Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOC 2 vs HIPAA comparison showing HIPAA as US federal law and SOC 2 as an AICPA attestation report

SOC 2 vs HIPAA: The Complete 2026 Compliance Guide

SOC 2 vs HIPAA is a comparison that trips up almost every health-tech founder, because the two are not competing options you pick between. One is a US federal law that already binds you the moment you touch patient data; the other is a voluntary report your customers ask for during procurement. Confusing them costs months of duplicated work — and, worse, leads teams to believe a clean audit report has discharged a legal obligation it never touched.

This guide sets out what each one actually requires, where they overlap, where they do not, and the order to tackle them in. For the wider context, see our complete SOC 2 guide.

SOC 2 vs HIPAA at a glance

The single most useful thing to understand about SOC 2 vs HIPAA is that they sit in different categories entirely. HIPAA is law. SOC 2 is evidence. You do not get to choose whether HIPAA applies to you — the facts of your business decide that. You do get to choose whether to commission a SOC 2 examination, and which parts of your service it covers.

HIPAASOC 2
What it isA US federal law and its implementing rules — Privacy, Security, and Breach NotificationA voluntary attestation examination defined by the AICPA
Who it applies toCovered entities and their business associates that handle protected health informationAny service organization whose customers ask for a report
What it coversProtected health information; the Security Rule covers electronic PHI specificallyWhichever Trust Services Criteria categories you select for the systems in scope
Who assesses youNobody, by default. HHS Office for Civil Rights investigates after complaints and breachesAn independent licensed CPA firm you engage and pay
What you receiveNo artifact. Compliance is a legal state, not a documentA report containing an auditor’s opinion, normally shared under NDA
Is certification available?No — there is no government-recognized HIPAA certificationNo — SOC 2 is an attestation, not a certification
Time frameA continuous obligation from the day you first handle PHIType 1 at a point in time; Type 2 across a period, commonly three to twelve months
Failure looks likeAn OCR investigation, a corrective action plan, civil monetary penalties, state attorney general actionExceptions noted in the report, or a qualified opinion your buyers will read

What HIPAA actually requires

Half of the SOC 2 vs HIPAA confusion disappears once you read what the rules actually say. HIPAA dates to 1996, but the obligations most software companies care about live in the rules written since. The HIPAA Security Rule, at 45 CFR Part 160 and Subparts A and C of Part 164, requires administrative, physical, and technical safeguards protecting the confidentiality, integrity, and availability of electronic PHI. The Privacy Rule governs how PHI may be used and disclosed. The Breach Notification Rule governs what happens when things go wrong.

Three features surprise teams coming from a pure security background:

  • The risk analysis is the foundation. Every other safeguard decision is supposed to flow from a documented, current assessment of risks to ePHI. Our HIPAA risk assessment guide covers what regulators expect to see.
  • Contracts are a control. A covered entity must have a signed business associate agreement with every vendor touching PHI, and business associates must flow the same terms down to their own subcontractors. See our guide to the business associate agreement.
  • The clock is fixed. Individuals must be notified of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more individuals go to the Secretary within the same 60 days; smaller breaches are reported annually, within 60 days of the end of the calendar year. A business associate must notify its covered entity within 60 days of discovery. Those breach notification requirements are not negotiable and not risk-rated.

One live caveat: HHS published a proposed rule on 6 January 2025 that would substantially rewrite the Security Rule. As of publication it remains proposed, not final, and the timetable has slipped more than once. We track it in our note on the HIPAA Security Rule update.

What a SOC 2 report actually proves

A SOC 2 examination is performed by a licensed CPA firm against the AICPA’s Trust Services Criteria. The Security category — the common criteria — is always included. Availability, Processing Integrity, Confidentiality, and Privacy are optional, and you choose which to add based on what you promise customers.

The output is a report, not a badge. It describes your system, lists the controls you claimed, records what the auditor tested, and states an opinion. A Type 1 report covers control design at a single date; a Type 2 covers operating effectiveness across a review period. Enterprise buyers almost always want the Type 2. Reports are typically refreshed annually and handed out under NDA, which is why a bridge letter exists to cover the gap between report periods.

Crucially, the scope is yours to define. That flexibility is what makes a SOC 2 useful commercially — and, in the SOC 2 vs HIPAA comparison, what makes it a poor substitute for a legal obligation whose scope somebody else already set.

SOC 2 vs HIPAA: the five differences that matter

Strip away the detail and the SOC 2 vs HIPAA distinction comes down to five things:

  1. Obligation versus option. HIPAA applies by operation of law. SOC 2 applies because a customer asked.
  2. Fixed scope versus chosen scope. HIPAA’s scope is every system that creates, receives, maintains, or transmits PHI. SOC 2’s scope is whatever boundary you and your auditor agree.
  3. Self-determined versus independently tested. Nobody signs off your HIPAA program in advance. A CPA firm tests and signs off your SOC 2 controls.
  4. No artifact versus a shareable report. There is nothing to send a prospect that proves HIPAA compliance. A SOC 2 report is exactly that artifact.
  5. Enforcement after the fact versus exceptions on the page. HIPAA failures typically surface through a breach or a complaint. SOC 2 failures surface as exceptions your buyers read.

Where the two overlap — and where they do not

The SOC 2 vs HIPAA overlap is wider than most teams assume, and the good news is that most of the engineering work is shared. Access control, workforce onboarding and offboarding, security awareness training, encryption in transit and at rest, logging and monitoring, incident response, vendor risk management, and a documented risk assessment all serve both. Build them once, evidence them once.

The gap is narrower than people fear but sharper than they expect. A standard SOC 2 examination does not test your business associate agreements, your breach notification mechanics against the 60-day clock, the minimum necessary standard, the Notice of Privacy Practices, or individual rights such as access, amendment, and an accounting of disclosures. Those are HIPAA-specific, and a Security-only SOC 2 will simply not look at them. Our HIPAA compliance checklist sets out what is left over.

Traffic runs the other way too. SOC 2 asks for change management discipline, availability commitments, and continuous monitoring in a level of detail HIPAA never spells out.

If you want one engagement to speak to both, ask your CPA firm about a SOC 2 examination with additional subject matter — often called SOC 2+. The auditor maps your existing controls to the HIPAA Security Rule administrative, physical, and technical safeguard standards at 45 CFR 164.308–316, tests them alongside the Trust Services Criteria, and reports the results in one document. It is not a HIPAA certification, because none exists, but it is the closest thing to a single answer for a buyer asking both questions.

SOC 2 vs HIPAA: which should you do first?

For anyone handling PHI, the SOC 2 vs HIPAA sequencing question answers itself: HIPAA first, because it is not optional and it is already running. You do not get to defer a legal obligation until a deal makes it commercially interesting. Get the risk analysis done, the safeguards implemented, the policies written, and the BAAs signed.

Then let sales pull the SOC 2. A sensible order looks like this:

  1. Confirm your status — covered entity, business associate, or neither — and document the reasoning.
  2. Run and record the HIPAA risk analysis, then remediate what it finds.
  3. Put the policy suite and BAAs in place, and train the workforce.
  4. Pick your Trust Services Criteria categories based on what you contractually promise customers.
  5. Run a readiness assessment against those criteria. Most of the gaps will be evidence, not controls.
  6. Choose Type 1 to unblock a deal quickly, or go straight to a Type 2 observation period if your buyers will wait.

Teams that treat SOC 2 vs HIPAA as one program rather than two save real calendar time, because the policies, registers, and evidence are shared. Teams that run them separately end up maintaining two versions of the same access control policy and reconciling them at audit.

Frequently asked questions

Does a SOC 2 report make me HIPAA compliant?

No. A SOC 2 report evidences that the controls you defined operated as described against the Trust Services Criteria you selected. It does not test business associate agreements, breach notification timing, the minimum necessary standard, or individual rights, all of which HIPAA requires.

Is there such a thing as HIPAA certification?

No. There is no government-issued or government-recognized HIPAA certification. Vendors selling “HIPAA certified” badges are selling their own assessment, not a regulatory approval. Compliance is a continuing legal state, evidenced by your risk analysis, safeguards, contracts, and records.

Can one examination cover both SOC 2 and HIPAA?

Partly. A SOC 2 examination with additional subject matter, known as SOC 2+, maps and tests your controls against the HIPAA Security Rule safeguards alongside the Trust Services Criteria, producing one report. It still does not discharge Privacy Rule or Breach Notification Rule obligations.

Do I still need a BAA if my vendor has a SOC 2 report?

Yes. A signed business associate agreement is a legal requirement whenever a vendor handles PHI on your behalf. A SOC 2 report is useful diligence evidence, but it is not a substitute for the contract.

SOC 2 vs HIPAA: which matters more to enterprise healthcare buyers?

Both, for different reasons. Hospital systems and health plans treat HIPAA compliance and a signed BAA as the legal baseline for even starting a conversation, and a SOC 2 Type 2 report as the independent evidence that your wider security program works. Answering the SOC 2 vs HIPAA question with “we have both” is what closes the security review.

The short answer

Do not think of SOC 2 vs HIPAA as a choice. HIPAA is the floor you are standing on whether you have looked down or not; SOC 2 is the document that lets a stranger verify you built something on top of it. Sequence them in that order, share the evidence between them, and neither one has to be a scramble.

Skip the drafting: our SOC 2 Toolkit gives you the policies, control documentation, and evidence templates mapped to the Trust Services Criteria, editable in Word and Excel, and the HIPAA Toolkit adds the 160+ PHI-specific policies, BAAs, and registers a SOC 2 will not cover. For a comparison of the other framework buyers commonly ask about, see ISO 27001 vs SOC 2.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.