International Standards US

SOC 2 + HIPAA Combined Reporting: One Audit for Health Data

Combining SOC 2 with HIPAA compliance evidence: SOC 2+ examinations mapped to the Security Rule, what a combined report proves to covered-entity customers, and BAA alignment.

Regulation

AICPA Trust Services Criteria plus HIPAA Security Rule (45 CFR Part 164 Subpart C) as additional subject matter in a SOC 2+ examination; HIPAA itself enforced separately by HHS OCR

Max Penalty

HIPAA civil penalties are tiered by culpability and adjusted for inflation, reaching roughly $2.1 million per violation category per year; the SOC 2 report itself carries no penalties

Enforcing Authority

CPA firms issue the combined report; HHS Office for Civil Rights enforces HIPAA regardless of any attestation

Official Source

www.hhs.gov

Executive Summary

  • There is no official 'HIPAA certification'; business associates evidence HIPAA posture through third-party assessments, and a SOC 2+ examination adding HIPAA Security Rule criteria is a common, efficient vehicle.
  • In a SOC 2+, the CPA examines controls against the Trust Services Criteria and against the Security Rule's safeguards as additional subject matter, producing one report serving both security diligence and BAA due-diligence requests.
  • The mapping is favorable: Security Rule administrative, physical, and technical safeguards overlap heavily with SOC 2 security criteria; the HIPAA-specific additions concentrate in ePHI-specific policies, BAA chains, and breach-notification procedures.
  • A combined report does not make you 'HIPAA compliant': OCR enforces the rules independently, the Privacy Rule's use-and-disclosure duties sit largely outside SOC 2's frame, and your risk analysis obligation under 164.308(a)(1)(ii)(A) stands on its own.
  • Covered-entity procurement increasingly accepts SOC 2+HIPAA in lieu of bespoke questionnaires; HITRUST remains the demand where large health systems require certification-style assurance.

The combined engagement exists because two bureaucratic facts collide: HIPAA requires covered entities to obtain assurances from every associate, and HIPAA offers no certification with which to give them. Into that vacuum the market inserted the SOC 2+, one examination, one period, one report, dual-framed against the criteria buyers know and the safeguards the law names. It works because the Security Rule and SOC 2 security were always describing the same controls in different dialects. The discipline it cannot substitute for is HIPAA’s own: the ePHI-specific risk analysis, the BAA chain, the breach clocks, obligations OCR enforces against conduct, not paperwork. Treat the combined report as the diligence artifact it is, keep the statutory machinery running underneath, and never let marketing say ‘certified.‘

InstrumentSOC 2+ examination: TSC + Security Rule safeguards as added criteria
ProvesSafeguards mapped to 164.308/310/312 operated over the period
Does not proveLegal compliance, Privacy Rule conformance, your specific BAA terms
AlternativeHITRUST r2 where large health systems mandate certification-style assurance
HIPAA enforcementOCR, independent of any attestation; penalties to ~$2.1M per category/year
SourceHHS Security Rule

Preparing the combined path

Map ePHI first. Scope flows from it; unmapped ePHI mid-fieldwork is the classic failure.

Run the real risk analysis. OCR’s most-cited gap; see the security risk assessment guide and BAA chain practices.

Reconcile breach clocks. Shortest contractual BAA window governs; the breach playbook covers the four-factor assessment.

Build once for both futures. The same control set serves SOC 2 privacy expansion and an eventual HITRUST cycle.

ePHI mapping starts with knowing your web-facing flows: baseline them with a free scan.

Frequently Asked Questions

What exactly is a combined SOC 2 + HIPAA examination, since HIPAA has no certification?

HIPAA has no official certification or seal, HHS says so explicitly, and OCR neither certifies nor recognizes certifications, so the market evidences HIPAA posture through third-party assessment artifacts. The SOC 2+ mechanism: AICPA attestation standards let a SOC 2 examination include additional subject matter or criteria beyond the Trust Services Criteria, and the common health-data pattern adds the HIPAA Security Rule's implementation specifications (45 CFR 164.308 administrative, 164.310 physical, 164.312 technical safeguards, plus 164.316 documentation) as mapped criteria. The examiner tests each control once and reports it against both frames: the SOC 2 opinion and description as usual, plus a section mapping controls and test results to the Security Rule specifications. What the buyer receives is one Type II report answering both the security-diligence question (did controls operate over the period) and the BAA-diligence question (do safeguards addressing the Security Rule exist and operate). Variants in the market: some firms structure the HIPAA content as a separate SOC 2-adjacent attestation or an agreed-upon-procedures engagement; the substance is similar, one fieldwork effort, dual-framed reporting. What it is not: a government-recognized compliance determination, a Privacy Rule assessment (unless expressly scoped in), or a substitute for your own statutory obligations, and marketing it as 'HIPAA certified' is exactly the misrepresentation the FTC has pursued in other certification contexts.

How well do the Security Rule safeguards map onto SOC 2 criteria?

Heavily, which is why the combined engagement is efficient. Administrative safeguards: the security-management process (risk analysis, risk management, sanctions, review) maps to SOC 2's risk-assessment and monitoring criteria; workforce security and training map to control-environment and HR criteria; access management maps to logical-access criteria; contingency planning maps to availability-category content (one argument for electing availability in health-data reports); incident procedures map to SOC 2's incident criteria. Physical safeguards: facility access, workstation, and media controls map to SOC 2's physical-access and data-disposal criteria, with cloud-hosted associates inheriting much from IaaS providers' own reports (carve-out or inclusive treatment must be decided). Technical safeguards: unique user identification, emergency access, automatic logoff, encryption at rest and in transit, audit controls, integrity, and authentication map to the logical-access and system-operations criteria almost one-to-one. The HIPAA-specific residue the mapping does not cover, and where combined engagements add genuine work: ePHI-specific scoping (knowing which systems hold ePHI, your data map must distinguish it), the risk analysis in HIPAA's specific sense (asset-and-ePHI-flow-based, documented, current, the single most cited OCR failure), BAA chain management (upstream BAAs with customers, downstream with subcontractors, 164.308(b) and 164.314), breach-notification procedures under the Breach Notification Rule's specific clocks (60 days to individuals, annual or 60-day HHS reporting by size, plus contractual BAA timelines, commonly shorter), and the addressable-versus-required specification analysis with documented decisions for addressable items not implemented as written.

What does a combined report prove to covered-entity customers, and what does it not?

What it proves: that an independent examiner tested the associate's safeguards, mapped to the Security Rule's specifications, over a real observation period, with results (including exceptions) in writing, which answers the covered entity's own due-diligence problem, they must have 'satisfactory assurances' that associates safeguard ePHI, and a Type II combined report is strong, standardized satisfaction of that duty, far better than the questionnaire theater it replaces. It also gives the covered entity's security team the operational detail (description, controls, test results) to assess integration risk concretely. What it does not prove: HIPAA compliance as a legal conclusion, OCR investigates conduct (breaches, complaints, audits) against the regulations directly, and no attestation precludes findings; Privacy Rule conformance, permitted uses and disclosures, minimum necessary, individual rights handling, authorizations, sit outside the Security Rule mapping unless the engagement deliberately adds them, and most combined reports do not; the associate's actual BAA conformance with each customer's specific terms (notification windows, subcontractor consent, offshore restrictions vary per BAA, and the report tests the associate's standard procedures, not your contract); and future performance, the period is historical. Sophisticated covered entities read it accordingly: accept it as safeguards diligence, verify the scope covers the services actually purchased, reconcile its breach-notification procedures against their own BAA's clocks, and keep Privacy Rule and use-limitation questions in the contract-and-questionnaire channel where they still live.

How does SOC 2+HIPAA compare with HITRUST, and when is each the right artifact?

HITRUST CSF certification: a certifiable framework harmonizing HIPAA, NIST, ISO, and other sources into scored requirement statements, assessed by HITRUST-authorized assessors with central quality review and a certification decision (r2 for full certification, e1 and i1 for lighter tiers). Compared to SOC 2+HIPAA: more prescriptive (defined requirement statements versus your own control set), more standardized across vendors (buyers can compare scores), heavier and costlier (the r2 build and assessment cycle typically exceeds a SOC 2+ effort meaningfully), and certification-shaped, which is why the largest health systems and payers, whose vendor-risk programs are built around it, often mandate HITRUST specifically and accept nothing else. SOC 2+HIPAA: cheaper, faster, built on audit machinery you may already run, richer in operational detail, but non-comparable across vendors and dependent on the buyer accepting attestation-form assurance. Market heuristic: selling to large hospital systems, national payers, or their tier-one vendors, expect HITRUST demands and price them into the roadmap; selling to digital-health companies, mid-market providers, employers, and health-adjacent SaaS, SOC 2+HIPAA usually satisfies; facing both, the combined report first (it monetizes sooner), HITRUST when a specific revenue threshold justifies it, and build the control set once, HITRUST's CSF maps to the same substrate, so the r2 becomes an assessment exercise rather than a rebuild. A watch item: HITRUST's lighter e1/i1 tiers are increasingly accepted for lower-risk vendors, narrowing the cost gap argument in both directions.

What should a business associate prepare before a first combined examination?

Six workstreams. ePHI data map: which systems create, receive, maintain, or transmit ePHI, including logs, backups, analytics, support tooling, and subcontractor flows, this scopes everything, and discovering ePHI in an unmapped system mid-fieldwork is the classic combined-engagement failure. HIPAA risk analysis: the documented, ePHI-specific, asset-and-flow-based risk analysis of 164.308(a)(1)(ii)(A), current within the period, with a risk-management plan working its findings; examiners test for it and OCR treats its absence as the cardinal sin, generic enterprise risk registers do not satisfy it. Policy set with HIPAA specificity: security policies referencing the safeguard specifications, the addressable-specification decisions documented (encryption choices especially), sanction policy, and the 164.316 documentation retention (six years). BAA hygiene: a complete inventory of upstream BAAs (customers) and downstream BAAs (every subcontractor touching ePHI, including cloud providers, verify you executed one with each), with notification-clock reconciliation, your internal breach procedure must satisfy your shortest contractual clock, not just the rule's. Breach machinery: the incident-to-breach assessment procedure (the four-factor compromise assessment), notification templates, and evidence the process has been exercised (tabletop at minimum). Workforce evidence: role-based training with completion records, access reviews tied to workforce changes, sanctions applied where warranted. Sequence with the SOC 2 calendar: remediate before the observation period opens, run the internal mini-audit quarterly, and align the examination window with customer renewal cycles so the fresh report lands when procurement asks for it.

Regulatory Crosswalk

HIPAA Security RuleHITRUST CSFSOC 2 Trust Services CriteriaHICP

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.