What exactly is a combined SOC 2 + HIPAA examination, since HIPAA has no certification?
HIPAA has no official certification or seal, HHS says so explicitly, and OCR neither certifies nor recognizes certifications, so the market evidences HIPAA posture through third-party assessment artifacts. The SOC 2+ mechanism: AICPA attestation standards let a SOC 2 examination include additional subject matter or criteria beyond the Trust Services Criteria, and the common health-data pattern adds the HIPAA Security Rule's implementation specifications (45 CFR 164.308 administrative, 164.310 physical, 164.312 technical safeguards, plus 164.316 documentation) as mapped criteria. The examiner tests each control once and reports it against both frames: the SOC 2 opinion and description as usual, plus a section mapping controls and test results to the Security Rule specifications. What the buyer receives is one Type II report answering both the security-diligence question (did controls operate over the period) and the BAA-diligence question (do safeguards addressing the Security Rule exist and operate). Variants in the market: some firms structure the HIPAA content as a separate SOC 2-adjacent attestation or an agreed-upon-procedures engagement; the substance is similar, one fieldwork effort, dual-framed reporting. What it is not: a government-recognized compliance determination, a Privacy Rule assessment (unless expressly scoped in), or a substitute for your own statutory obligations, and marketing it as 'HIPAA certified' is exactly the misrepresentation the FTC has pursued in other certification contexts.
How well do the Security Rule safeguards map onto SOC 2 criteria?
Heavily, which is why the combined engagement is efficient. Administrative safeguards: the security-management process (risk analysis, risk management, sanctions, review) maps to SOC 2's risk-assessment and monitoring criteria; workforce security and training map to control-environment and HR criteria; access management maps to logical-access criteria; contingency planning maps to availability-category content (one argument for electing availability in health-data reports); incident procedures map to SOC 2's incident criteria. Physical safeguards: facility access, workstation, and media controls map to SOC 2's physical-access and data-disposal criteria, with cloud-hosted associates inheriting much from IaaS providers' own reports (carve-out or inclusive treatment must be decided). Technical safeguards: unique user identification, emergency access, automatic logoff, encryption at rest and in transit, audit controls, integrity, and authentication map to the logical-access and system-operations criteria almost one-to-one. The HIPAA-specific residue the mapping does not cover, and where combined engagements add genuine work: ePHI-specific scoping (knowing which systems hold ePHI, your data map must distinguish it), the risk analysis in HIPAA's specific sense (asset-and-ePHI-flow-based, documented, current, the single most cited OCR failure), BAA chain management (upstream BAAs with customers, downstream with subcontractors, 164.308(b) and 164.314), breach-notification procedures under the Breach Notification Rule's specific clocks (60 days to individuals, annual or 60-day HHS reporting by size, plus contractual BAA timelines, commonly shorter), and the addressable-versus-required specification analysis with documented decisions for addressable items not implemented as written.
What does a combined report prove to covered-entity customers, and what does it not?
What it proves: that an independent examiner tested the associate's safeguards, mapped to the Security Rule's specifications, over a real observation period, with results (including exceptions) in writing, which answers the covered entity's own due-diligence problem, they must have 'satisfactory assurances' that associates safeguard ePHI, and a Type II combined report is strong, standardized satisfaction of that duty, far better than the questionnaire theater it replaces. It also gives the covered entity's security team the operational detail (description, controls, test results) to assess integration risk concretely. What it does not prove: HIPAA compliance as a legal conclusion, OCR investigates conduct (breaches, complaints, audits) against the regulations directly, and no attestation precludes findings; Privacy Rule conformance, permitted uses and disclosures, minimum necessary, individual rights handling, authorizations, sit outside the Security Rule mapping unless the engagement deliberately adds them, and most combined reports do not; the associate's actual BAA conformance with each customer's specific terms (notification windows, subcontractor consent, offshore restrictions vary per BAA, and the report tests the associate's standard procedures, not your contract); and future performance, the period is historical. Sophisticated covered entities read it accordingly: accept it as safeguards diligence, verify the scope covers the services actually purchased, reconcile its breach-notification procedures against their own BAA's clocks, and keep Privacy Rule and use-limitation questions in the contract-and-questionnaire channel where they still live.
How does SOC 2+HIPAA compare with HITRUST, and when is each the right artifact?
HITRUST CSF certification: a certifiable framework harmonizing HIPAA, NIST, ISO, and other sources into scored requirement statements, assessed by HITRUST-authorized assessors with central quality review and a certification decision (r2 for full certification, e1 and i1 for lighter tiers). Compared to SOC 2+HIPAA: more prescriptive (defined requirement statements versus your own control set), more standardized across vendors (buyers can compare scores), heavier and costlier (the r2 build and assessment cycle typically exceeds a SOC 2+ effort meaningfully), and certification-shaped, which is why the largest health systems and payers, whose vendor-risk programs are built around it, often mandate HITRUST specifically and accept nothing else. SOC 2+HIPAA: cheaper, faster, built on audit machinery you may already run, richer in operational detail, but non-comparable across vendors and dependent on the buyer accepting attestation-form assurance. Market heuristic: selling to large hospital systems, national payers, or their tier-one vendors, expect HITRUST demands and price them into the roadmap; selling to digital-health companies, mid-market providers, employers, and health-adjacent SaaS, SOC 2+HIPAA usually satisfies; facing both, the combined report first (it monetizes sooner), HITRUST when a specific revenue threshold justifies it, and build the control set once, HITRUST's CSF maps to the same substrate, so the r2 becomes an assessment exercise rather than a rebuild. A watch item: HITRUST's lighter e1/i1 tiers are increasingly accepted for lower-risk vendors, narrowing the cost gap argument in both directions.
What should a business associate prepare before a first combined examination?
Six workstreams. ePHI data map: which systems create, receive, maintain, or transmit ePHI, including logs, backups, analytics, support tooling, and subcontractor flows, this scopes everything, and discovering ePHI in an unmapped system mid-fieldwork is the classic combined-engagement failure. HIPAA risk analysis: the documented, ePHI-specific, asset-and-flow-based risk analysis of 164.308(a)(1)(ii)(A), current within the period, with a risk-management plan working its findings; examiners test for it and OCR treats its absence as the cardinal sin, generic enterprise risk registers do not satisfy it. Policy set with HIPAA specificity: security policies referencing the safeguard specifications, the addressable-specification decisions documented (encryption choices especially), sanction policy, and the 164.316 documentation retention (six years). BAA hygiene: a complete inventory of upstream BAAs (customers) and downstream BAAs (every subcontractor touching ePHI, including cloud providers, verify you executed one with each), with notification-clock reconciliation, your internal breach procedure must satisfy your shortest contractual clock, not just the rule's. Breach machinery: the incident-to-breach assessment procedure (the four-factor compromise assessment), notification templates, and evidence the process has been exercised (tabletop at minimum). Workforce evidence: role-based training with completion records, access reviews tied to workforce changes, sanctions applied where warranted. Sequence with the SOC 2 calendar: remediate before the observation period opens, run the internal mini-audit quarterly, and align the examination window with customer renewal cycles so the fresh report lands when procurement asks for it.