Scrutineer.ai

Scrutineer · By framework

SOC 2 HIPAA compliance software, SOC 2 + HIPAA mapping

Most companies that sell software to hospitals, health plans or clinics get asked for two things in the same security review: a SOC 2 report and proof that they meet HIPAA as a business associate. The two overlap heavily, but SOC 2 does not make you HIPAA compliant and there is no HIPAA certification to buy.

Scrutineer maps each control once to the Trust Services Criteria and to the HIPAA Security Rule, evidences it continuously, and lists the HIPAA duties SOC 2 never tests. Readiness software; your CPA firm issues the report.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with SOC 2 + HIPAA

SOC 2 does not make you HIPAA compliant, and a SOC 2 + HIPAA report is not a certification either

HIPAA is law. A business associate that creates, receives, maintains or transmits ePHI owes the Security Rule, the breach notification rule and the parts of the Privacy Rule its business associate agreements pass down, whether or not anyone audits it. SOC 2 is a voluntary attestation against the AICPA Trust Services Criteria, and its criteria were never written around ePHI. The AICPA does let a service auditor examine additional subject matter against additional criteria in the same engagement, which is what the market calls SOC 2+ or SOC 2 + HIPAA: the report then carries an opinion on the Security Rule requirements you put in scope. That is a stronger artifact to hand a hospital, but it is still one auditor's opinion over one period. HHS does not certify anyone as HIPAA compliant and does not recognize private certifications. So the honest sentence for a sales deck is: our SOC 2 report includes an examination of our controls against the HIPAA Security Rule, not we are HIPAA certified.

A Security-only SOC 2 can leave HIPAA's contingency plan untested

Most first SOC 2 reports scope in the Security category only, because it is mandatory and the others add cost. That choice matters for HIPAA. Section 164.308(a)(7) makes a data backup plan, a disaster recovery plan and an emergency mode operation plan required implementation specifications, with testing and revision addressable. In the Trust Services Criteria, backup, recovery infrastructure and recovery plan testing sit mainly in the Availability category, A1.2 and A1.3. The common criteria reach part of the ground through CC7.5 (recovering from incidents) and CC9.1 (business disruption risk), but a report that never scoped Availability may never have tested whether you can restore ePHI. Health system reviewers increasingly read the scope page first. If HIPAA is the reason you are doing SOC 2, put Availability in scope, or at least evidence 164.308(a)(7) on its own, and do not let a clean Security opinion stand in for a contingency plan nobody tested.

The overlap is real, so evidence each control once and report it twice

Roughly the whole technical and administrative core lines up. Risk analysis in 164.308(a)(1)(ii)(A) meets CC3.2. Information system activity review and audit controls meet CC7.2. Access management, unique user IDs and person or entity authentication meet CC6.1 to CC6.3. Security incident procedures meet CC7.3 to CC7.5. Workforce training meets CC1.4 and CC2.2, sanctions meet CC1.5, transmission security meets CC6.7, and device and media disposal meets CC6.5. That overlap is why running the two programs in separate spreadsheets wastes months: the same access review screenshot, the same backup restore log and the same training record satisfy both, if one control library owns them. What does not overlap is where the effort goes: business associate agreements and their pass-through terms, the 60-day breach notice clock, six-year documentation retention, the emergency access procedure and the addressable-specification decisions HIPAA expects you to write down.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps every control in one library to both the SOC 2 Trust Services Criteria and the HIPAA Security Rule standards and implementation specifications, so one piece of evidence counts for both
  • Flags the HIPAA requirements a SOC 2 examination does not test, including business associate agreements, breach notification timing and six-year retention
  • Records each addressable implementation specification with the decision you made and why, which is the documentation OCR asks for and SOC 2 never requires
  • Checks your SOC 2 scope against HIPAA and warns when Availability is out of scope while the contingency plan in 164.308(a)(7) is unevidenced
  • Collects evidence continuously from your cloud, identity and ticketing tools, so the SOC 2 Type 2 window and your HIPAA program run on the same live record
  • Tracks subcontractor business associate agreements alongside vendor risk reviews, because every vendor that touches ePHI needs both
  • Keeps the security incident and breach assessment record that starts the 60-day notice clock to your covered entity customers
  • Answers hospital and health plan security questionnaires from the same mapped controls, so the answer in the questionnaire matches the report
SOC 2 + HIPAA readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Where SOC 2 covers HIPAA and where it stops

HIPAA Security Rule requirements against the SOC 2 criteria that cover them

Most SOC 2 and HIPAA comparisons stop at "they overlap". This table shows which Trust Services Criteria cover each HIPAA requirement, whether that coverage depends on which SOC 2 categories you scope in, and what is left for your HIPAA program alone. Section numbers are 45 CFR Part 164; criteria are the 2017 Trust Services Criteria.

HIPAA requirement Section SOC 2 criteria that cover it Covered by a Security-only SOC 2? What remains HIPAA-only
Risk analysis and risk management 164.308(a)(1)(ii)(A) and (B) CC3.1 to CC3.4 Yes Scoping the analysis to every system holding ePHI, not only the in-scope SOC 2 system
Sanction policy 164.308(a)(1)(ii)(C) CC1.5 Yes Little: document sanctions applied to workforce members
Information system activity review and audit controls 164.308(a)(1)(ii)(D), 164.312(b) CC7.2 Yes Little: show logs cover ePHI systems
Workforce security and access management 164.308(a)(3) and (a)(4), 164.312(a)(2)(i) CC6.1 to CC6.3 Yes Emergency access procedure in 164.312(a)(2)(ii), which SOC 2 does not name
Security awareness and training 164.308(a)(5) CC1.4, CC2.2 Yes Little: HIPAA content in the training
Security incident procedures 164.308(a)(6) CC7.3 to CC7.5 Yes The breach risk assessment and notice decision under 164.402 and 164.410
Contingency plan: backup, disaster recovery, emergency mode 164.308(a)(7) A1.2, A1.3, with CC7.5 and CC9.1 in part Only in part Backup and restore testing if Availability is out of scope
Periodic evaluation 164.308(a)(8) CC4.1, CC4.2 Yes An evaluation against the Security Rule itself, not against the criteria
Business associate contracts 164.308(b), 164.314(a) CC9.2 in part Only in part BAA terms with every covered entity and every subcontractor that touches ePHI
Facility, workstation, device and media controls 164.310 CC6.4, CC6.5, CC6.7 Yes Workstation use rules for remote staff handling ePHI
Integrity and transmission security 164.312(c), 164.312(e) CC6.7, CC7.1, PI1 in part Yes, mostly Addressable-specification decisions, documented
Documentation retention 164.316(b)(2) None No Six years from creation or last effective date
Breach notification to the covered entity 164.410 None No Notice without unreasonable delay and no later than 60 days after discovery, often shorter under the BAA

Good questions

Questions about SOC 2 + HIPAA

Partly. The SOC 2 Trust Services Criteria overlap with most of the HIPAA Security Rule, especially risk assessment, access control, logging, incident response and training. A standard SOC 2 report does not assess HIPAA itself, and it does not test business associate agreements, breach notification or six-year documentation retention. A SOC 2 + HIPAA engagement adds the Security Rule as additional criteria.
SOC 2 + HIPAA is a SOC 2 examination in which the service auditor also examines your controls against the HIPAA Security Rule requirements, reported together with the Trust Services Criteria. The AICPA allows this through additional subject matter and additional criteria in a SOC 2 engagement, often called SOC 2+. It gives healthcare customers one report instead of a SOC 2 plus a separate HIPAA assessment.
No. HIPAA does not require a SOC 2 report or any other third-party audit. Hospitals, health plans and larger clinics often require one from their vendors anyway, as proof that the vendor's HIPAA program works in practice. So SOC 2 is usually a customer requirement for a business associate, not a legal one.
Often yes, if you sell to healthcare enterprises. HIPAA compliance is self-assessed, and buyers want an independent auditor's opinion. A SOC 2 Type 2 report, ideally with HIPAA as additional criteria, answers the security review in one document. If your customers are small practices that only ask for a signed BAA, you may not need SOC 2 yet.
HIPAA is a federal law that applies to covered entities and business associates handling protected health information, enforced by the HHS Office for Civil Rights. SOC 2 is a voluntary attestation report issued by a CPA firm against the AICPA Trust Services Criteria. HIPAA says what you must do with ePHI; SOC 2 shows an auditor tested your controls over a period.
No. HHS does not certify organizations as HIPAA compliant and does not endorse private certifications. What exists are third-party assessments and attestations, such as a SOC 2 + HIPAA report or a HITRUST certification, which show an independent party examined your controls. Be careful with any vendor or marketing claim of being HIPAA certified.
Yes. Many CPA firms run the SOC 2 Type 2 examination and the HIPAA assessment in one engagement, with one set of evidence requests and one observation period, and issue either a combined SOC 2 + HIPAA report or two reports. It works best when your controls are already mapped to both, so each request is answered once.
If HIPAA is a main reason for your SOC 2, usually yes. The Security Rule requires a data backup plan, disaster recovery plan and emergency mode operation plan, and the SOC 2 criteria that test backup and recovery sit mostly in the Availability category. A Security-only report may leave your contingency plan untested.
No. Scrutineer is readiness and continuous compliance software. It maps your controls to SOC 2 and HIPAA, collects the evidence, flags gaps and keeps the records. A licensed CPA firm issues the SOC 2 or SOC 2 + HIPAA report, and HIPAA compliance remains your organization's responsibility. Multi-framework mapping is on the Growth plan.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification