
OpenEvidence grew faster than any compliance program around it. Major health systems were signing Business Associate Agreements and sending vendor security reviews that expected a SOC 2 report, not a promise. HIPAA compliance was in place, but HIPAA answers a different question than the Trust Services Criteria, and the audit evidence did not exist yet. At the same time, the company was blocking EU access entirely because GDPR obligations were unresolved, which left demand from European clinicians on the table. The team was small, senior, and busy building the product. Compliance had to move at the company's speed without borrowing its engineers for months.
BD Emerson ran security and privacy as one program. On the SOC 2 side, the team designed controls across identity, endpoints, cloud infrastructure, and change management, wrote the policy set, and stood up evidence collection so proof accumulated as a byproduct of operating. An independent audit firm issued the SOC 2 Type 1 in August 2025, roughly ninety days in. The Type 2 observation window opened days later, ran August 11 through November 11, 2025, and the completed Type 2 report followed. On the privacy side, BD Emerson built the GDPR program: data processing agreement, records of processing, privacy policy rework, cookie consent, and an EU representative arrangement, so the company could open Europe deliberately rather than react to it.
OpenEvidence now holds a completed SOC 2 Type 2 and answers institutional diligence with a report instead of a meeting. The program is annual by design: the next observation window was booked for the same August through November period the following year, on the same evidence base. Security and privacy kept pace with a company that grew into one of the most widely used clinical tools in the country.