If you sell software into healthcare, two acronyms will dominate your security conversations: HIPAA and SOC 2. They get compared constantly and confused almost as often. Buyers ask “are you HIPAA certified and SOC 2 compliant?” — a question that gets both frameworks backwards in a single sentence. This post untangles them: what each one actually is, where they overlap, which one your customers really care about, and how to build one control program that satisfies both without doing the work twice.
The one-sentence versions
HIPAA is a United States federal law. Its Privacy, Security, and Breach Notification Rules (45 CFR Parts 160 and 164) impose mandatory requirements on covered entities and their business associates for protecting protected health information (PHI). Nobody audits you into HIPAA compliance; the law applies automatically, and the Office for Civil Rights enforces it with investigations and civil money penalties.
SOC 2 is a voluntary attestation framework from the AICPA. A licensed CPA firm examines your controls against the Trust Services Criteria — Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are optional add-ons — and issues a report. A Type I report covers control design at a point in time; a Type II report covers operating effectiveness over a period, typically 3 to 12 months.
The categorical difference matters more than any control-level difference: HIPAA is law you must follow; SOC 2 is evidence you choose to produce. You can be sued or fined under HIPAA. Nobody fines you for lacking a SOC 2 — you just lose deals.
Neither one is a certification (and HIPAA never can be)
Worth pausing on, because vendor marketing muddies it relentlessly. There is no such thing as HIPAA certification. HHS does not certify anyone, does not accredit certifiers, and explicitly says third-party “certifications” carry no legal weight. If a vendor’s badge says “HIPAA Certified,” it means exactly as much as the vendor’s own reputation, which is to say: nothing OCR will accept in your defense. What actually exists — and what sophisticated buyers accept — is an independent HIPAA assessment or readiness report that maps your safeguards to the regulatory requirements, backed by the documentation itself.
SOC 2, strictly speaking, is not a certification either — it is an attestation. The auditor doesn’t “pass” you; they issue an opinion on whether your controls were suitably designed and (for Type II) operating effectively. Reports can contain exceptions and still be useful. But because a signed report from a CPA firm exists as an artifact, SOC 2 functions like a credential in sales conversations in a way HIPAA structurally cannot.
Where they overlap: most of the security territory
Here’s the good news for anyone dreading two parallel programs: the HIPAA Security Rule and SOC 2’s Security criteria are aiming at the same target from different angles. Controls that serve both include:
- Risk assessment. HIPAA’s required risk analysis (164.308(a)(1)) and SOC 2’s risk assessment criteria are close cousins. One well-run, documented risk assessment feeds both.
- Access control. Unique user IDs, role-based access, timely deprovisioning, and access reviews satisfy HIPAA’s access management specifications and SOC 2’s logical access criteria simultaneously.
- Encryption. HIPAA treats encryption as addressable (meaning: implement it or document a very good reason); SOC 2 auditors expect it as standard for sensitive data. Encrypt in transit and at rest and both boxes are handled — plus, under HIPAA, properly encrypted data that’s lost generally isn’t a reportable breach.
- Audit logging and monitoring. HIPAA’s audit controls standard and SOC 2’s monitoring criteria both want logs collected and actually reviewed.
- Incident response. Both frameworks require a documented, tested process for detecting, responding to, and learning from incidents.
- Workforce security and training. Background checks, sanction policies, and security awareness training appear in both — our post on building a training program covers a design that satisfies either auditor or investigator.
- Vendor management. SOC 2 wants vendor risk management; HIPAA wants it too, plus a very specific artifact: the business associate agreement.
- Change management, backups, contingency planning. HIPAA’s contingency plan standard (data backup, disaster recovery, emergency mode operations) maps neatly onto SOC 2’s Availability criteria if you include them in scope.
Realistically, an organization with a mature Security Rule program has built 60–80% of what a SOC 2 Security examination will test, and vice versa. The HIPAA Security Rule guide walks the full safeguard list if you want to see the raw material.
Where they genuinely differ
The overlap is real, but so are the gaps — in both directions.
Things HIPAA requires that SOC 2 doesn’t touch
- The Privacy Rule. Patient rights — access to records within 30 days, amendments, accounting of disclosures — plus minimum necessary rules and permitted-use analysis. SOC 2’s optional Privacy criteria are generic and consumer-oriented; they are not the HIPAA Privacy Rule.
- Business associate agreements. A specific, legally required contract with mandatory clauses. No BAA, no compliance, regardless of how good your controls are.
- Breach notification. The 60-day individual notice requirement, HHS reporting, the four-factor risk assessment — covered in depth in our first-72-hours breach guide. SOC 2 requires incident response but imposes no notification duties on anyone.
- Designated officers. HIPAA requires named privacy and security officials.
- Six-year documentation retention for policies, assessments, and training records.
Things SOC 2 brings that HIPAA doesn’t
- Independent examination by default. HIPAA has no routine audit; you self-manage until an investigator shows up. SOC 2 puts a skeptical third party in your controls every year, which keeps programs honest.
- Operating-effectiveness evidence. A Type II report proves controls ran for months, not just that policies exist. HIPAA documentation, left alone, can rot into shelfware.
- A shareable artifact. You can hand a SOC 2 report (under NDA) to a prospect. There is no equivalent official HIPAA document — which is exactly why independent readiness reports exist as a category.
- Broader scope options. Availability and Processing Integrity criteria cover reliability concerns HIPAA barely addresses.
Which one do customers actually ask for?
Depends entirely on who’s buying:
- Hospitals, health systems, and payers ask for both, in a specific shape: a signed BAA plus completed security questionnaires as the HIPAA layer, and a SOC 2 Type II as the general security evidence layer. Increasingly their questionnaires accept a SOC 2 report in lieu of answering 300 questions, which alone can justify the audit cost.
- Enterprise buyers outside healthcare ask for SOC 2 and rarely mention HIPAA unless PHI is in scope.
- Small practices and clinics mostly ask “will you sign a BAA?” and take yes for an answer. They’ve often never heard of SOC 2.
- Procurement and legal teams care about HIPAA because their regulatory exposure flows through you as their business associate; CISOs and security reviewers care about SOC 2 because it’s evidence they can actually evaluate.
The practical takeaway for a health tech company: HIPAA is the legal floor you owe the moment PHI arrives; SOC 2 Type II is the sales asset that shortens enterprise deals. Sequencing-wise, HIPAA first (it’s the law), SOC 2 as soon as revenue justifies it. See how the platforms that manage this compare on our comparison page.
One control set for both: how to actually do it
The wasteful path is two programs, two policy sets, two evidence piles. The efficient path is a single control set mapped to both frameworks. Concretely:
- Write policies once, map twice. Each policy (access control, encryption, incident response, vendor management) carries a mapping table: HIPAA citation on one side, Trust Services Criteria on the other. Our policy templates are built with this dual-mapping in mind.
- Run one risk assessment. Scope it to satisfy 164.308(a)(1) — asset inventory, threats, vulnerabilities, likelihood, impact, documented decisions — and hand the same document to your SOC 2 auditor.
- Collect evidence continuously, not annually. Access review records, training completions, vulnerability scans, backup tests, incident logs. The same artifacts feed the SOC 2 observation window and the HIPAA six-year file.
- Add the HIPAA-only layer explicitly. BAAs (both directions — with your customers and your subprocessors), Privacy Rule procedures, breach notification playbook, named officers. Treat these as a distinct workstream so they don’t fall into the gap between frameworks.
- Consider scoping SOC 2 to include Availability and Confidentiality. For PHI-handling companies, those criteria align with HIPAA’s contingency planning and confidentiality obligations, tightening the overlap further.
- Time the audit after the controls have run. A Type II needs months of operating history; stand the unified control set up first, let it run, then open the observation window.
Done this way, the marginal cost of the second framework drops sharply — most companies find that once HIPAA safeguards genuinely operate, SOC 2 readiness is a gap-closing exercise rather than a second mountain.
Common traps to avoid
- Believing a vendor’s SOC 2 means you inherit compliance. Your cloud provider’s report covers their controls, not your configuration of their services. Shared responsibility cuts both ways under both frameworks.
- Buying a “HIPAA certification” badge. It has no legal standing, and sophisticated buyers know it. Spend the money on a real independent assessment instead.
- Letting SOC 2 scope quietly exclude the systems that hold PHI. Reports have system boundaries; buyers read them. So do plaintiffs’ lawyers.
- Treating either as one-and-done. SOC 2 renews annually by design; HIPAA expects your risk analysis and safeguards to be reviewed as your environment changes. A 2022-dated risk analysis in 2026 is a finding waiting to happen — and it’s the first thing requested in an OCR investigation.
Where to start
If you’re staring at both frameworks wondering how much work is ahead, measure before you plan. Our free HIPAA readiness assessment scores you against the Security Rule safeguards in about ten minutes — and because of the overlap described above, that score doubles as a rough SOC 2 Security gap estimate. From there, pricing covers what a unified program costs to run with SuperHIPAA, or book a 20-minute call and we’ll map your specific customer requirements to the shortest path through both frameworks. One control set, two audiences, no duplicated work — that’s the whole strategy.