Skip to main content

Healthcare · Alder Health ·

Healthcare Provider Passes Compliance Audit After Security Overhaul

Ahead of a SOC 2 audit, Nex Lab Systems ran a full security assessment and remediation program that closed every critical finding before the auditor arrived.

SOC 2 audit passed with zero critical findings

Challenge

Alder Health had five months to pass a SOC 2 Type II audit. Two enterprise prospects had made the certification a contract requirement, and neither deal would close without it. Alder had never gone through a third-party security assessment, and the team suspected their access controls and logging wouldn't hold up to scrutiny.

That suspicion turned out to be correct. The company had grown its patient-data application quickly, and security controls hadn't kept pace with the engineering work. With a small internal team and no prior audit experience, Alder needed a partner who could find the gaps fast and help close them before the audit window ran out.

Approach

Nex Lab Systems started with a gap assessment against the SOC 2 trust services criteria, mapping Alder's existing controls against what the audit would require. That assessment fed directly into a full penetration test of the patient-data application, targeting the systems that would draw the most auditor attention.

The testing turned up 3 critical findings and 9 medium findings. The critical issues centered on database access roles that granted far broader read and write permissions than any given service or team member needed, and on missing audit logging for access to patient records, a gap that would have been disqualifying on its own under the audit criteria.

Nex Lab Systems worked alongside Alder's engineering team for 10 weeks, embedding directly in their sprint cycle rather than handing over a report and leaving. Each finding was remediated and verified in place: access roles were rebuilt around least privilege, and logging was added to capture every read and write against patient data. At the end of the 10 weeks, Nex Lab Systems ran a focused re-test against the original findings to confirm the fixes held before the audit began.

Result

Alder passed its SOC 2 Type II audit with zero critical findings outstanding at audit time. All 3 critical and 9 medium issues identified in the initial assessment were remediated and verified before the auditor's fieldwork started.

The certification unblocked the deals it was meant to unblock. Alder closed two enterprise contracts in the following quarter, both of which had been on hold pending SOC 2 compliance. The access control and logging work also gave Alder's engineering team a durable baseline they could carry into future audit cycles, rather than a one-time fix built to pass a single review.

Want a result like this one?

Tell us what you're working with. We reply within one business day.

Start a project