How Jiro Health achieved dual SOC 2 and HIPAA compliance with Openlane
Jiro turns real-world practice data into personalized clinical, operational, and financial intelligence for clinicians, benchmarked against peers and updated continuously. Jiro is HIPAA compliant, SOC 2 certified, and offers accredited CME. For more information, visit jirohealth.com.
Jiro Health is a Practice Intelligence platform that turns real-world practice data into personalized clinical, operational, and financial intelligence for clinicians. Because the platform handles protected health information at scale, rigorous security and regulatory compliance are essential to earning and maintaining clinicians’ trust.
The Challenge
Jiro Health's CEO, Greg Field, is no stranger to the audit process; he navigated compliance in a past venture and knew rigid and expensive tools would be a mismatch for their complex, data-intensive healthcare technology business. Software vendors will advertise "compliance in days" or "fully automated" but those promises often come with a trade-off: the controls are pre-written and the platform is rigid. If your business doesn't fit the mold, you either have to change your operations to match the platform or find a new solution.
What I remember [about previous tools] was it was very turnkey... like ordering from McDonald's... exactly what's on the menu. I'm not sure that model would have been able to support the dual SOC 2 plus HIPAA audit with the level of complexity in our business.
The Solution
Jiro partnered with Openlane and gained the control, flexibility, and transparency to write controls based on how their business actually operates, not adopted from a vendor's menu. The distinction is practical... a stock control library reads like a list of requirements, and teams treat it that way: the control says endpoint monitoring or MDM, so someone procures endpoint monitoring or MDM, assuming the framework requires it. Usually it doesn't. The framework asks you to manage a risk, and the pre-written control is one vendor's opinion of how, an opinion you often can't edit without breaking all the other assumptions they attach to it. It's the same pattern that keeps password rotation policies alive long after the security guidance behind them shifted.
Openlane works the other way around: the platform bends to the way the customer works. Jiro wrote control language that represents what the business does and collected evidence against that, so the audit reviewed the company as it actually runs.
In a similar fashion, Openlane's pricing met Jiro Health's needs; where most compliance automation platforms charge per framework making it so each standard added raises the bill, Openlane provides unlimited frameworks for the same price (without the need for quotes and sales calls).
The Experience
Bergdis Magnusdottir, Jiro Health's Head of Operations, ran the audit program day to day. Task assignment in Openlane empowered Jiro's CTO and Ops departments to have clear ownership: every control had an owner and a due date, so compliance work didn't pool on one founder's desk. The same machinery simplified the auditor interactions - evidence requests, task assignments, and review status lived in one place, visible to both sides, so the team could watch a task move from pending review to the auditor requesting additional information and respond in real time. Openlane's team stayed directly available through preparation and observation, and when Jiro Health needed a specific feature or workflow adjustment, they asked, and the team built it.
Every time we brought feedback to Openlane, they delivered. It genuinely felt like they cared about making us a success.
The Results
The expected timeline held true: one to two months of preparation, a three month observation window, and a signed report about five months after starting, for a dual-framework audit. Because evidence flowed to the auditors throughout observation rather than arriving in an end-of-audit bundle, there were no late surprises, and Jiro's report closed with zero findings on the first attempt. Beyond the report itself, Jiro came away with:
- A single SOC 2 Type II + HIPAA report to hand enterprise customers
- Evidence collection and policy management that runs in one system
- A Trust Center for answering security reviews before they become questionnaires
- A control set that extends to additional frameworks as requirements grow
Jiro Health now maintains both frameworks in Openlane and can add the next one without starting over.