HIPAA + SOC 2
HIPAA vs SOC 2: what each one is, and why healthcare vendors usually need both
HIPAA is a law; SOC 2 is an attestation framework. This guide explains what each covers, who asks for them, and how the work overlaps.
Two different kinds of thing
The most common confusion in healthcare compliance is treating HIPAA and SOC 2 as interchangeable badges. They are different kinds of thing entirely.
HIPAA is a United States federal law. If you are a covered entity (provider, plan, clearinghouse) or a business associate (a vendor handling protected health information for one), it applies to you whether or not you do anything about it. There is no certificate: HHS explicitly does not recognize private HIPAA certifications. Compliance means actually operating the required safeguards — a documented risk analysis, policies, training, business associate agreements, incident procedures — and being able to prove it.
SOC 2 is a voluntary attestation framework defined by the AICPA. An independent CPA firm examines your controls against the Trust Services Criteria and issues a report containing its opinion. Nobody is legally required to have one — but enterprise customers, including hospitals and payers, require it commercially before they will buy.
Who asks for which
- HIPAA is enforced by regulators and demanded by customers via the BAA. A health system will not send you PHI without one, and signing a BAA you cannot honor is a serious risk.
- SOC 2 is demanded by security review teams during procurement. It answers the question "can we trust this vendor's controls?" with an independent opinion instead of your own claims.
The overlap — and the differences that remain
Perhaps 60–70% of the underlying work serves both: access control and MFA, risk assessment, security training, vendor management, incident response, logging, change management, and backup. Build those controls once, and both HIPAA and a SOC 2 auditor will examine the same evidence.
What stays framework-specific:
- HIPAA: PHI data-flow inventories, BAAs, minimum-necessary workflows, and breach-notification rules with regulatory deadlines.
- SOC 2: system description drafting, Trust Services Criteria scoping, the observation window for Type 2, and the auditor relationship itself.
Practical sequencing
For a healthcare vendor, running the two as one program is usually cheaper and faster than sequencing them, because the shared controls are built and evidenced once. If budget forces a choice, HIPAA comes first — it is the legal obligation and the BAA-blocker — with SOC 2 following when the sales pipeline demands it.
Sources
HIPAA does not provide or recognize an official private certification. ClearCompliance provides readiness, implementation, and assessment services; clients remain responsible for their legal obligations. SOC 2 reports are issued by independent qualified CPA firms. ClearCompliance is not a law firm and does not provide legal advice. This article is educational and is not legal advice.