Chat with us, powered by LiveChat

Get A Free Revenue Cycle Management Assessment

Register Now

NewBecker's 2026 Top RCM · Inc. 5000 · Dallas 100
A behavioral health platform grew collections by $2.4M / year with Plutus Health →
SOC 2 Type 2 · HIPAA · BHCOE · CASP

Get A Free Revenue Cycle Management Assessment

Register Now

PRESS RELEASE

Plutus Health Completes KPMG-Examined SOC 2 Type II Attestation

Monday, August 10, 2026
–
Dallas, TX
(2 min read)
Plutus Health has completed its SOC 2 Type II examination, with the attestation report issued by KPMG after an independent review of how the company protects client data over an extended period. For healthcare organizations that rely on Plutus Health to run their revenue cycle, the report is outside confirmation that the controls guarding their financial and patient information hold up in daily practice, not just on paper.

Inside the SOC 2 Type II Examination

A Type II examination is the most demanding of the two SOC 2 assessments. Rather than checking whether controls exist on a single day, it observes how they perform across a defined window of time. Over that period, KPMG evaluated the way Plutus Health governs security, manages access, encrypts information, monitors its systems, and responds when something looks off. SOC 2 is an attestation standard maintained by the American Institute of Certified Public Accountants (AICPA) and measured against its Trust Services Criteria. Clearing a Type II examination signals that these safeguards were not only designed correctly but operating consistently throughout the review.

Why It Matters for the Practices We Serve

Revenue cycle work runs on some of the most sensitive material a provider holds - patient demographics, insurance data, payer correspondence, and financial records. When a healthcare organization hands that information to an outside partner, a promise of protection isn't enough. The SOC 2 Type II report gives Plutus Health's clients an objective, third-party basis for that trust: confirmation that the controls protecting their data were tested and found to be working, day after day, across the examination period.

Leadership Perspective

"A Type II examination is the harder test. It asks whether your controls actually hold up over months, not whether they happen to exist on the day someone checks. Having KPMG confirm that gives our clients real assurance that data protection is built into how we operate every day, not a box we tick once a year."

- Ravindra MG, Vice President – IT Infrastructure & Infosec, Plutus Health

Ravindra MG

Security That Reinforces Performance

It also adds to the ISO 27001 certification Plutus Health already holds, broadening a portfolio of independently verified security credentials. Read together, the two point to a security program that is reviewed and refined continuously, rather than validated once and shelved.

The attestation sits alongside the operational results Plutus Health already delivers through its OlympusAI workflow- a 98% net collection rate, a 97% first-pass rate, AR days held under 30, and denials kept below 5%. Strong protection and strong performance are meant to reinforce one another: clients get the financial outcomes they came for without giving up control of their data to get them.