SOC 2 Audits for Telehealth Companies
Health systems, provider groups, and health plans won't route patients through your platform without a Business Associate Agreement and the SOC 2 evidence behind it. Here is how telehealth companies scope the audit — the ePHI boundary, availability for live care, criteria, and cost.
Why telehealth companies get asked for SOC 2
Telehealth sells into hospital systems, provider groups, health plans, and employer health programs whose vendor-risk teams operate under HIPAA. Before your platform carries a single video visit or prescription, those teams ask whether you will sign a Business Associate Agreement (BAA) and whether a current SOC 2 Type 2 backs the controls you attest to in it. Because care happens in real time, their reviews weigh uptime and incident response as heavily as data protection.
The data at stake is electronic protected health information (ePHI) in motion and at rest: video and audio of clinical encounters, chat transcripts, e-prescribing records that flow to pharmacies, and remote patient monitoring (RPM) streams from connected devices. A breach carries mandatory notification obligations for you and your covered-entity customer, and an outage can interrupt active care — so reviewers dig into encryption of live media, access logging over patient records, and tested failover for the systems clinicians use during a visit. SOC 2 complements HIPAA; it does not replace it.
Trust Services Criteria focus for Telehealth
Security (the Common Criteria) is mandatory in every SOC 2 report. The other four criteria are elective — you scope them in based on what your customers actually rely on. Here is how telehealth companies typically scope them, and why:
| Criterion | Typical scope | Why it matters in Telehealth |
|---|---|---|
| Security | Always in scope | Mandatory in every SOC 2. For telehealth, expect scrutiny on access to systems carrying ePHI, encryption of live video and RPM streams in transit, and change control over any code path that can reach a clinical encounter. |
| Availability | Usually in scope | Care is delivered in real time, so downtime can interrupt a visit or delay a prescription. Health-system contracts often carry SLAs, and reviewers want tested failover, capacity planning, and incident evidence for the systems clinicians rely on live. |
| Confidentiality | Usually in scope | ePHI and covered-entity data are confidential by the BAA. Reviewers look for data classification, encryption, retention, and disposal controls over recordings, transcripts, and monitoring data. |
| Processing Integrity | Sometimes | Scoped in mainly for e-prescribing and RPM workflows where the accuracy and completeness of a prescription or a device reading drives a clinical decision; platforms that only connect patient and clinician often leave it out. |
| Privacy | Common | Comes up when you make direct commitments to patients about how their health data is used, especially in consumer-facing virtual care. Many B2B telehealth vendors handle PHI through the BAA and Confidentiality, adding Privacy when buyers ask. |
Each elective criterion adds controls and evidence — and cost. Scope what your customers demand in security reviews, not everything at once.
Scoping decisions specific to Telehealth
These are the Telehealth-specific calls that shape your system description, control list, and ultimately your audit price. Settle them before you request quotes — firms price scope, not industry labels.
Draw the ePHI boundary across the full visit path
Decide which systems store, process, or transmit ePHI across the encounter — waiting room, live video, chat, recordings and transcripts, e-prescribing, and RPM ingestion — and make that the audited boundary. Transcription services, notification pipelines, and logs that capture PHI are the ones teams miss.
Map BAAs to every subprocessor in the care flow
Your video or WebRTC vendor, SMS and notification provider, e-prescribing network, RPM device cloud, and cloud host each touch ePHI and should sit under a BAA, typically carved out as subservice organizations. Confirm each has its own SOC 2 or HIPAA attestation before your audit starts.
Availability evidence tuned for live care
Downtime here interrupts care, not just access. Auditors sample tested failover, redundancy for real-time media, on-call incident response, and status communication, so build the availability evidence around clinical encounters rather than generic uptime dashboards.
Audit logging over PHI access and encounters
Covered-entity customers expect immutable logs of who viewed which patient record, recording, or transcript and when. Make sure logging captures PHI access inside the application and break-glass events — not just infrastructure and login events.
Encryption of live media and device streams
Encrypt video and audio in transit, recordings at rest, and RPM telemetry from connected devices, and be ready to show key management. Reviewers treat live-media and device channels as first-class ePHI paths, not incidental traffic.
What a SOC 2 audit costs for telehealth companies
These are first-party published rates from accredited firms on the AuditNex network — actual prices, not survey estimates. Data as of 2026-07-26.
Quote requests priced at network rates: Withheld — 2 samples, below our 5-sample minimum.
Frameworks telehealth companies pair with SOC 2
SOC 2 is rarely the only requirement in this category. These are the frameworks most often pursued alongside it — and overlapping evidence you can reuse if you plan both from the start:
| Framework | Why it comes up alongside SOC 2 |
|---|---|
| HIPAA Security & Privacy Rules | The reason telehealth buyers ask for anything at all. SOC 2 evidence overlaps heavily with the HIPAA safeguards, so one control set can support both — but a SOC 2 report does not make you HIPAA compliant. |
| HITRUST CSF | Some hospital systems and health plans request HITRUST specifically. Its controls map closely to SOC 2, so firms often plan the two together and reuse evidence collected for one to reduce work on the other. |
| ISO 27001 | Comes up with international virtual-care deployments and larger enterprise health customers who prefer certification to attestation. The ISMS overlaps substantially with SOC 2 Security controls. |
Finding an auditor who knows Telehealth
Best SOC 2 auditors for healthcare › · All auditor profiles › · How we verify auditors ›
SOC 2 for Telehealth: common questions
Does a SOC 2 report make our telehealth platform HIPAA compliant?
No. SOC 2 and HIPAA overlap heavily in technical and administrative safeguards, so the same controls often support both, but HIPAA compliance is a separate legal obligation you attest to yourself and back with a BAA. Most covered-entity buyers want to see both a signed BAA and a current SOC 2 Type 2.
Why does availability matter more for a telehealth SOC 2?
Because care is delivered in real time. When your platform is down, a visit cannot happen or a prescription is delayed, so health-system buyers scrutinize tested failover, redundancy for live media, and incident response far more than they would for a system that only stores data. Many telehealth vendors scope Availability for exactly this reason.
How do we handle the video vendor and RPM device cloud in scope?
Both process ePHI on your behalf, so they belong under a BAA and are usually carved out as subservice organizations in your system description. Document the complementary controls you rely on them for and collect their SOC 2 or HIPAA attestations before your audit begins.
Should telehealth add the Privacy criterion or rely on Confidentiality?
Many B2B telehealth companies handle PHI obligations through the BAA and scope Confidentiality plus Security, treating Privacy as elective. If you run consumer-facing virtual care and make direct commitments to patients about how their data is used, or a buyer specifically asks, adding Privacy strengthens the report.
Get SOC 2 quotes scoped for Telehealth
Answer five questions once — we’ll show accredited auditors that fit your scope, with transparent pricing and no sales calls. Scope it the way this guide describes: report type, criteria mix, and timeline are what drive your quotes.
Start a quote →