Scrutineer · By framework
SOC 2 HIPAA compliance software, SOC 2 + HIPAA mapping
Most companies that sell software to hospitals, health plans or clinics get asked for two things in the same security review: a SOC 2 report and proof that they meet HIPAA as a business associate. The two overlap heavily, but SOC 2 does not make you HIPAA compliant and there is no HIPAA certification to buy.
Scrutineer maps each control once to the Trust Services Criteria and to the HIPAA Security Rule, evidences it continuously, and lists the HIPAA duties SOC 2 never tests. Readiness software; your CPA firm issues the report.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with SOC 2 + HIPAA
SOC 2 does not make you HIPAA compliant, and a SOC 2 + HIPAA report is not a certification either
HIPAA is law. A business associate that creates, receives, maintains or transmits ePHI owes the Security Rule, the breach notification rule and the parts of the Privacy Rule its business associate agreements pass down, whether or not anyone audits it. SOC 2 is a voluntary attestation against the AICPA Trust Services Criteria, and its criteria were never written around ePHI. The AICPA does let a service auditor examine additional subject matter against additional criteria in the same engagement, which is what the market calls SOC 2+ or SOC 2 + HIPAA: the report then carries an opinion on the Security Rule requirements you put in scope. That is a stronger artifact to hand a hospital, but it is still one auditor's opinion over one period. HHS does not certify anyone as HIPAA compliant and does not recognize private certifications. So the honest sentence for a sales deck is: our SOC 2 report includes an examination of our controls against the HIPAA Security Rule, not we are HIPAA certified.
A Security-only SOC 2 can leave HIPAA's contingency plan untested
Most first SOC 2 reports scope in the Security category only, because it is mandatory and the others add cost. That choice matters for HIPAA. Section 164.308(a)(7) makes a data backup plan, a disaster recovery plan and an emergency mode operation plan required implementation specifications, with testing and revision addressable. In the Trust Services Criteria, backup, recovery infrastructure and recovery plan testing sit mainly in the Availability category, A1.2 and A1.3. The common criteria reach part of the ground through CC7.5 (recovering from incidents) and CC9.1 (business disruption risk), but a report that never scoped Availability may never have tested whether you can restore ePHI. Health system reviewers increasingly read the scope page first. If HIPAA is the reason you are doing SOC 2, put Availability in scope, or at least evidence 164.308(a)(7) on its own, and do not let a clean Security opinion stand in for a contingency plan nobody tested.
The overlap is real, so evidence each control once and report it twice
Roughly the whole technical and administrative core lines up. Risk analysis in 164.308(a)(1)(ii)(A) meets CC3.2. Information system activity review and audit controls meet CC7.2. Access management, unique user IDs and person or entity authentication meet CC6.1 to CC6.3. Security incident procedures meet CC7.3 to CC7.5. Workforce training meets CC1.4 and CC2.2, sanctions meet CC1.5, transmission security meets CC6.7, and device and media disposal meets CC6.5. That overlap is why running the two programs in separate spreadsheets wastes months: the same access review screenshot, the same backup restore log and the same training record satisfy both, if one control library owns them. What does not overlap is where the effort goes: business associate agreements and their pass-through terms, the 60-day breach notice clock, six-year documentation retention, the emergency access procedure and the addressable-specification decisions HIPAA expects you to write down.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps every control in one library to both the SOC 2 Trust Services Criteria and the HIPAA Security Rule standards and implementation specifications, so one piece of evidence counts for both
- Flags the HIPAA requirements a SOC 2 examination does not test, including business associate agreements, breach notification timing and six-year retention
- Records each addressable implementation specification with the decision you made and why, which is the documentation OCR asks for and SOC 2 never requires
- Checks your SOC 2 scope against HIPAA and warns when Availability is out of scope while the contingency plan in 164.308(a)(7) is unevidenced
- Collects evidence continuously from your cloud, identity and ticketing tools, so the SOC 2 Type 2 window and your HIPAA program run on the same live record
- Tracks subcontractor business associate agreements alongside vendor risk reviews, because every vendor that touches ePHI needs both
- Keeps the security incident and breach assessment record that starts the 60-day notice clock to your covered entity customers
- Answers hospital and health plan security questionnaires from the same mapped controls, so the answer in the questionnaire matches the report
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Where SOC 2 covers HIPAA and where it stops
HIPAA Security Rule requirements against the SOC 2 criteria that cover them
Most SOC 2 and HIPAA comparisons stop at "they overlap". This table shows which Trust Services Criteria cover each HIPAA requirement, whether that coverage depends on which SOC 2 categories you scope in, and what is left for your HIPAA program alone. Section numbers are 45 CFR Part 164; criteria are the 2017 Trust Services Criteria.
| HIPAA requirement | Section | SOC 2 criteria that cover it | Covered by a Security-only SOC 2? | What remains HIPAA-only |
|---|---|---|---|---|
| Risk analysis and risk management | 164.308(a)(1)(ii)(A) and (B) | CC3.1 to CC3.4 | Yes | Scoping the analysis to every system holding ePHI, not only the in-scope SOC 2 system |
| Sanction policy | 164.308(a)(1)(ii)(C) | CC1.5 | Yes | Little: document sanctions applied to workforce members |
| Information system activity review and audit controls | 164.308(a)(1)(ii)(D), 164.312(b) | CC7.2 | Yes | Little: show logs cover ePHI systems |
| Workforce security and access management | 164.308(a)(3) and (a)(4), 164.312(a)(2)(i) | CC6.1 to CC6.3 | Yes | Emergency access procedure in 164.312(a)(2)(ii), which SOC 2 does not name |
| Security awareness and training | 164.308(a)(5) | CC1.4, CC2.2 | Yes | Little: HIPAA content in the training |
| Security incident procedures | 164.308(a)(6) | CC7.3 to CC7.5 | Yes | The breach risk assessment and notice decision under 164.402 and 164.410 |
| Contingency plan: backup, disaster recovery, emergency mode | 164.308(a)(7) | A1.2, A1.3, with CC7.5 and CC9.1 in part | Only in part | Backup and restore testing if Availability is out of scope |
| Periodic evaluation | 164.308(a)(8) | CC4.1, CC4.2 | Yes | An evaluation against the Security Rule itself, not against the criteria |
| Business associate contracts | 164.308(b), 164.314(a) | CC9.2 in part | Only in part | BAA terms with every covered entity and every subcontractor that touches ePHI |
| Facility, workstation, device and media controls | 164.310 | CC6.4, CC6.5, CC6.7 | Yes | Workstation use rules for remote staff handling ePHI |
| Integrity and transmission security | 164.312(c), 164.312(e) | CC6.7, CC7.1, PI1 in part | Yes, mostly | Addressable-specification decisions, documented |
| Documentation retention | 164.316(b)(2) | None | No | Six years from creation or last effective date |
| Breach notification to the covered entity | 164.410 | None | No | Notice without unreasonable delay and no later than 60 days after discovery, often shorter under the BAA |
Good questions
Questions about SOC 2 + HIPAA
Keep reading
Guides that go deeper on this framework
HITRUST vs SOC 2
When a health system asks for HITRUST instead of SOC 2, and what carries over.
Read the guideBest HIPAA risk assessment software
The 164.308(a)(1) risk analysis, and which tools actually produce it.
Read the guideBest SOC 2 compliance software
How the SOC 2 platforms differ once HIPAA is on the list too.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification