SOC 2 and Your Practice Data, Explained

Key facts
- Shepherd Veterinary Software completed a SOC 2 Type II examination, renewed annually.
- Shepherd data is hosted on Amazon Web Services in the AWS Ohio region (us-east-2), across multiple availability zones.
- Shepherd Pay follows the Payment Card Industry Data Security Standard (PCI DSS).
Choosing veterinary software means working through a long list of practical questions. Is it easy to learn? Will it fit how the team already works? Can we reach a real person?
Here’s one that rarely comes up in a demo: What happens to your practice’s data once it lives in someone else’s system?
That question is what SOC 2 exists to answer.
What is SOC 2?
SOC 2 stands for System and Organization Controls. SOC 2 is a framework developed by the American Institute of CPAs (AICPA) that allows an independent auditor to assess how a software company protects the information its customers hand over.
A SOC 2 examination looks at five trust services criteria:
- Security. Is data protected from unauthorized access?
- Availability. Is the system there when your team needs it?
- Processing integrity. Does the system do what it says it does, accurately and on time?
- Confidentiality. Does sensitive information remain restricted to those who should see it?
- Privacy. Is personal information collected and handled responsibly?
No company grades its own homework here. A third-party CPA firm runs the examination and issues the report.
SOC 2 Type I vs Type II: what’s the difference?
There are two kinds of SOC 2 reports, and vendors sometimes blur the line between them.
| Type I | Type II | |
|---|---|---|
| What it tests | Whether controls are designed correctly | Whether controls actually operated |
| Time covered | One specific date | 3-12 months |
| What it tells a buyer | The program exists on paper | The program held up over time |
A Type II report is the more demanding of the two, because the auditor tests performance across a window rather than checking a snapshot.
So when a veterinary software vendor says they are “SOC 2,” ask two follow-ups: which report, and what period does it cover? A vendor with a current report answers both without hesitating.
What Shepherd’s SOC 2 examination covered
Shepherd completed a SOC 2 Type II examination. The auditor reviewed Shepherd’s policies, procedures, and infrastructure across:
- Data security
- Firewall configuration
- Change management
- Logical access
- Backup management
- Business continuity and disaster recovery
- Security incident response
- Other core areas of the business
We renew the examination annually, so the review is ongoing rather than a one-time exercise.
“For veterinary practices using our software, there’s always a worry about confidential data and financial information ending up somewhere it shouldn’t,” says Kyle Estes, General Manager at Shepherd Veterinary Software. “The SOC 2 examination is how we show our work on that instead of asking anyone to take our word for it.”
Where Shepherd hosts your practice data
Shepherd runs on Amazon Web Services (AWS). Production sits in the AWS Ohio region (us-east-2), distributed across multiple availability zones, which are physically separate data centers. That distribution is designed for redundancy, so a problem in one zone doesn’t take the whole environment with it.
A few specifics your practice manager or IT contact may ask about:
- Data is encrypted in transit between the software, your team, and your records
- Backups run both internally and externally
- The servers hosting Shepherd data have no public access points
Is veterinary software covered by HIPAA?
Generally, no. HIPAA governs protected health information for human patients, and veterinary medical records fall outside it.
That surprises people, and it’s why the question comes up so often. But the absence of HIPAA doesn’t mean the data is low-stakes. Your practice holds client names, addresses, phone numbers, payment details, and staff payroll information. A breach of any of that is a real problem for real people, and it’s a problem your clients will associate with your practice rather than with your software vendor.
Payment security and PCI DSS
If your practice uses Shepherd Pay, card data is handled in accordance with the Payment Card Industry Data Security Standard (PCI DSS) for storage, transmission, and encryption. Whether a client pays at the front desk or from their phone at home, their financial information is handled under that standard.
Security questions to ask any veterinary software vendor
Bring these to your next demo, with us or with anyone else:
- Do you have a current SOC 2 report, and is it Type I or Type II?
- What period does the report cover, and when does the next examination start?
- Can we review the report under NDA?
- Where is our data physically hosted, and who else has access to it?
- What is your process when a security incident happens?
- If we leave, how do we get a complete export of our records?
That last one catches people off guard more than it should. Data portability is a security question too.
Common questions about SOC 2 and veterinary software
Is Shepherd SOC 2 certified? SOC 2 is not technically a certification. SOC 2 is an independent examination that produces a report on how a company’s controls are designed and operating. Shepherd Veterinary Software has completed one and renews it annually. Plenty of vendors use “certified” as shorthand, including us in the past, but “report” is the correct term.
Does SOC 2 mean our data can never be breached? No, and any vendor who says otherwise is overselling. A SOC 2 report is an independent auditor’s assessment of a company’s controls against a recognized standard and documentation of their findings. It is evidence of a security program, not a promise that nothing will ever go wrong.
Is SOC 2 the same as HIPAA? No. HIPAA governs protected human health information and generally does not cover veterinary medical records. SOC 2 speaks to how a software vendor handles the client, payment, and staff data your practice stores.
How often is a SOC 2 examination renewed? Annually. Security programs drift when nobody is checking, so the yearly cycle keeps controls current rather than letting a one-time result persist for years.
Do all veterinary practice management systems have SOC 2 reports? Because the category has no mandated security standard, the answer varies by vendor, which is why the question belongs on your evaluation checklist.
Ask questions
Nobody picks veterinary software because of a compliance report. You pick it because the schedule makes sense, the records match how you already chart, and your team can learn it quickly.
Security sits underneath all of that. You’re handing a vendor your client list, your financials, and years of medical records, and that deserves more than a reassuring answer in a demo.
So take the six questions above to every vendor on your list. Start with us if you like. We’ll tell you which report we hold, what period it covers, and where we’re focused next.
