HIPAA and SOC 2 Together: Building One Program for Two Different Goals
How health technology companies can coordinate HIPAA safeguards and SOC 2 controls while preserving differences in law, scope, evidence, and assurance.
Health technology companies are frequently asked whether HIPAA compliance and a SOC 2 report can be handled together. The practical answer is yes at the control-program level, but no at the conclusion level.
HIPAA is a body of U.S. legal requirements that applies to covered entities and business associates in defined circumstances. SOC 2 is an attestation engagement in which an independent CPA firm evaluates controls relevant to selected Trust Services Criteria for a described system. A SOC 2 report does not certify HIPAA compliance, and saying “HIPAA certified through SOC 2” is misleading.
The productive approach is to operate one coherent security program, map it carefully to both sets of expectations, and preserve the evidence and analysis unique to each.
Confirm roles before selecting controls
Begin with the organization’s HIPAA role. A covered entity, business associate, subcontractor business associate, and general software vendor can have different obligations. Determine where protected health information is created, received, maintained, or transmitted and whether contractual relationships create business associate responsibilities.
Document data flows, customers, vendors, workforce access, and system boundaries. Distinguish PHI from electronic PHI where the specific rule requires it, while remembering that privacy obligations can extend beyond electronic systems.
For SOC 2, define the system presented in the system description. The boundary may include products, infrastructure, people, procedures, data, and third parties. Do not assume it automatically matches the HIPAA environment. If the SOC 2 scope excludes a support tool containing ePHI, the report cannot provide assurance over controls for that tool.
Use a shared control library
Many well-designed controls can support both programs:
- security risk assessment and remediation;
- workforce access authorization and termination;
- strong authentication and privileged-access review;
- audit logging and security monitoring;
- incident response and escalation;
- change management and secure development;
- vendor risk management;
- backup, recovery, and contingency testing;
- security awareness and role-based training;
- facility and device protections.
Write controls in operational language with owner, scope, frequency, expected evidence, and exception handling. Then map each control to specific SOC 2 criteria and HIPAA requirements.
Mark mappings as direct, partial, or supporting. An annual risk assessment may support SOC 2 risk-identification criteria, while HIPAA’s security risk analysis has a specific focus on potential risks and vulnerabilities to ePHI. A shared process can satisfy both only if its scope and method genuinely address both.
Preserve HIPAA-specific work
HIPAA adds obligations that should not disappear inside a generic security program. Depending on role and facts, work may include:
- business associate agreements and subcontractor flow-downs;
- privacy policies and permitted-use analysis;
- minimum necessary processes;
- individual rights and designated record sets;
- breach risk assessment and required notifications;
- documentation retention;
- sanctions and workforce procedures;
- contingency planning for systems containing ePHI;
- evaluation after environmental or operational changes.
The Security Rule distinguishes required and addressable implementation specifications. “Addressable” does not mean optional. The regulated entity must assess whether a specification is reasonable and appropriate and, if not implemented, document the rationale and any equivalent alternative measure where appropriate.
That analysis is not replaced by a SOC 2 control matrix.
Preserve SOC 2-specific work
SOC 2 requires a suitable system description and management assertion, selected criteria, control design, and independent examination procedures. A Type I report addresses design as of a date; a Type II report also addresses operating effectiveness over a period.
Evidence must align to that period and to the auditor’s samples. An access review completed today may support HIPAA program oversight but cannot prove that quarterly reviews operated throughout a prior SOC 2 period.
The report also includes boundaries, subservice organizations, complementary controls, tests, and results that customers should read carefully. It is not a public seal covering every company process.
Choose additional Trust Services categories based on commitments and customer needs. Availability may be relevant for clinical workflows; Confidentiality may align with contractual protection of sensitive data; Privacy can be relevant but should not be treated as equivalent to HIPAA Privacy Rule compliance.
Coordinate risk assessment
One enterprise risk process can feed both programs if it records enough context. Maintain assets, threats, vulnerabilities, likelihood, impact, existing safeguards, treatment decisions, owners, and due dates. Clearly identify systems containing ePHI and effects on confidentiality, integrity, and availability.
SOC 2 risk work should also consider business objectives, commitments, fraud, vendors, changes, and selected criteria. Rather than conducting two disconnected workshops, use a shared risk register with views or tags for each framework and perform framework-specific completeness reviews.
Reassess after major architecture, vendor, product, or regulatory changes. Acquisition of a clinical customer or introduction of an AI transcription provider can change data flows and risk even if the annual assessment is months away.
Integrate incident response carefully
A common response plan can define detection, triage, containment, evidence preservation, recovery, and lessons learned. Add decision paths for HIPAA-specific legal analysis and contractual notice.
Not every security incident is a reportable HIPAA breach, and not every privacy event is detected by a security alert. Establish who performs the breach risk assessment, what facts are collected, how deadlines are tracked, and how business associates and covered entities coordinate.
Exercise scenarios involving ePHI. A tabletop might test compromised support credentials, ransomware affecting availability, or a subprocessor exposing patient data. Retain the scenario, participants, decisions, gaps, and remediation evidence.
Reuse evidence without losing context
Identity logs, access reviews, risk records, training reports, vendor assessments, backup tests, vulnerability reports, and incident tickets can support both programs. Maintain an evidence catalog that records source, owner, period, systems covered, and integrity checks.
However, evidence reuse should never imply scope reuse. A cloud configuration report may cover the production account but exclude a separate analytics environment containing ePHI. A workforce training record may show security training while omitting required privacy content.
Perform separate gap assessments against authoritative HIPAA requirements and selected SOC 2 criteria. The shared library should make gaps easier to see, not hide them behind a “mapped” status.
Sequence the work realistically
First, establish HIPAA applicability, roles, data flows, agreements, and risk analysis. These are legal and operational foundations, not items to defer until a SOC 2 audit.
Second, stabilize shared controls and collect evidence through normal operations. Third, conduct SOC 2 readiness work, correct gaps, define the examination scope and criteria, and coordinate the period with the CPA firm.
Some teams pursue the work in parallel, but audit deadlines should not crowd out breach procedures, BAAs, or safeguards that already apply. Customer pressure for a report does not postpone legal obligations.
The combined program succeeds when teams understand one set of operating responsibilities and compliance leaders can explain how those responsibilities support two distinct goals. Reuse controls, systems, and evidence aggressively. Keep legal analysis, framework scope, and assurance conclusions precise.
Disclaimer: Educational only — not legal advice or an audit opinion. Confirm HIPAA applicability with qualified counsel and SOC 2 scope and evidence with an independent CPA firm.