
– Gabor Braun
CTO, Zeto
– Gabor Braun
CTO, Zeto
Introduction
Zeto has been cognizant of healthcare compliance from the beginning, building with due consideration to the security guardrails that protect sensitive data. What changed was the buyer. Once the company started engaging larger institutions, formal compliance programs, security audits, and certifications became critical to getting product clearance.
Selling into a hospital means satisfying a long chain of reviewers. “In hospitals, you need to get a green light from everyone, including the janitor,” remarks Gabor Braun, CTO at Zeto.
The Problem
“Hospitals demand a lot more of their vendors. HIPAA aside, every product and system they work with needs to demonstrate the highest levels of data security,” Gabor notes. Zeto systems already followed HIPAA guidelines for Protected Health Information, yet the team increasingly found itself in sales conversations that turned into detailed examinations of its security posture and IT practices.
Zeto hit the limit on volume. “Each hospital has a list of some 400 IT questions about everything from data encryption to access management,” notes Gabor. “Even the simplest IT questionnaires take as much as a week to complete. To be honest, we do have canned responses for everything but it is not saving us from completing those IT security questionnaires,” he adds.
SOC 2 was the way out of that loop. “Manually filling IT reviews are no longer viable – they are slowing us down. And it is evident that SOC2 can help us circumvent these reviews or at least cut them short,” he notes. The requirement was a partner who could help Zeto get SOC 2 compliant and complete the audit without taking a lot of time away from the leadership team.
“SOC2 can be a prohibiting experience – you can get caught up in very long timelines and very high costs. Sprinto was a good match because it shortened the timelines and was cost-effective right off the bat,” says Gabor.
The Solution
Zeto integrated Sprinto to operationalize a SOC 2 Type 1 and Type 2 compliance program against 3 Trust Service Criteria. Working through the SOC 2 checklist with Sprinto’s automation, the team completed tasks quickly and finished platform implementation in 14 days with 2 members of the Zeto team involved.
That staffing number is the point. Keeping the program off the leadership calendar was a stated requirement going in, and a two-person implementation is what met it.
Impact
Zeto reached SOC 2 Type 1 compliance in 2 weeks and completed its audit 20 days later.
Armed with the SOC 2 report, the team completes security reviews far more efficiently. “The old way meant taking out 8 hours to complete a single security questionnaire. Then, it would take the hospitals another week or so to interpret our answers. With a SOC2 report, the clearance cycle is much faster – you don’t end up explaining as much,” remarks Gabor.
A faster clearance cycle shows up directly in conversion. “As a company that cares greatly about making patient and physician experience seamless, we are happy with how comfortably we moved toward SOC 2 compliance with Sprinto,” notes Gabor.
“The very first day we got our hands on the SOC2 report, we closed a sale!” says Gabor.
Got questions? Talk to our experts!



Healthcare technology, medical devices





