On this page
- Does SOC 2 make you HIPAA compliant?
- Does HIPAA require a SOC 2 report?
- How to read the crosswalk
- Which administrative safeguards does a SOC 2 report cover?
- Which physical safeguards does SOC 2 cover?
- Which technical safeguards does SOC 2 cover?
- Does SOC 2 cover business associate agreements?
- Does SOC 2 cover HIPAA documentation requirements?
- Does SOC 2 cover HIPAA breach notification?
- What does the Privacy Rule ask of a business associate?
- Will the proposed Security Rule change this mapping?
- Can one auditor examine SOC 2 and HIPAA together?
- Questions about SOC 2 and HIPAA
- Sources and method
SOC 2 is a voluntary attestation: a CPA firm tests your controls against the Trust Services Criteria. HIPAA is federal law for covered entities and their business associates. Under the HIPAA rules in force on October 8, 2026, a clean SOC 2 report is evidence for many Security Rule safeguards but does not make a company HIPAA compliant. HIPAA does not require SOC 2, and HHS issues no HIPAA certification.
In our mapping, typical SOC 2 evidence fully covers 33 of the 65 Security Rule provisions and partly covers 26 more. It does not give you business associate agreements with the terms the rule requires, a risk analysis of all electronic protected health information (ePHI) as 164.308(a)(1)(ii)(A) defines it, a written decision for each addressable specification, six-year retention of that documentation, or the breach notification duties in 164.400 to 164.414.
The Security Rule’s administrative, physical and technical safeguards (45 CFR 164.308 to 164.312) contain 18 standards and 36 implementation specifications. The organizational requirements (164.314) and the documentation section (164.316) bring the totals to 22 standards and 43 implementation specifications. We count 164.314 as four specifications: three titled business associate specifications and one untitled block for group health plans. One row per standard and per specification gives 65 Security Rule rows, and the breach notification table adds 17.
This page is the HIPAA entry in our comparison of SOC 2 with other compliance frameworks, and the HIPAA reference card summarizes the law on its own. To see HIPAA beside ISO 27001 and PCI DSS on one grid, use the SOC 2 framework comparison chart. If you are still deciding whether a healthcare company needs SOC 2 at all, start with SOC 2 for healthcare companies.
Does SOC 2 make you HIPAA compliant?
No. A SOC 2 report shows that a CPA firm tested your controls against the Trust Services Criteria for the system you described. HIPAA compliance means meeting every applicable standard in the Security Rule for all ePHI you hold (164.306(c)), plus the Privacy and Breach Notification Rules where they apply to you.
The two overlap heavily on access control, logging, incident response, backups and vendor oversight, which is why the same evidence can serve both. They part ways on legal obligations that no Trust Services Criterion tests: the contract terms a business associate agreement must carry, the HIPAA risk analysis, documented decisions on addressable specifications, six-year document retention and breach notification deadlines.
| Topic | SOC 2 | HIPAA |
|---|---|---|
| What it is | A voluntary attestation under AICPA standards | Federal law: the Privacy, Security and Breach Notification Rules in 45 CFR Part 164 |
| Who it applies to | Service organizations whose customers ask for a report | Covered entities (health plans, health care clearinghouses, and health care providers that conduct standard transactions electronically) and their business associates |
| Who checks | A licensed CPA firm you hire | The HHS Office for Civil Rights enforces the rules; no one certifies compliance |
| What you get | A report with the auditor’s opinion: Type 1 covers design at a date, Type 2 covers operation over a period | No certificate; your own documented compliance |
| Scope | The system and criteria management describes; Security is always included | All ePHI for the Security Rule; unsecured protected health information (PHI), in any form, for breach notification |
| Breach notice | The criteria set no deadline | Notice to individuals within 60 calendar days of discovery at the latest; breaches affecting fewer than 500 people go to HHS in an annual report (164.408(c)); a business associate notifies the covered entity (164.410) |
Does HIPAA require a SOC 2 report?
No. The Security Rule sets safeguards, not an audit format, and neither the Security Rule nor the Breach Notification Rule mentions SOC 2, attestation or certification. Customers usually ask for SOC 2 because their vendor reviews want an independent report, so the requirement comes from contracts, not from HHS.
If a customer asks for HITRUST rather than HIPAA evidence, our SOC 2 vs HITRUST comparison covers that choice.
How to read the crosswalk
Each row is one CFR provision, judged for the company that holds the SOC 2 report and must meet HIPAA, usually a business associate such as a software or service company handling ePHI for health plans or providers. We built the mapping from the rule text in the eCFR, using NIST SP 800-66 Revision 2 (February 2024) as the implementation reference. Criteria are listed by ID only; our Trust Services Criteria guide explains each one.
- Covered: typical SOC 2 evidence for the listed criteria meets the provision.
- Partly: SOC 2 evidence meets part of it, and a HIPAA-specific element remains.
- Not covered: no criterion tests it, or SOC 2 has no counterpart for the duty (for example, a notice only a covered entity sends). The criteria cell is left empty, and the last column gives the reason with its cite.
R/A is the rule’s own mark: R for Required, A for Addressable. A standard that has implementation specifications is left blank, because the rule marks only the specifications. A standard with no specifications shows R, as the rule’s matrix in Appendix A to Subpart C does.
For every row marked A, HIPAA also needs a documented decision: implement the specification if it is reasonable and appropriate, or record why not and adopt an equivalent measure where reasonable (164.306(d)(3)). HHS guidance says the decision must be documented in writing either way, with the factors considered and the risk assessment results behind it (HHS FAQ 2020). A SOC 2 report does not produce that record. Where an A row is otherwise Covered, the last column names that decision as the only remaining item.
Three conditions apply to every verdict. The report’s system description must include every system that creates, receives, maintains or transmits ePHI. Rows that rely on Availability (A1), Processing Integrity (PI), Confidentiality (C) or Privacy (P) criteria assume those categories are in the report’s scope, because Security is the only required category. Where a report carves out a cloud provider, the physical safeguard rows for its data centers rest on that provider’s own report.
Our coverage verdicts are an editorial mapping, not an auditor’s opinion or legal advice. Download the crosswalk as a CSV, with no signup:
Download the crosswalk as a CSV
Which administrative safeguards does a SOC 2 report cover?
SOC 2 evidence fully covers 16 of the 30 administrative safeguard rows in 45 CFR 164.308 and partly covers the other 14. The largest gaps are the HIPAA risk analysis, the evaluation against the Security Rule itself, emergency mode operations and business associate agreements.
| CFR cite | Provision | R/A | SOC 2 criteria | Coverage | What HIPAA still needs |
|---|---|---|---|---|---|
| 164.308(a)(1) | Security management process | CC3.2, CC5.1, CC7.2, CC7.4 | Partly | A risk analysis and a risk management plan built for ePHI, as 164.308(a)(1)(ii)(A) and (B) require. | |
| 164.308(a)(1)(ii)(A) | Risk analysis | R | CC3.1, CC3.2, CC3.4 | Partly | An accurate and thorough assessment of risks to all ePHI the company holds, wherever it is stored or sent; a SOC 2 risk assessment covers the system in the report. |
| 164.308(a)(1)(ii)(B) | Risk management | R | CC3.2, CC5.1 | Partly | Security measures that bring each risk found in the HIPAA risk analysis down to a reasonable and appropriate level. |
| 164.308(a)(1)(ii)(C) | Sanction policy | R | CC1.1, CC1.5 | Covered | None beyond the SOC 2 evidence. |
| 164.308(a)(1)(ii)(D) | Information system activity review | R | CC7.2, CC7.3 | Covered | None beyond the SOC 2 evidence. |
| 164.308(a)(2) | Assigned security responsibility | R | CC1.3 | Partly | One named security official responsible for the Security Rule policies and procedures; the criteria do not require a single named person. |
| 164.308(a)(3) | Workforce security | CC1.4, CC6.1, CC6.2, CC6.3 | Covered | None beyond the SOC 2 evidence. | |
| 164.308(a)(3)(ii)(A) | Authorization and/or supervision | A | CC6.2, CC6.3 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(3)(ii)(B) | Workforce clearance procedure | A | CC1.4, CC6.2 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(3)(ii)(C) | Termination procedures | A | CC6.2 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(4) | Information access management | CC6.1, CC6.2, CC6.3 | Partly | Access rules that also meet the Privacy Rule, including minimum necessary (164.502(b)), because the standard ties access to Subpart E. | |
| 164.308(a)(4)(ii)(A) | Isolating health care clearinghouse functions | R | CC6.1, CC6.3 | Partly | If the company is a health care clearinghouse inside a larger organization, separation of the clearinghouse’s ePHI from the rest of that organization. |
| 164.308(a)(4)(ii)(B) | Access authorization | A | CC6.1, CC6.2, CC6.3 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(4)(ii)(C) | Access establishment and modification | A | CC6.2, CC6.3 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(5) | Security awareness and training | CC1.4, CC2.2 | Covered | None beyond the SOC 2 evidence. | |
| 164.308(a)(5)(ii)(A) | Security reminders | A | CC2.2 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(5)(ii)(B) | Protection from malicious software | A | CC2.2, CC6.8 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(5)(ii)(C) | Log-in monitoring | A | CC6.1, CC7.2 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(5)(ii)(D) | Password management | A | CC2.2, CC6.1 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(6) | Security incident procedures | CC7.3, CC7.4 | Partly | Incident policies written to HIPAA’s definition of a security incident, which includes attempted as well as successful unauthorized access (164.304). | |
| 164.308(a)(6)(ii) | Response and reporting | R | CC7.3, CC7.4, CC7.5 | Partly | A record of each security incident and its outcome under HIPAA’s definition, which counts attempts (164.304); a SOC 2 incident log may use a narrower threshold. |
| 164.308(a)(7) | Contingency plan | CC7.5, CC9.1, A1.2, A1.3 | Partly | A plan for emergencies that damage systems holding ePHI, including the emergency mode operation plan in 164.308(a)(7)(ii)(C). | |
| 164.308(a)(7)(ii)(A) | Data backup plan | R | CC7.5, A1.2 | Covered | None beyond the SOC 2 evidence. |
| 164.308(a)(7)(ii)(B) | Disaster recovery plan | R | CC7.5, CC9.1, A1.2, A1.3 | Covered | None beyond the SOC 2 evidence. |
| 164.308(a)(7)(ii)(C) | Emergency mode operation plan | R | CC9.1, A1.2 | Partly | Procedures that keep critical business processes running with ePHI security intact during an emergency; recovery testing shows a restore, not security during the emergency. |
| 164.308(a)(7)(ii)(D) | Testing and revision procedures | A | CC7.5, A1.3 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.308(a)(7)(ii)(E) | Applications and data criticality analysis | A | CC3.2, CC9.1 | Partly | A written ranking of applications and data by how critical they are to the contingency plan; the criteria do not require one. |
| 164.308(a)(8) | Evaluation | R | CC4.1, CC4.2 | Partly | A periodic evaluation of how well the policies and procedures meet the Security Rule, repeated after environmental or operational changes; a SOC 2 examination measures against the Trust Services Criteria instead. |
| 164.308(b)(1) | Business associate contracts and other arrangements | CC9.2 | Partly | Satisfactory assurances documented in a business associate agreement, which a business associate must also obtain from each subcontractor that handles ePHI (164.308(b)(2)). | |
| 164.308(b)(3) | Written contract or other arrangement | R | CC9.2, P6.4 | Partly | A written agreement with the terms 164.314(a) lists; vendor reviews show oversight, not those terms. |
Which physical safeguards does SOC 2 cover?
SOC 2 evidence fully covers 6 of the 12 physical safeguard rows in 45 CFR 164.310, partly covers 5, and does not cover 1, the facility maintenance records specification. Most partial rows concern emergencies, workstations away from the office and records of equipment movements.
| CFR cite | Provision | R/A | SOC 2 criteria | Coverage | What HIPAA still needs |
|---|---|---|---|---|---|
| 164.310(a)(1) | Facility access controls | CC6.4 | Covered | None beyond the SOC 2 evidence. | |
| 164.310(a)(2)(i) | Contingency operations | A | CC6.4, A1.2 | Partly | Procedures that let authorized people into facilities during an emergency to restore lost data; SOC 2 physical access testing covers normal operation. |
| 164.310(a)(2)(ii) | Facility security plan | A | CC6.4 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.310(a)(2)(iii) | Access control and validation procedures | A | CC6.4, CC8.1 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.310(a)(2)(iv) | Maintenance records | A | Not covered | A record of repairs and changes to the security-related physical parts of a facility, such as doors and locks; no criterion asks for one (164.310(a)(2)(iv)). | |
| 164.310(b) | Workstation use | R | CC2.2, CC5.3 | Partly | Rules for how and where workstations that access ePHI are used, including their physical surroundings. |
| 164.310(c) | Workstation security | R | CC6.4, CC6.7 | Partly | Physical safeguards for every workstation that accesses ePHI, including laptops used away from the office; SOC 2 testing usually covers facilities and device encryption, not the physical protection of each workstation. |
| 164.310(d)(1) | Device and media controls | CC6.5, CC6.7 | Covered | None beyond the SOC 2 evidence. | |
| 164.310(d)(2)(i) | Disposal | R | CC6.5, C1.2 | Covered | None beyond the SOC 2 evidence. |
| 164.310(d)(2)(ii) | Media re-use | R | CC6.5 | Covered | None beyond the SOC 2 evidence. |
| 164.310(d)(2)(iii) | Accountability | A | CC6.1 | Partly | A record of each movement of hardware and electronic media holding ePHI and the person responsible; an asset inventory alone does not record movements. |
| 164.310(d)(2)(iv) | Data backup and storage | A | A1.2 | Partly | A retrievable, exact copy of ePHI made before equipment is moved; scheduled backup testing does not show that step. |
Which technical safeguards does SOC 2 cover?
SOC 2 evidence fully covers 9 of the 12 technical safeguard rows in 45 CFR 164.312 and partly covers 3: emergency access, the access control standard that includes it, and the mechanism that proves ePHI was not altered. Encryption is addressable under the current rule, at 164.312(a)(2)(iv) for stored data and 164.312(e)(2)(ii) for transmission, so a company that does not encrypt must document why and what it uses instead.
| CFR cite | Provision | R/A | SOC 2 criteria | Coverage | What HIPAA still needs |
|---|---|---|---|---|---|
| 164.312(a)(1) | Access control | CC6.1, CC6.2, CC6.3 | Partly | The emergency access procedure in 164.312(a)(2)(ii). | |
| 164.312(a)(2)(i) | Unique user identification | R | CC6.1, CC6.2 | Covered | None beyond the SOC 2 evidence. |
| 164.312(a)(2)(ii) | Emergency access procedure | R | CC6.1 | Partly | A procedure for obtaining necessary ePHI during an emergency; the criteria do not require one. |
| 164.312(a)(2)(iii) | Automatic logoff | A | CC6.1 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.312(a)(2)(iv) | Encryption and decryption | A | CC6.1 | Covered | Only the documented addressable decision (164.306(d)(3)); ePHI encrypted to HHS guidance is also not unsecured PHI for breach notification (164.402), if the decryption key was not also compromised. |
| 164.312(b) | Audit controls | R | CC7.2 | Covered | None beyond the SOC 2 evidence. |
| 164.312(c)(1) | Integrity | CC6.1, CC8.1 | Covered | None beyond the SOC 2 evidence. | |
| 164.312(c)(2) | Mechanism to authenticate electronic protected health information | A | CC7.1 | Partly | Electronic checks, such as checksums or digital signatures, over the ePHI itself; change detection under the criteria usually covers system and configuration files, not each record. |
| 164.312(d) | Person or entity authentication | R | CC6.1 | Covered | None beyond the SOC 2 evidence. |
| 164.312(e)(1) | Transmission security | CC6.1, CC6.7 | Covered | None beyond the SOC 2 evidence. | |
| 164.312(e)(2)(i) | Integrity controls | A | CC6.7 | Covered | Only the documented addressable decision (164.306(d)(3)). |
| 164.312(e)(2)(ii) | Encryption | A | CC6.7 | Covered | Only the documented addressable decision (164.306(d)(3)). |
Does SOC 2 cover business associate agreements?
Only in part. SOC 2 vendor management (CC9.2) and, when Privacy is in scope, vendor privacy commitments (P6.4) show that a company oversees its subcontractors. No criterion tests whether a business associate agreement exists or carries the terms 45 CFR 164.314 requires. Of the 6 rows, 2 are partly covered and 4 are not covered.
| CFR cite | Provision | R/A | SOC 2 criteria | Coverage | What HIPAA still needs |
|---|---|---|---|---|---|
| 164.314(a)(1) | Business associate contracts or other arrangements | CC9.2, P6.4 | Partly | Each business associate agreement must meet 164.314(a)(2)(i), (ii) or (iii), whichever applies. | |
| 164.314(a)(2)(i) | Business associate contracts | R | Not covered | An agreement that binds the business associate to comply with the Security Rule, bind its subcontractors, and report security incidents and breaches (164.314(a)(2)(i)(A) to (C)); no criterion tests contract terms. | |
| 164.314(a)(2)(ii) | Other arrangements | R | Not covered | An arrangement that meets 164.504(e)(3), such as a memorandum of understanding between two government entities; SOC 2 has no counterpart. | |
| 164.314(a)(2)(iii) | Business associate contracts with subcontractors | R | CC9.2, P6.4 | Partly | Subcontractor agreements carrying the same terms the business associate accepted; vendor reviews and privacy commitments do not test those terms. |
| 164.314(b)(1) | Requirements for group health plans | Not covered | Applies only to group health plans, whose plan documents must bind the plan sponsor to safeguard ePHI (164.314(b)(1)); SOC 2 has no counterpart. | ||
| 164.314(b)(2) | Plan document provisions | R | Not covered | Plan documents that require the sponsor to implement safeguards, support the plan-sponsor separation that 164.504(f)(2)(iii) requires with security measures, bind its agents and report security incidents (164.314(b)(2)(i) to (iv)). |
The text of 164.314(a)(2)(iii) points to 164.308(b)(4), a paragraph that does not exist. The business associate’s duty to obtain assurances from its subcontractors is at 164.308(b)(2). The rule gives 164.314(b)(2) no title, so “Plan document provisions” is our label.
Does SOC 2 cover HIPAA documentation requirements?
In part. SOC 2 evidence fully covers 2 of the 5 rows in 45 CFR 164.316, partly covers 2 and does not cover 1. The criteria set no retention period, while HIPAA requires six years.
| CFR cite | Provision | R/A | SOC 2 criteria | Coverage | What HIPAA still needs |
|---|---|---|---|---|---|
| 164.316(a) | Policies and procedures | R | CC5.3 | Partly | Policies and procedures that address each Security Rule standard and implementation specification, with every change documented. |
| 164.316(b)(1) | Documentation | CC5.3 | Partly | Written records of each action, activity or assessment the Security Rule requires, including the risk analysis and addressable decisions. | |
| 164.316(b)(2)(i) | Time limit | R | Not covered | Documentation kept for 6 years from its creation or the date it was last in effect, whichever is later (164.316(b)(2)(i)); the criteria set no retention period. | |
| 164.316(b)(2)(ii) | Availability | R | CC2.2, CC5.3 | Covered | None beyond the SOC 2 evidence. |
| 164.316(b)(2)(iii) | Updates | R | CC3.4, CC5.3 | Covered | None beyond the SOC 2 evidence. |
Does SOC 2 cover HIPAA breach notification?
No. None of the 17 breach notification rows is fully covered: 5 are partly covered and 12 are not covered. The Trust Services Criteria set no notice deadline, content, recipient list or delivery method, which is where most of 45 CFR 164.400 to 164.414 sits.
A business associate’s own duty is 164.410: notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. Notices to individuals, the media and HHS (164.404 to 164.408) are covered entity duties, which a business associate supports through its agreement. The rule applies to breaches on or after September 23, 2009 (164.400), so that scope section has no row. This table has no R/A column, because Subpart D marks nothing required or addressable.
| CFR cite | Provision | SOC 2 criteria | Coverage | What HIPAA still needs |
|---|---|---|---|---|
| 164.402 | Definitions: breach and unsecured PHI | CC7.3 | Partly | Treat an impermissible use or disclosure of PHI that falls outside the three exclusions as a breach unless a documented assessment of at least the four factors in 164.402 shows a low probability of compromise. |
| 164.404(a) | Notification to individuals | P6.6 | Partly | A covered entity duty to notify each affected individual; P6.6, when Privacy is in scope, tests breach notice without HIPAA’s terms. |
| 164.404(b) | Timeliness of notification | Not covered | Covered entity duty: notice without unreasonable delay and no later than 60 calendar days after discovery (164.404(b)). | |
| 164.404(c) | Content of notification | Not covered | Covered entity duty: the five content elements in 164.404(c)(1), written in plain language. | |
| 164.404(d) | Methods of individual notification | Not covered | Covered entity duty: first-class mail or agreed email, with substitute notice when contact details are out of date (164.404(d)). | |
| 164.406(a) | Notification to the media | Not covered | Covered entity duty: notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction (164.406(a)); no criterion requires notice to the media. | |
| 164.406(b) | Timeliness of notification | Not covered | Covered entity duty: media notice within the same 60-calendar-day limit as individual notice (164.406(b)). | |
| 164.406(c) | Content of notification | Not covered | Covered entity duty: media notice carries the content 164.404(c) requires (164.406(c)). | |
| 164.408(a) | Notification to the Secretary | P6.6 | Partly | A covered entity duty to notify the HHS Secretary of breaches of unsecured PHI; P6.6, when Privacy is in scope, tests breach notice to regulators without HIPAA’s terms. |
| 164.408(b) | Breaches involving 500 or more individuals | Not covered | Covered entity duty: notify HHS at the same time as the individuals when 500 or more are affected (164.408(b)). | |
| 164.408(c) | Breaches involving less than 500 individuals | Not covered | Covered entity duty: log smaller breaches and report them to HHS within 60 days after the end of each calendar year (164.408(c)). | |
| 164.410(a) | Notification by a business associate | CC7.4, P6.6 | Partly | Notify the covered entity of each breach of unsecured PHI, treating it as discovered on the first day any employee, officer or agent knew or should have known of it (164.410(a)(2)); CC7.4 incident communication and, with Privacy in scope, P6.6 breach notice cover telling customers, but not this discovery rule. |
| 164.410(b) | Timeliness of notification | Not covered | Notice to the covered entity without unreasonable delay and no later than 60 calendar days after discovery (164.410(b)); a business associate agreement may set a shorter window. | |
| 164.410(c) | Content of notification | Not covered | The identity of each affected individual and the other details the covered entity needs for its own notices, given at notification or promptly after (164.410(c)). | |
| 164.412 | Law enforcement delay | Not covered | A hold on notice when a law enforcement official says it would impede a criminal investigation or damage national security: for the period in a written statement, or up to 30 days after a documented oral one (164.412). | |
| 164.414(a) | Administrative requirements | Not covered | Covered entity duty: apply the administrative requirements of 164.530, such as training, complaints, sanctions and documentation, to breach notification (164.414(a)). | |
| 164.414(b) | Burden of proof | CC7.3, CC7.4 | Partly | Records proving each required notice was sent, or that an incident was not a breach, because 164.414(b) puts that burden on the company. |
What does the Privacy Rule ask of a business associate?
A business associate’s Privacy Rule duties arrive mostly through its business associate agreement. It may use or disclose PHI only as that agreement permits or requires, or as law requires (164.502(a)(3)), and it must limit uses, disclosures and requests to the minimum necessary (164.502(b)). The agreement terms in 164.504(e)(2) also require it to report uses or disclosures the agreement does not allow, make PHI available for individuals’ access, amendment and accounting of disclosures, bind subcontractors to the same restrictions, open its records to HHS, and return or destroy PHI when the contract ends where that is feasible. SOC 2’s optional Privacy criteria overlap in places: P4.1 (use limited to identified purposes), P4.3 (disposal), P5.1 and P5.2 (access and correction), P6.4 (vendor privacy commitments) and P6.7 (accounting of disclosures). They test the company’s own privacy commitments rather than these HIPAA terms, and they apply only when Privacy is in the report’s scope.
Will the proposed Security Rule change this mapping?
Possibly, but not yet. HHS announced a proposed rewrite of the Security Rule on December 27, 2024, and the Federal Register published it on January 6, 2025 (90 FR 898). The proposal would remove the distinction between required and addressable implementation specifications, making all of them required with limited exceptions, and it would require encryption and multi-factor authentication, also with limited exceptions. As of October 8, 2026, no final rule has been published in the Federal Register or the eCFR, and HHS states that the current Security Rule remains in effect during the rulemaking. Holland & Knight (July 6, 2026) and Clark Hill (July 13, 2026) report that the federal regulatory agenda now projects final action in July 2027; a projected date is not a deadline. We will revise this crosswalk when a final rule is published.
Can one auditor examine SOC 2 and HIPAA together?
Yes: a CPA firm can add HIPAA criteria to a SOC 2+ examination, or deliver a SOC 2 report alongside a separate HIPAA assessment, and both routes reuse the shared evidence mapped on this page. Our guide to SOC 2 + HIPAA overlay engagements explains how firms scope, price and report each format.
To compare firms that examine both, see our list of SOC 2 and HIPAA audit firms.
Questions about SOC 2 and HIPAA
Is encryption required under HIPAA?
Not under the Security Rule in force on October 8, 2026. Encryption of stored ePHI (164.312(a)(2)(iv)) and of ePHI in transmission (164.312(e)(2)(ii)) are addressable: you implement encryption where it is reasonable and appropriate, or document why not and adopt an equivalent measure (164.306(d)(3)). Encryption that meets HHS guidance also means the data is not “unsecured PHI” (164.402), so losing it does not trigger breach notification as long as the key was not also compromised. The January 2025 proposal would make encryption required, with limited exceptions.
Does a business associate need its own HIPAA risk analysis?
Yes. The risk analysis specification (164.308(a)(1)(ii)(A)) applies to business associates directly and covers all ePHI the business associate holds. A covered entity customer’s analysis does not cover it, and a SOC 2 risk assessment is a starting point for it rather than a substitute.
How much of HIPAA does SOC 2 cover?
In our mapping, typical SOC 2 evidence fully covers 33 of the 65 Security Rule provisions, partly covers 26 and does not cover 6. None of the 17 breach notification rows is fully covered. A single overlap percentage hides two things that change the answer: which criteria the report includes, and whether every ePHI system sits inside its scope.
Sources and method
- Electronic Code of Federal Regulations, 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information) and Subpart D (Notification in the Case of Breach of Unsecured Protected Health Information), text current through October 6, 2026. Privacy Rule references: 164.502 and 164.504.
- HHS, The Security Rule and Breach Notification Rule guidance pages.
- HHS, HIPAA Security Rule notice of proposed rulemaking fact sheet (December 27, 2024).
- Federal Register, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, 90 FR 898 (January 6, 2025).
- NIST, SP 800-66 Revision 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide (February 2024).
- Reports of the regulatory agenda status: Holland & Knight (July 6, 2026) and Clark Hill (July 13, 2026).
Our mapping pairs each provision with criteria from the AICPA’s 2017 Trust Services Criteria (revised points of focus, 2022), cited by ID only. Each coverage verdict is our editorial judgment of what typical SOC 2 evidence shows, not an auditor’s opinion and not legal advice; confirm scope with your CPA firm and counsel.
More in Framework Comparisons