Last updated: July 26, 2026
SOC 2 by Industry

SOC 2 Audits for Telehealth Companies

Health systems, provider groups, and health plans won't route patients through your platform without a Business Associate Agreement and the SOC 2 evidence behind it. Here is how telehealth companies scope the audit — the ePHI boundary, availability for live care, criteria, and cost.

Why telehealth companies get asked for SOC 2

Telehealth sells into hospital systems, provider groups, health plans, and employer health programs whose vendor-risk teams operate under HIPAA. Before your platform carries a single video visit or prescription, those teams ask whether you will sign a Business Associate Agreement (BAA) and whether a current SOC 2 Type 2 backs the controls you attest to in it. Because care happens in real time, their reviews weigh uptime and incident response as heavily as data protection.

The data at stake is electronic protected health information (ePHI) in motion and at rest: video and audio of clinical encounters, chat transcripts, e-prescribing records that flow to pharmacies, and remote patient monitoring (RPM) streams from connected devices. A breach carries mandatory notification obligations for you and your covered-entity customer, and an outage can interrupt active care — so reviewers dig into encryption of live media, access logging over patient records, and tested failover for the systems clinicians use during a visit. SOC 2 complements HIPAA; it does not replace it.

Trust Services Criteria focus for Telehealth

Security (the Common Criteria) is mandatory in every SOC 2 report. The other four criteria are elective — you scope them in based on what your customers actually rely on. Here is how telehealth companies typically scope them, and why:

CriterionTypical scopeWhy it matters in Telehealth
SecurityAlways in scopeMandatory in every SOC 2. For telehealth, expect scrutiny on access to systems carrying ePHI, encryption of live video and RPM streams in transit, and change control over any code path that can reach a clinical encounter.
AvailabilityUsually in scopeCare is delivered in real time, so downtime can interrupt a visit or delay a prescription. Health-system contracts often carry SLAs, and reviewers want tested failover, capacity planning, and incident evidence for the systems clinicians rely on live.
ConfidentialityUsually in scopeePHI and covered-entity data are confidential by the BAA. Reviewers look for data classification, encryption, retention, and disposal controls over recordings, transcripts, and monitoring data.
Processing IntegritySometimesScoped in mainly for e-prescribing and RPM workflows where the accuracy and completeness of a prescription or a device reading drives a clinical decision; platforms that only connect patient and clinician often leave it out.
PrivacyCommonComes up when you make direct commitments to patients about how their health data is used, especially in consumer-facing virtual care. Many B2B telehealth vendors handle PHI through the BAA and Confidentiality, adding Privacy when buyers ask.

Each elective criterion adds controls and evidence — and cost. Scope what your customers demand in security reviews, not everything at once.

Scoping decisions specific to Telehealth

These are the Telehealth-specific calls that shape your system description, control list, and ultimately your audit price. Settle them before you request quotes — firms price scope, not industry labels.

Draw the ePHI boundary across the full visit path

Decide which systems store, process, or transmit ePHI across the encounter — waiting room, live video, chat, recordings and transcripts, e-prescribing, and RPM ingestion — and make that the audited boundary. Transcription services, notification pipelines, and logs that capture PHI are the ones teams miss.

Map BAAs to every subprocessor in the care flow

Your video or WebRTC vendor, SMS and notification provider, e-prescribing network, RPM device cloud, and cloud host each touch ePHI and should sit under a BAA, typically carved out as subservice organizations. Confirm each has its own SOC 2 or HIPAA attestation before your audit starts.

Availability evidence tuned for live care

Downtime here interrupts care, not just access. Auditors sample tested failover, redundancy for real-time media, on-call incident response, and status communication, so build the availability evidence around clinical encounters rather than generic uptime dashboards.

Audit logging over PHI access and encounters

Covered-entity customers expect immutable logs of who viewed which patient record, recording, or transcript and when. Make sure logging captures PHI access inside the application and break-glass events — not just infrastructure and login events.

Encryption of live media and device streams

Encrypt video and audio in transit, recordings at rest, and RPM telemetry from connected devices, and be ready to show key management. Reviewers treat live-media and device channels as first-class ePHI paths, not incidental traffic.

What a SOC 2 audit costs for telehealth companies

These are first-party published rates from accredited firms on the AuditNex network — actual prices, not survey estimates. Data as of 2026-07-26.

SOC 2 Type 1 — network rates
$1,500–$5,000
Published range, by company size
SOC 2 Type 2 — network rates
$2,500–$15,000
Published range, by company size

Quote requests priced at network rates: Withheld — 2 samples, below our 5-sample minimum.

Honest data note: the figures above are network-wide — they cover every industry we serve, not Telehealth specifically. We do not yet have enough Telehealth engagements to publish industry-segmented medians under our 5-sample minimum, and we won’t imply otherwise. What actually moves your price is scope (report type, company size, number of elective criteria), not your industry label. How we use pricing data · Full pricing report

Estimate your SOC 2 cost →

Frameworks telehealth companies pair with SOC 2

SOC 2 is rarely the only requirement in this category. These are the frameworks most often pursued alongside it — and overlapping evidence you can reuse if you plan both from the start:

FrameworkWhy it comes up alongside SOC 2
HIPAA Security & Privacy RulesThe reason telehealth buyers ask for anything at all. SOC 2 evidence overlaps heavily with the HIPAA safeguards, so one control set can support both — but a SOC 2 report does not make you HIPAA compliant.
HITRUST CSFSome hospital systems and health plans request HITRUST specifically. Its controls map closely to SOC 2, so firms often plan the two together and reuse evidence collected for one to reduce work on the other.
ISO 27001Comes up with international virtual-care deployments and larger enterprise health customers who prefer certification to attestation. The ISMS overlaps substantially with SOC 2 Security controls.

Finding an auditor who knows Telehealth

Straight answer: no firm in our directory has a confirmed Telehealth industry focus on record yet. That reflects our verification data — not the market. Industry tags only appear on a profile after the firm discloses them or public records confirm them; we never guess. Until then, the strongest starting points are the ranked list below (verification status and profile transparency first) and asking each firm directly about Telehealth references when you request quotes.

Best SOC 2 auditors for healthcare ›  ·  All auditor profiles ›  ·  How we verify auditors ›

SOC 2 for Telehealth: common questions

Does a SOC 2 report make our telehealth platform HIPAA compliant?

No. SOC 2 and HIPAA overlap heavily in technical and administrative safeguards, so the same controls often support both, but HIPAA compliance is a separate legal obligation you attest to yourself and back with a BAA. Most covered-entity buyers want to see both a signed BAA and a current SOC 2 Type 2.

Why does availability matter more for a telehealth SOC 2?

Because care is delivered in real time. When your platform is down, a visit cannot happen or a prescription is delayed, so health-system buyers scrutinize tested failover, redundancy for live media, and incident response far more than they would for a system that only stores data. Many telehealth vendors scope Availability for exactly this reason.

How do we handle the video vendor and RPM device cloud in scope?

Both process ePHI on your behalf, so they belong under a BAA and are usually carved out as subservice organizations in your system description. Document the complementary controls you rely on them for and collect their SOC 2 or HIPAA attestations before your audit begins.

Should telehealth add the Privacy criterion or rely on Confidentiality?

Many B2B telehealth companies handle PHI obligations through the BAA and scope Confidentiality plus Security, treating Privacy as elective. If you run consumer-facing virtual care and make direct commitments to patients about how their data is used, or a buyer specifically asks, adding Privacy strengthens the report.

Get SOC 2 quotes scoped for Telehealth

Answer five questions once — we’ll show accredited auditors that fit your scope, with transparent pricing and no sales calls. Scope it the way this guide describes: report type, criteria mix, and timeline are what drive your quotes.

Start a quote →