Jul 17, 2026

Henry Cherry on ReleasePoint’s Commitment to Data Security

In an industry built on trust and confidentiality, data security isn’t optional. It’s fundamental. Medical record retrieval companies handle some of the most sensitive information imaginable: protected health information, personally identifiable information, and critical data that impacts life-changing decisions about insurance coverage, disability benefits, and legal cases.

We sat down with Henry Cherry, VP of Information Technology at ReleasePoint, to discuss how the company approaches data security, what clients should expect from their medical records partners, and why ReleasePoint’s commitment to compliance sets a standard in the industry.

What did you want to accomplish in this conversation?

Henry: I wanted to make it clear how proactive and thoughtful we are about our security approach. My team and I take the security of not just ReleasePoint, but our clients’ data as Job One.

We’re constantly monitoring for concerns, alerts, and incidents in real time. But we’re also forward-looking. We keep an eye on potential threats, vulnerabilities, and trends in the cybersecurity world that could impact us down the road.

I’m proud of what we’ve built. I think it’s a differentiator for us, and we have third-party security audits that validate our approach.

How would you characterize ReleasePoint’s operating environment from a regulatory standpoint?

Henry: We’re absolutely in a highly regulated environment. We process, work with, and handle personally identifiable information as well as protected health information on a very frequent basis. That means we have HITECH and HIPAA requirements that we must align with.

We do a very good job of ensuring that we’re current, but we’re also forward-looking for any changes or best practices that emerge as technology evolves.

Can you walk us through ReleasePoint’s approach to compliance reporting and audits?

Henry: On an annual basis, my compliance team undergoes a SOC 2 Type II audit conducted by A-LIGN, a third-party auditor. They examine our security, compliance, HR practices, privacy controls, and incident management — really everything around how we protect and manage information.

We’ve been doing this for four years running and have passed with no problems. I’m actually wrapping up the 2026 report and anticipating it any day now.

What is SOC 2, and why does it matter for medical record retrieval?

Henry: SOC 2 is a highly regarded certification that validates an organization’s commitment to data security. It’s not just about having policies and procedures in place. It’s about proving to a third party that you actually do what you say you do.

The audit evaluates whether we have the right controls in place and whether those controls operated effectively over a sustained period, usually a year. It looks at everything: Do we check for vulnerabilities on a weekly basis? Do we patch systems on time? Do we have proper backups? How do we handle disaster recovery?

Why isn’t SOC 2 compliance required for all medical record retrieval providers?

Henry: I don’t have a clear answer for why it’s not required across the industry. But the value for a client is clear. SOC 2 compliance gives confidence that ReleasePoint not only has a strong security program, but that we’ve put it into process, are actively managing it, and are doing everything we say we do.

Without that third-party validation, a vendor could claim things they don’t actually do. SOC 2 eliminates that uncertainty. My sense is that we’re one of the few companies in our space going through this process annually, and I think it’s a differentiator worth highlighting.

Beyond SOC 2, how else do clients evaluate ReleasePoint’s security practices?

Henry: Most clients ask us to complete an annual security questionnaire. We provide copies of our extensive documentation: data handling procedures, security controls, our information security program, incident response protocols. Basically, we show them exactly how we go about keeping their data safe.

What should clients know about how ReleasePoint protects their data?

Henry: We have encryption at every level, including data at rest. No data is transported or delivered to a client without being encrypted. We have many layers of observability into who’s touching the data, where it’s being transferred, and how it’s being collected.

We’re doing all of the best-practice-related things, but we also respond when clients identify emerging needs. For example, we’re currently working with a potential client asking about post-quantum cryptography, dealing with the threat from quantum computers. That’s a real, near-future concern, and we’re already taking steps to align with it.

As the industry embraces more EHR data and AI solutions, is data security becoming more complex?

Henry: Absolutely. It’s already one of the most critical components of what we do, simply because of the nature of our business. As complexity increases and the rate of change accelerates, we’re going to need to continue investing in our controls, our people, and our automation capabilities.

Our team is always doing continuing education around technology. It’s going to become more demanding as things evolve, but I would like to think we are on top of it. It’s a key part of what we do, and we’re going to keep it that way.

Do you feel like ReleasePoint is setting expectations for the industry, or are clients pushing you to raise the bar?

Henry: A little of both. When we go into security assessments with potential clients, they’re pleasantly reinforced. They see that we have a level of standards that genuinely meet industry best practices.

We’ve got a really good program. Most folks are satisfied with our approach, and they have a lot of confidence in what we do.

What do you love most about your role?

Henry: I love the constantly evolving nature of technology. We have to always be engaged, learning new things, implementing new approaches, coming up with creative solutions to challenges we face. That keeps my day exciting.

My first career was as a paramedic, so facing new challenges has become my nature. Being in technology, especially in a regulated environment, certainly keeps things interesting.

Security You Can Verify, Not Just Trust

The companies entrusted with protected health information have an obligation that goes beyond compliance checkboxes. Henry’s perspective reflects what genuine commitment to data security looks like: annual third-party audits, continuous monitoring, and the organizational discipline to actually do what you say you do.

For organizations evaluating medical record retrieval partners, that distinction matters more than ever.