On this page

SOC 2 is a voluntary attestation: a CPA firm tests your controls against the Trust Services Criteria. HIPAA is federal law for covered entities and their business associates. Under the HIPAA rules in force on October 8, 2026, a clean SOC 2 report is evidence for many Security Rule safeguards but does not make a company HIPAA compliant. HIPAA does not require SOC 2, and HHS issues no HIPAA certification.

In our mapping, typical SOC 2 evidence fully covers 33 of the 65 Security Rule provisions and partly covers 26 more. It does not give you business associate agreements with the terms the rule requires, a risk analysis of all electronic protected health information (ePHI) as 164.308(a)(1)(ii)(A) defines it, a written decision for each addressable specification, six-year retention of that documentation, or the breach notification duties in 164.400 to 164.414.

The Security Rule’s administrative, physical and technical safeguards (45 CFR 164.308 to 164.312) contain 18 standards and 36 implementation specifications. The organizational requirements (164.314) and the documentation section (164.316) bring the totals to 22 standards and 43 implementation specifications. We count 164.314 as four specifications: three titled business associate specifications and one untitled block for group health plans. One row per standard and per specification gives 65 Security Rule rows, and the breach notification table adds 17.

This page is the HIPAA entry in our comparison of SOC 2 with other compliance frameworks, and the HIPAA reference card summarizes the law on its own. To see HIPAA beside ISO 27001 and PCI DSS on one grid, use the SOC 2 framework comparison chart. If you are still deciding whether a healthcare company needs SOC 2 at all, start with SOC 2 for healthcare companies.

Does SOC 2 make you HIPAA compliant?

No. A SOC 2 report shows that a CPA firm tested your controls against the Trust Services Criteria for the system you described. HIPAA compliance means meeting every applicable standard in the Security Rule for all ePHI you hold (164.306(c)), plus the Privacy and Breach Notification Rules where they apply to you.

The two overlap heavily on access control, logging, incident response, backups and vendor oversight, which is why the same evidence can serve both. They part ways on legal obligations that no Trust Services Criterion tests: the contract terms a business associate agreement must carry, the HIPAA risk analysis, documented decisions on addressable specifications, six-year document retention and breach notification deadlines.

TopicSOC 2HIPAA
What it isA voluntary attestation under AICPA standardsFederal law: the Privacy, Security and Breach Notification Rules in 45 CFR Part 164
Who it applies toService organizations whose customers ask for a reportCovered entities (health plans, health care clearinghouses, and health care providers that conduct standard transactions electronically) and their business associates
Who checksA licensed CPA firm you hireThe HHS Office for Civil Rights enforces the rules; no one certifies compliance
What you getA report with the auditor’s opinion: Type 1 covers design at a date, Type 2 covers operation over a periodNo certificate; your own documented compliance
ScopeThe system and criteria management describes; Security is always includedAll ePHI for the Security Rule; unsecured protected health information (PHI), in any form, for breach notification
Breach noticeThe criteria set no deadlineNotice to individuals within 60 calendar days of discovery at the latest; breaches affecting fewer than 500 people go to HHS in an annual report (164.408(c)); a business associate notifies the covered entity (164.410)

Does HIPAA require a SOC 2 report?

No. The Security Rule sets safeguards, not an audit format, and neither the Security Rule nor the Breach Notification Rule mentions SOC 2, attestation or certification. Customers usually ask for SOC 2 because their vendor reviews want an independent report, so the requirement comes from contracts, not from HHS.

If a customer asks for HITRUST rather than HIPAA evidence, our SOC 2 vs HITRUST comparison covers that choice.

How to read the crosswalk

Each row is one CFR provision, judged for the company that holds the SOC 2 report and must meet HIPAA, usually a business associate such as a software or service company handling ePHI for health plans or providers. We built the mapping from the rule text in the eCFR, using NIST SP 800-66 Revision 2 (February 2024) as the implementation reference. Criteria are listed by ID only; our Trust Services Criteria guide explains each one.

  • Covered: typical SOC 2 evidence for the listed criteria meets the provision.
  • Partly: SOC 2 evidence meets part of it, and a HIPAA-specific element remains.
  • Not covered: no criterion tests it, or SOC 2 has no counterpart for the duty (for example, a notice only a covered entity sends). The criteria cell is left empty, and the last column gives the reason with its cite.

R/A is the rule’s own mark: R for Required, A for Addressable. A standard that has implementation specifications is left blank, because the rule marks only the specifications. A standard with no specifications shows R, as the rule’s matrix in Appendix A to Subpart C does.

For every row marked A, HIPAA also needs a documented decision: implement the specification if it is reasonable and appropriate, or record why not and adopt an equivalent measure where reasonable (164.306(d)(3)). HHS guidance says the decision must be documented in writing either way, with the factors considered and the risk assessment results behind it (HHS FAQ 2020). A SOC 2 report does not produce that record. Where an A row is otherwise Covered, the last column names that decision as the only remaining item.

Three conditions apply to every verdict. The report’s system description must include every system that creates, receives, maintains or transmits ePHI. Rows that rely on Availability (A1), Processing Integrity (PI), Confidentiality (C) or Privacy (P) criteria assume those categories are in the report’s scope, because Security is the only required category. Where a report carves out a cloud provider, the physical safeguard rows for its data centers rest on that provider’s own report.

Our coverage verdicts are an editorial mapping, not an auditor’s opinion or legal advice. Download the crosswalk as a CSV, with no signup:

Download the crosswalk as a CSV

Which administrative safeguards does a SOC 2 report cover?

SOC 2 evidence fully covers 16 of the 30 administrative safeguard rows in 45 CFR 164.308 and partly covers the other 14. The largest gaps are the HIPAA risk analysis, the evaluation against the Security Rule itself, emergency mode operations and business associate agreements.

CFR citeProvisionR/ASOC 2 criteriaCoverageWhat HIPAA still needs
164.308(a)(1)Security management processCC3.2, CC5.1, CC7.2, CC7.4PartlyA risk analysis and a risk management plan built for ePHI, as 164.308(a)(1)(ii)(A) and (B) require.
164.308(a)(1)(ii)(A)Risk analysisRCC3.1, CC3.2, CC3.4PartlyAn accurate and thorough assessment of risks to all ePHI the company holds, wherever it is stored or sent; a SOC 2 risk assessment covers the system in the report.
164.308(a)(1)(ii)(B)Risk managementRCC3.2, CC5.1PartlySecurity measures that bring each risk found in the HIPAA risk analysis down to a reasonable and appropriate level.
164.308(a)(1)(ii)(C)Sanction policyRCC1.1, CC1.5CoveredNone beyond the SOC 2 evidence.
164.308(a)(1)(ii)(D)Information system activity reviewRCC7.2, CC7.3CoveredNone beyond the SOC 2 evidence.
164.308(a)(2)Assigned security responsibilityRCC1.3PartlyOne named security official responsible for the Security Rule policies and procedures; the criteria do not require a single named person.
164.308(a)(3)Workforce securityCC1.4, CC6.1, CC6.2, CC6.3CoveredNone beyond the SOC 2 evidence.
164.308(a)(3)(ii)(A)Authorization and/or supervisionACC6.2, CC6.3CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(3)(ii)(B)Workforce clearance procedureACC1.4, CC6.2CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(3)(ii)(C)Termination proceduresACC6.2CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(4)Information access managementCC6.1, CC6.2, CC6.3PartlyAccess rules that also meet the Privacy Rule, including minimum necessary (164.502(b)), because the standard ties access to Subpart E.
164.308(a)(4)(ii)(A)Isolating health care clearinghouse functionsRCC6.1, CC6.3PartlyIf the company is a health care clearinghouse inside a larger organization, separation of the clearinghouse’s ePHI from the rest of that organization.
164.308(a)(4)(ii)(B)Access authorizationACC6.1, CC6.2, CC6.3CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(4)(ii)(C)Access establishment and modificationACC6.2, CC6.3CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(5)Security awareness and trainingCC1.4, CC2.2CoveredNone beyond the SOC 2 evidence.
164.308(a)(5)(ii)(A)Security remindersACC2.2CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(5)(ii)(B)Protection from malicious softwareACC2.2, CC6.8CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(5)(ii)(C)Log-in monitoringACC6.1, CC7.2CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(5)(ii)(D)Password managementACC2.2, CC6.1CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(6)Security incident proceduresCC7.3, CC7.4PartlyIncident policies written to HIPAA’s definition of a security incident, which includes attempted as well as successful unauthorized access (164.304).
164.308(a)(6)(ii)Response and reportingRCC7.3, CC7.4, CC7.5PartlyA record of each security incident and its outcome under HIPAA’s definition, which counts attempts (164.304); a SOC 2 incident log may use a narrower threshold.
164.308(a)(7)Contingency planCC7.5, CC9.1, A1.2, A1.3PartlyA plan for emergencies that damage systems holding ePHI, including the emergency mode operation plan in 164.308(a)(7)(ii)(C).
164.308(a)(7)(ii)(A)Data backup planRCC7.5, A1.2CoveredNone beyond the SOC 2 evidence.
164.308(a)(7)(ii)(B)Disaster recovery planRCC7.5, CC9.1, A1.2, A1.3CoveredNone beyond the SOC 2 evidence.
164.308(a)(7)(ii)(C)Emergency mode operation planRCC9.1, A1.2PartlyProcedures that keep critical business processes running with ePHI security intact during an emergency; recovery testing shows a restore, not security during the emergency.
164.308(a)(7)(ii)(D)Testing and revision proceduresACC7.5, A1.3CoveredOnly the documented addressable decision (164.306(d)(3)).
164.308(a)(7)(ii)(E)Applications and data criticality analysisACC3.2, CC9.1PartlyA written ranking of applications and data by how critical they are to the contingency plan; the criteria do not require one.
164.308(a)(8)EvaluationRCC4.1, CC4.2PartlyA periodic evaluation of how well the policies and procedures meet the Security Rule, repeated after environmental or operational changes; a SOC 2 examination measures against the Trust Services Criteria instead.
164.308(b)(1)Business associate contracts and other arrangementsCC9.2PartlySatisfactory assurances documented in a business associate agreement, which a business associate must also obtain from each subcontractor that handles ePHI (164.308(b)(2)).
164.308(b)(3)Written contract or other arrangementRCC9.2, P6.4PartlyA written agreement with the terms 164.314(a) lists; vendor reviews show oversight, not those terms.

Which physical safeguards does SOC 2 cover?

SOC 2 evidence fully covers 6 of the 12 physical safeguard rows in 45 CFR 164.310, partly covers 5, and does not cover 1, the facility maintenance records specification. Most partial rows concern emergencies, workstations away from the office and records of equipment movements.

CFR citeProvisionR/ASOC 2 criteriaCoverageWhat HIPAA still needs
164.310(a)(1)Facility access controlsCC6.4CoveredNone beyond the SOC 2 evidence.
164.310(a)(2)(i)Contingency operationsACC6.4, A1.2PartlyProcedures that let authorized people into facilities during an emergency to restore lost data; SOC 2 physical access testing covers normal operation.
164.310(a)(2)(ii)Facility security planACC6.4CoveredOnly the documented addressable decision (164.306(d)(3)).
164.310(a)(2)(iii)Access control and validation proceduresACC6.4, CC8.1CoveredOnly the documented addressable decision (164.306(d)(3)).
164.310(a)(2)(iv)Maintenance recordsANot coveredA record of repairs and changes to the security-related physical parts of a facility, such as doors and locks; no criterion asks for one (164.310(a)(2)(iv)).
164.310(b)Workstation useRCC2.2, CC5.3PartlyRules for how and where workstations that access ePHI are used, including their physical surroundings.
164.310(c)Workstation securityRCC6.4, CC6.7PartlyPhysical safeguards for every workstation that accesses ePHI, including laptops used away from the office; SOC 2 testing usually covers facilities and device encryption, not the physical protection of each workstation.
164.310(d)(1)Device and media controlsCC6.5, CC6.7CoveredNone beyond the SOC 2 evidence.
164.310(d)(2)(i)DisposalRCC6.5, C1.2CoveredNone beyond the SOC 2 evidence.
164.310(d)(2)(ii)Media re-useRCC6.5CoveredNone beyond the SOC 2 evidence.
164.310(d)(2)(iii)AccountabilityACC6.1PartlyA record of each movement of hardware and electronic media holding ePHI and the person responsible; an asset inventory alone does not record movements.
164.310(d)(2)(iv)Data backup and storageAA1.2PartlyA retrievable, exact copy of ePHI made before equipment is moved; scheduled backup testing does not show that step.

Which technical safeguards does SOC 2 cover?

SOC 2 evidence fully covers 9 of the 12 technical safeguard rows in 45 CFR 164.312 and partly covers 3: emergency access, the access control standard that includes it, and the mechanism that proves ePHI was not altered. Encryption is addressable under the current rule, at 164.312(a)(2)(iv) for stored data and 164.312(e)(2)(ii) for transmission, so a company that does not encrypt must document why and what it uses instead.

CFR citeProvisionR/ASOC 2 criteriaCoverageWhat HIPAA still needs
164.312(a)(1)Access controlCC6.1, CC6.2, CC6.3PartlyThe emergency access procedure in 164.312(a)(2)(ii).
164.312(a)(2)(i)Unique user identificationRCC6.1, CC6.2CoveredNone beyond the SOC 2 evidence.
164.312(a)(2)(ii)Emergency access procedureRCC6.1PartlyA procedure for obtaining necessary ePHI during an emergency; the criteria do not require one.
164.312(a)(2)(iii)Automatic logoffACC6.1CoveredOnly the documented addressable decision (164.306(d)(3)).
164.312(a)(2)(iv)Encryption and decryptionACC6.1CoveredOnly the documented addressable decision (164.306(d)(3)); ePHI encrypted to HHS guidance is also not unsecured PHI for breach notification (164.402), if the decryption key was not also compromised.
164.312(b)Audit controlsRCC7.2CoveredNone beyond the SOC 2 evidence.
164.312(c)(1)IntegrityCC6.1, CC8.1CoveredNone beyond the SOC 2 evidence.
164.312(c)(2)Mechanism to authenticate electronic protected health informationACC7.1PartlyElectronic checks, such as checksums or digital signatures, over the ePHI itself; change detection under the criteria usually covers system and configuration files, not each record.
164.312(d)Person or entity authenticationRCC6.1CoveredNone beyond the SOC 2 evidence.
164.312(e)(1)Transmission securityCC6.1, CC6.7CoveredNone beyond the SOC 2 evidence.
164.312(e)(2)(i)Integrity controlsACC6.7CoveredOnly the documented addressable decision (164.306(d)(3)).
164.312(e)(2)(ii)EncryptionACC6.7CoveredOnly the documented addressable decision (164.306(d)(3)).

Does SOC 2 cover business associate agreements?

Only in part. SOC 2 vendor management (CC9.2) and, when Privacy is in scope, vendor privacy commitments (P6.4) show that a company oversees its subcontractors. No criterion tests whether a business associate agreement exists or carries the terms 45 CFR 164.314 requires. Of the 6 rows, 2 are partly covered and 4 are not covered.

CFR citeProvisionR/ASOC 2 criteriaCoverageWhat HIPAA still needs
164.314(a)(1)Business associate contracts or other arrangementsCC9.2, P6.4PartlyEach business associate agreement must meet 164.314(a)(2)(i), (ii) or (iii), whichever applies.
164.314(a)(2)(i)Business associate contractsRNot coveredAn agreement that binds the business associate to comply with the Security Rule, bind its subcontractors, and report security incidents and breaches (164.314(a)(2)(i)(A) to (C)); no criterion tests contract terms.
164.314(a)(2)(ii)Other arrangementsRNot coveredAn arrangement that meets 164.504(e)(3), such as a memorandum of understanding between two government entities; SOC 2 has no counterpart.
164.314(a)(2)(iii)Business associate contracts with subcontractorsRCC9.2, P6.4PartlySubcontractor agreements carrying the same terms the business associate accepted; vendor reviews and privacy commitments do not test those terms.
164.314(b)(1)Requirements for group health plansNot coveredApplies only to group health plans, whose plan documents must bind the plan sponsor to safeguard ePHI (164.314(b)(1)); SOC 2 has no counterpart.
164.314(b)(2)Plan document provisionsRNot coveredPlan documents that require the sponsor to implement safeguards, support the plan-sponsor separation that 164.504(f)(2)(iii) requires with security measures, bind its agents and report security incidents (164.314(b)(2)(i) to (iv)).

The text of 164.314(a)(2)(iii) points to 164.308(b)(4), a paragraph that does not exist. The business associate’s duty to obtain assurances from its subcontractors is at 164.308(b)(2). The rule gives 164.314(b)(2) no title, so “Plan document provisions” is our label.

Does SOC 2 cover HIPAA documentation requirements?

In part. SOC 2 evidence fully covers 2 of the 5 rows in 45 CFR 164.316, partly covers 2 and does not cover 1. The criteria set no retention period, while HIPAA requires six years.

CFR citeProvisionR/ASOC 2 criteriaCoverageWhat HIPAA still needs
164.316(a)Policies and proceduresRCC5.3PartlyPolicies and procedures that address each Security Rule standard and implementation specification, with every change documented.
164.316(b)(1)DocumentationCC5.3PartlyWritten records of each action, activity or assessment the Security Rule requires, including the risk analysis and addressable decisions.
164.316(b)(2)(i)Time limitRNot coveredDocumentation kept for 6 years from its creation or the date it was last in effect, whichever is later (164.316(b)(2)(i)); the criteria set no retention period.
164.316(b)(2)(ii)AvailabilityRCC2.2, CC5.3CoveredNone beyond the SOC 2 evidence.
164.316(b)(2)(iii)UpdatesRCC3.4, CC5.3CoveredNone beyond the SOC 2 evidence.

Does SOC 2 cover HIPAA breach notification?

No. None of the 17 breach notification rows is fully covered: 5 are partly covered and 12 are not covered. The Trust Services Criteria set no notice deadline, content, recipient list or delivery method, which is where most of 45 CFR 164.400 to 164.414 sits.

A business associate’s own duty is 164.410: notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. Notices to individuals, the media and HHS (164.404 to 164.408) are covered entity duties, which a business associate supports through its agreement. The rule applies to breaches on or after September 23, 2009 (164.400), so that scope section has no row. This table has no R/A column, because Subpart D marks nothing required or addressable.

CFR citeProvisionSOC 2 criteriaCoverageWhat HIPAA still needs
164.402Definitions: breach and unsecured PHICC7.3PartlyTreat an impermissible use or disclosure of PHI that falls outside the three exclusions as a breach unless a documented assessment of at least the four factors in 164.402 shows a low probability of compromise.
164.404(a)Notification to individualsP6.6PartlyA covered entity duty to notify each affected individual; P6.6, when Privacy is in scope, tests breach notice without HIPAA’s terms.
164.404(b)Timeliness of notificationNot coveredCovered entity duty: notice without unreasonable delay and no later than 60 calendar days after discovery (164.404(b)).
164.404(c)Content of notificationNot coveredCovered entity duty: the five content elements in 164.404(c)(1), written in plain language.
164.404(d)Methods of individual notificationNot coveredCovered entity duty: first-class mail or agreed email, with substitute notice when contact details are out of date (164.404(d)).
164.406(a)Notification to the mediaNot coveredCovered entity duty: notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction (164.406(a)); no criterion requires notice to the media.
164.406(b)Timeliness of notificationNot coveredCovered entity duty: media notice within the same 60-calendar-day limit as individual notice (164.406(b)).
164.406(c)Content of notificationNot coveredCovered entity duty: media notice carries the content 164.404(c) requires (164.406(c)).
164.408(a)Notification to the SecretaryP6.6PartlyA covered entity duty to notify the HHS Secretary of breaches of unsecured PHI; P6.6, when Privacy is in scope, tests breach notice to regulators without HIPAA’s terms.
164.408(b)Breaches involving 500 or more individualsNot coveredCovered entity duty: notify HHS at the same time as the individuals when 500 or more are affected (164.408(b)).
164.408(c)Breaches involving less than 500 individualsNot coveredCovered entity duty: log smaller breaches and report them to HHS within 60 days after the end of each calendar year (164.408(c)).
164.410(a)Notification by a business associateCC7.4, P6.6PartlyNotify the covered entity of each breach of unsecured PHI, treating it as discovered on the first day any employee, officer or agent knew or should have known of it (164.410(a)(2)); CC7.4 incident communication and, with Privacy in scope, P6.6 breach notice cover telling customers, but not this discovery rule.
164.410(b)Timeliness of notificationNot coveredNotice to the covered entity without unreasonable delay and no later than 60 calendar days after discovery (164.410(b)); a business associate agreement may set a shorter window.
164.410(c)Content of notificationNot coveredThe identity of each affected individual and the other details the covered entity needs for its own notices, given at notification or promptly after (164.410(c)).
164.412Law enforcement delayNot coveredA hold on notice when a law enforcement official says it would impede a criminal investigation or damage national security: for the period in a written statement, or up to 30 days after a documented oral one (164.412).
164.414(a)Administrative requirementsNot coveredCovered entity duty: apply the administrative requirements of 164.530, such as training, complaints, sanctions and documentation, to breach notification (164.414(a)).
164.414(b)Burden of proofCC7.3, CC7.4PartlyRecords proving each required notice was sent, or that an incident was not a breach, because 164.414(b) puts that burden on the company.

What does the Privacy Rule ask of a business associate?

A business associate’s Privacy Rule duties arrive mostly through its business associate agreement. It may use or disclose PHI only as that agreement permits or requires, or as law requires (164.502(a)(3)), and it must limit uses, disclosures and requests to the minimum necessary (164.502(b)). The agreement terms in 164.504(e)(2) also require it to report uses or disclosures the agreement does not allow, make PHI available for individuals’ access, amendment and accounting of disclosures, bind subcontractors to the same restrictions, open its records to HHS, and return or destroy PHI when the contract ends where that is feasible. SOC 2’s optional Privacy criteria overlap in places: P4.1 (use limited to identified purposes), P4.3 (disposal), P5.1 and P5.2 (access and correction), P6.4 (vendor privacy commitments) and P6.7 (accounting of disclosures). They test the company’s own privacy commitments rather than these HIPAA terms, and they apply only when Privacy is in the report’s scope.

Will the proposed Security Rule change this mapping?

Possibly, but not yet. HHS announced a proposed rewrite of the Security Rule on December 27, 2024, and the Federal Register published it on January 6, 2025 (90 FR 898). The proposal would remove the distinction between required and addressable implementation specifications, making all of them required with limited exceptions, and it would require encryption and multi-factor authentication, also with limited exceptions. As of October 8, 2026, no final rule has been published in the Federal Register or the eCFR, and HHS states that the current Security Rule remains in effect during the rulemaking. Holland & Knight (July 6, 2026) and Clark Hill (July 13, 2026) report that the federal regulatory agenda now projects final action in July 2027; a projected date is not a deadline. We will revise this crosswalk when a final rule is published.

Can one auditor examine SOC 2 and HIPAA together?

Yes: a CPA firm can add HIPAA criteria to a SOC 2+ examination, or deliver a SOC 2 report alongside a separate HIPAA assessment, and both routes reuse the shared evidence mapped on this page. Our guide to SOC 2 + HIPAA overlay engagements explains how firms scope, price and report each format.

To compare firms that examine both, see our list of SOC 2 and HIPAA audit firms.

Questions about SOC 2 and HIPAA

Is encryption required under HIPAA?

Not under the Security Rule in force on October 8, 2026. Encryption of stored ePHI (164.312(a)(2)(iv)) and of ePHI in transmission (164.312(e)(2)(ii)) are addressable: you implement encryption where it is reasonable and appropriate, or document why not and adopt an equivalent measure (164.306(d)(3)). Encryption that meets HHS guidance also means the data is not “unsecured PHI” (164.402), so losing it does not trigger breach notification as long as the key was not also compromised. The January 2025 proposal would make encryption required, with limited exceptions.

Does a business associate need its own HIPAA risk analysis?

Yes. The risk analysis specification (164.308(a)(1)(ii)(A)) applies to business associates directly and covers all ePHI the business associate holds. A covered entity customer’s analysis does not cover it, and a SOC 2 risk assessment is a starting point for it rather than a substitute.

How much of HIPAA does SOC 2 cover?

In our mapping, typical SOC 2 evidence fully covers 33 of the 65 Security Rule provisions, partly covers 26 and does not cover 6. None of the 17 breach notification rows is fully covered. A single overlap percentage hides two things that change the answer: which criteria the report includes, and whether every ePHI system sits inside its scope.

Sources and method

Our mapping pairs each provision with criteria from the AICPA’s 2017 Trust Services Criteria (revised points of focus, 2022), cited by ID only. Each coverage verdict is our editorial judgment of what typical SOC 2 evidence shows, not an auditor’s opinion and not legal advice; confirm scope with your CPA firm and counsel.