SOC 2 to HIPAA: control mapping & evidence reuse
8 of 13 control domains map directly. See exactly where SOC 2 and HIPAA overlap, which evidence carries over, and which engagement to run first.
How SOC 2 and HIPAA relate
Software vendors, digital health startups, and IT service providers that touch protected health information usually have to satisfy two different audiences at once. Healthcare customers expect a SOC 2 report as proof of a mature security program, while federal law obligates covered entities and their business associates to meet the HIPAA Security Rule. Teams selling into hospitals, payers, and health-tech platforms therefore end up managing both at the same time.
Structurally the two frameworks come at security from different angles. SOC 2 is an AICPA attestation built on the Trust Services Criteria, organized as Common Criteria CC1 through CC9 plus optional categories for availability, confidentiality, processing integrity, and privacy. HIPAA is federal regulation in 45 CFR Part 164, Subpart C, which groups requirements into administrative, physical, and technical safeguards. Both are risk-based control sets, so a large share of the underlying controls line up even though the language and enforcement models differ.
The mappings below are practical guidance from AuditNex to help teams plan a combined program. They are not an official crosswalk from the AICPA or the U.S. Department of Health and Human Services, and every organization should confirm scope with its own auditor and counsel.
Domain-by-domain mapping
Each row pairs the closest SOC 2 and HIPAA requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.
Across 13 control domains, 8 map directly between SOC 2 and HIPAA, 5 map partially, and 0 have no equivalent on one side. Counts are computed live from the mapping table below.
| Control domain | SOC 2 reference | HIPAA reference | Match & notes |
|---|---|---|---|
| Governance & risk assessment | CC1.1–CC1.5; CC3.1–CC3.4 | §164.308(a)(1) | Partial Both require a documented risk analysis and ongoing risk management, so that evidence reuses well. SOC 2 adds board-level governance and control-environment criteria under CC1 that HIPAA's security management process does not explicitly demand. |
| Policies & documentation | CC5.1–CC5.3 | §164.316 | Direct match Both require written, approved, and maintained policies and procedures. HIPAA §164.316 also imposes a six-year documentation retention period that SOC 2 leaves to the organization. |
| Access control & identity | CC6.1–CC6.3 | §164.308(a)(4); §164.312(a); §164.312(d) | Direct match Both require access authorization, least privilege, unique user identification, and authentication, so provisioning and access-review evidence maps almost one to one. |
| Change management | CC8.1 | §164.308(a)(1) | Partial SOC 2 CC8.1 requires a formal change-management process, while HIPAA has no explicit change-management standard. Its only real hook is the security management process and risk analysis, so change evidence maps partially at best. |
| Data protection & encryption | CC6.1; CC6.7 | §164.312(a)(2)(iv); §164.312(c); §164.312(e) | Direct match Both expect protection of data in transit and at rest along with integrity controls. Note that HIPAA treats encryption as an addressable specification, so you document the decision rather than applying it as a flat requirement. |
| Logging & monitoring | CC7.1–CC7.2 | §164.312(b) | Direct match HIPAA audit controls align with SOC 2 system-monitoring and anomaly-detection criteria, so log-generation and review evidence reuses across both. SOC 2 places more explicit emphasis on detecting and evaluating anomalies. |
| Incident response | CC7.3–CC7.5 | §164.308(a)(6) | Direct match Both require documented procedures to detect, respond to, and mitigate security incidents. HIPAA layers in breach-notification obligations that go beyond the SOC 2 incident criteria. |
| Vendor & third-party risk | CC9.2 | §164.308(b); §164.314 | Direct match SOC 2 CC9.2 vendor and business-partner management aligns with HIPAA's business associate contracts and requirements. HIPAA is more prescriptive about required contract terms, while SOC 2 emphasizes ongoing vendor risk assessment. |
| Business continuity & availability | CC9.1; A1.1–A1.3 | §164.308(a)(7) | Partial HIPAA's contingency plan for data backup, disaster recovery, and emergency-mode operation maps to SOC 2 CC9.1 and the Availability criteria. The A1 series only applies when Availability is in the SOC 2 scope, so overlap depends on the report's chosen categories. |
| Personnel security & training | CC1.4; CC2.2 | §164.308(a)(3); §164.308(a)(5) | Direct match Both require workforce security and security-awareness training, so onboarding, screening, and training records carry over. HIPAA calls out specific training reminders and sanction policies that SOC 2 addresses more generally. |
| Asset & configuration management | CC6.1; CC7.1 | §164.310(d) | Partial Neither framework has a dedicated configuration-management domain. SOC 2 treats asset control implicitly under CC6.1 and CC7.1, while HIPAA covers device and media inventory and disposal under §164.310(d), so coverage is partial on both sides. |
| Physical & environmental security | CC6.4–CC6.5 | §164.310(a); §164.310(b); §164.310(c) | Direct match Both require facility access controls and workstation protections. Scope depends on whether operations run in owned facilities or in cloud environments covered by a provider's own SOC 2 report. |
| Vulnerability & patch management | CC7.1 | §164.308(a)(1); §164.308(a)(5)(ii)(B) | Partial SOC 2 CC7.1 expects vulnerability identification, but HIPAA has no explicit scanning or patching standard. The closest hooks are the risk analysis and the malicious-software protection requirement, so this domain maps only partially. |
Which should you do first?
HIPAA has no certification and no mandatory third-party audit; the HHS Office for Civil Rights enforces it, and any HIPAA attestation or examination a vendor buys is voluntary. Because of that, most companies cannot simply hand a buyer a HIPAA certificate. The common market pattern is to lead with SOC 2 and add HIPAA mapping to it, producing a combined report that demonstrates security posture to healthcare purchasers.
Sequencing SOC 2 first also makes sense on scope grounds. The SOC 2 Common Criteria broadly cover the same access control, monitoring, incident response, and governance ground that the HIPAA administrative, physical, and technical safeguards require, so a working SOC 2 program becomes a strong foundation. Once those controls are operating, extending them to close HIPAA-specific gaps such as business associate agreements and breach-notification procedures is a smaller step.
Companies running both should scope a single control environment, then run the SOC 2 examination with HIPAA requirements mapped in parallel. Aligning the SOC 2 Type 2 observation window with the HIPAA readiness work lets one evidence-collection effort serve both, rather than standing up two separate programs.
Evidence you can reuse
Most foundational artifacts carry over between the two efforts. Written security policies, the risk analysis and risk-management plan, access authorization and periodic access reviews, incident-response records, security-awareness training logs, and vendor or business associate reviews all satisfy criteria on both sides. Encryption configurations, audit-log settings, and facility access controls likewise support SOC 2 and HIPAA at the same time.
Some items do not transfer cleanly. HIPAA adds a breach-notification process, specific business associate agreement contract terms, a six-year documentation retention requirement, and workforce sanction expectations that SOC 2 does not spell out. Conversely, SOC 2 change-management evidence under CC8.1 and the availability controls in the A1 series have no direct HIPAA counterpart, so those artifacts strengthen the SOC 2 report without a matching HIPAA obligation.
Find auditors for each framework
No directory firm is currently confirmed for both SOC 2 and HIPAA — browse each ranking separately, or submit one request covering both and let firms respond.
Budget both engagements
AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.
SOC 2 cost data › · HIPAA cost data › · All compliance audit costs ›
One request, both frameworks
Tell us your scope once — get transparent quotes from vetted firms that can run SOC 2 and HIPAA together.
Get matched →Related crosswalks
Sources: AICPA Trust Services Criteria (TSC), 2017, with revised 2022 points of focus; HIPAA Security Rule, 45 CFR Part 164, Subpart C (U.S. Department of Health and Human Services); HIPAA Administrative Simplification, 45 CFR Parts 160 and 164 (business associate and documentation requirements). Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.