a due date, so compliance work didn't pool on one founder's desk. The same machinery simplified the auditor interactions — evidence requests, task assignments, and review status lived in one place, visible to both sides, so the team could see when the auditor asked for more information and respond. Openlane's team stayed directly available through preparation and observation, and when Jiro Health needed a specific feature or workflow adjustment, they asked, and the team built it.
Every time we brought feedback to Openlane, they delivered. It genuinely felt like they cared about making us a success.
The results
The expected timeline held: one to two months of preparation, a three-month observation window, and a signed report about five months after starting, for a dual-framework audit. Because evidence flowed to the auditors throughout observation rather than arriving in an end-of-audit bundle, there were no late surprises, and Jiro's report closed with zero findings on the first attempt. Beyond the report itself, Jiro came away with:
- A single SOC 2 Type II and HIPAA report to hand enterprise customers
- Evidence and policy management that runs in one system
- A Trust Center that answers security reviews before they become questionnaires
Jiro Health now maintains both frameworks in Openlane and can add the next one without starting over.
Bring your next audit to a program you defined
No credit card. 30-day free trial.