SOC 2 vs HIPAA: What Each One Proves About a Vendor
September 21, 2026
You asked a vendor if their service is HIPAA compliant. They sent you a SOC 2 report. The SOC 2 vs HIPAA mix-up starts right there.
It is not a trick. The report is real proof. It just answers a different question than the one you asked.
TL;DR
The SOC 2 vs HIPAA split is voluntary proof against binding law. SOC 2 is a choice: a CPA firm checks a provider's controls and writes an opinion. HIPAA is federal law, run by HHS, and it applies whether anyone checks you or not. A SOC 2 report is useful proof that a vendor runs its platform the way it says. It does not replace a business associate agreement, and no report makes a vendor HIPAA compliant, because HHS does not recognize private certificates at all. Read the report for what it covers. Then ask for the agreement.
Key Takeaways
The SOC 2 vs HIPAA gap is simple. One is chosen. The other applies to you anyway.
A SOC 2 report covers only the trust services categories that were in scope. Security is the one always included. Availability, confidentiality, processing integrity, and privacy are each optional.
Type 1 tests design on a single date. Type 2 tests how controls ran over months. Only Type 2 shows they worked.
HHS says it "does not endorse or otherwise recognize private organizations' 'certifications'" about the Security Rule, and that they "do not absolve covered entities of their legal obligations."
A vendor that handles patient data is a business associate. Federal rule says you need a contract with set terms. No SOC 2 report holds those terms.
A proposed rule change would make business associates verify their safeguards every 12 months in writing. It was still only a proposal in September 2026.
Who This Is For
Best for: compliance leads and practice administrators who review vendor proof · regulated groups with several sites running a vendor security questionnaire · buyers handed a report they did not ask for.
Not ideal for: companies picking which framework to chase for themselves · anyone who needs legal advice, since this is a reading of published federal guidance and nothing more.
Top use cases: weighing a phone platform, answering service, or contact center that will touch patient or client data · building a vendor security questionnaire · settling a SOC 2 vs HIPAA argument about whether a report closes a gap.
What the SOC 2 vs HIPAA Question Really Asks
Few people type this phrase out of idle interest. A SOC 2 vs HIPAA search is usually a proxy for something sharper: the vendor sent me this — am I covered?
Framed that way, it gets easier. You are not weighing two rival standards and picking one. You are checking whether a document answers a duty that sits with you either way. So the useful SOC 2 vs HIPAA comparison is not a feature grid. It is a question about what each document can carry.
What a SOC 2 Report Is
SOC 2 comes from the AICPA, the professional body for US accountants. A CPA firm checks a provider's controls and issues an opinion. The AICPA describes the SOC suite as "service offerings CPAs may provide in connection with system-level controls of a service organization," and its guide for practitioners is titled as reporting on an examination of controls. That word counts. Nobody hands out a certificate, and no body exists to issue one.
Two things decide what a report is worth to you, and half the SOC 2 vs HIPAA confusion comes from skipping them.
Scope. The check covers whichever of five trust services categories the provider picked: security, availability, processing integrity, confidentiality, and privacy. Security is nearly always in. The other four are not. A report scoped to security alone has tested nothing about uptime, or about how data stays private in transit.
Type. A Type 1 report says the controls were built right as of one date. A Type 2 report says they ran well across a window, often three to twelve months. Type 1 is a photo. Type 2 is a recording, and it is the one to ask for.
These reports are restricted, which is why a vendor sends one under NDA instead of posting it. A public summary is usually a SOC 3, which the AICPA calls a general use report that does "not provide the same level of detail." A badge on a website is not the report.
What HIPAA Asks For Instead
HIPAA runs on other machinery, and that is the heart of the SOC 2 vs HIPAA gap.
The HHS summary of the Security Rule tells regulated entities to put in place "reasonable and appropriate administrative, physical, and technical safeguards" for patient data held in electronic form. They must also run "an accurate and thorough assessment of the potential risks and vulnerabilities." The rule is loose on purpose. It "does not dictate the specific security measures," because a dental group with four sites and a hospital network do not need the same controls.
When a vendor handles that data for you, it becomes a business associate. HHS then makes you get "satisfactory assurances that the business associate will appropriately safeguard the information" through a written contract. 45 CFR 164.314(a)(2)(i) sets out what that contract must say. The business associate will meet the rules of the subpart. It will bind its own subcontractors the same way. And it will "report to the covered entity any security incident of which it becomes aware, including breaches of unsecured protected health information."
Look at what those three terms are: promises made to you that you can enforce. A SOC 2 report holds none of them. It is an opinion written to a CPA firm's standard.
SOC 2 vs HIPAA in One Table
|
SOC 2 |
HIPAA |
|
|---|---|---|
|
What it is |
Voluntary examination |
Federal rule |
|
Who runs it |
A licensed CPA firm |
HHS Office for Civil Rights |
|
Applies because |
The provider chose it |
Your role and your data trigger it |
|
Output |
A restricted report and opinion |
No output, just an ongoing duty |
|
Scope |
The categories the provider picked |
All patient data you touch |
|
Certificate exists |
No |
No |
|
Who holds the risk |
The examined provider |
You, and your business associate |
The last two rows settle most internal arguments. Neither one ends in a certificate, and in both cases the risk stays with you.

Why the SOC 2 vs HIPAA Answer Is Never a Certificate
This is what buyers get wrong most often, and federal guidance is blunt about it.
Asked whether groups must certify they meet the Security Rule, HHS answers no, then adds the line that settles the SOC 2 vs HIPAA question outright:
HHS "does not endorse or otherwise recognize private organizations' 'certifications'" regarding the Security Rule, and such certifications "do not absolve covered entities of their legal obligations under the Security Rule."
HHS adds that an outside check will not stop it finding a violation later. OCR has also published a notice about misleading marketing claims saying that HHS and OCR "do not endorse any private consultants' or education providers' seminars, materials or systems, and do not certify any persons or products as 'HIPAA compliant.'"
None of this makes a report worthless. It makes it proof rather than a pardon, which is the whole SOC 2 vs HIPAA lesson. Our guide to what a HIPAA compliant answering service can and cannot claim works the same point for that category.
The Rule Change That Raises the Stakes
Here is the moving piece, and the best reason to sort your vendor files now. It could change the SOC 2 vs HIPAA answer for every buyer in healthcare.
On 6 January 2025, HHS published a notice of proposed rulemaking to strengthen the Security Rule at 90 FR 898. Two parts of it reshape the SOC 2 vs HIPAA math for buyers.
First, the HHS fact sheet describes removing "the distinction between 'required' and 'addressable' implementation specifications" and making nearly all of them required. Today a vendor can write up why it took another route on an addressable item. That slack would mostly close.
Second, the proposal would have business associates "verify at least once every 12 months" that they have put the required technical safeguards in place, "through a written analysis of the business associate's relevant electronic information systems by a subject matter expert and a written certification that the analysis has been performed and is accurate."
That is a yearly written duty naming your vendor. A Type 2 report would help support it, but it would not be that check.
Status counts too. The OMB Unified Agenda listed the rule at Final Rule Stage with a projected final action of May 2026. That date passed. As of 17 September 2026 no final rule had published, and HHS says that "while the Department is undertaking this rulemaking, the current Security Rule remains in effect." Plan for it. Do not cite it as law yet.
How to Read a Vendor's Report
If a vendor sends one, four checks take ten minutes and tell you most of what you need.
- Find the opinion. It sits near the front. A clean one is unqualified. A qualified one means the examiner found something, and the exceptions are listed later. Read them.
- Check the type and the window. You want Type 2, ending recently. A window that closed nineteen months ago describes a company that may have changed since.
- Check the categories in scope. Security only, or security plus others? Match that against what you care about here.
- Check the system description. Every report names a system. One covering the corporate network says little about the call platform you are buying.
Then ask what the report cannot answer. That is where the SOC 2 vs HIPAA line falls. The report covers the platform. The agreement covers you.
The SOC 2 vs HIPAA Questions to Ask Every Vendor
Ask all of these, of every provider, ours included. A vendor that answers cleanly is easy to work with later.
- Will you sign a business associate agreement for the plan I was quoted, or is it held behind a higher tier?
- Which services does that agreement cover, and which are left out?
- How do you tell us about a security incident, in what window, and to whom?
- Which subcontractors touch our data, and what binds them?
- If you hold a current report, what type is it, who ran it, what period does it cover, and which categories were in scope?
That last one is the honest form of the SOC 2 vs HIPAA request. It asks for the report's real shape instead of taking the fact of a report as the answer. Buyers in other regulated fields run the same play. Our guide for insurance agencies and our guide for dental groups apply it to those workflows, and the Cluster A pillar covers how the service types differ before compliance enters.
The Short Answer
Stop treating SOC 2 vs HIPAA as a contest. A report is good proof that a provider runs the way it claims, and a Type 2 scoped to the right system is worth asking for. HIPAA is the duty you carry anyway, and a signed business associate agreement with real incident terms is what meets it. Collect both. Confuse neither for the other.

Frequently Asked Questions
Is SOC 2 HIPAA compliant?
No, and the phrase mixes two things. SOC 2 is a voluntary check of a provider's controls. HIPAA is federal law that binds covered entities and business associates. A provider can hold a clean Type 2 report and still have no business associate agreement with you, which is the thing HIPAA asks for.
Is SOC 2 required for HIPAA compliance?
No. Nothing in the Security Rule calls for a SOC 2 report. HHS says there is "no standard or implementation specification that requires a covered entity to 'certify' compliance." The rule does ask for periodic review, done in house or by an outside party, but it names no framework.
Does HIPAA compliance require a SOC 2 report?
It does not. It asks for a written contract with set terms, a documented risk analysis, and safeguards that fit your group. A report can support what you learn about a vendor. It cannot stand in for the contract. This is where the SOC 2 vs HIPAA mix-up costs the most.
Does HIPAA compliance cover SOC 2?
No, and it runs neither way. The SOC 2 vs HIPAA overlap is real but partial. HIPAA governs patient data. SOC 2 checks controls across whichever categories a provider picked, for any kind of data. The two overlap on access control, incident response, and change management, but neither holds the other.
Do you need HIPAA certification if you have SOC 2?
There is no HIPAA certification to get. HHS does not certify any person or product as HIPAA compliant, and does not recognize private certificates about the Security Rule. A vendor selling you one is selling paper with nothing behind it.
Do healthcare startups need SOC 2 or HIPAA first?
HIPAA is not optional and not a stage. If you handle patient data, it already applies. SOC 2 is a business call about how fast you can answer buyer questionnaires. Most groups meet the legal duty first, then chase the report when large buyers start asking.
Does HIPAA need SOC 2?
No. The two grew up apart, one from federal law and one from an accounting body. Many vendors pursue both, because HIPAA binds their market and a Type 2 report shortens their sales cycle. That is a business reason. A SOC 2 vs HIPAA pairing is common, but it is not required.
Comments