HIPAA·12 min read

SOC 2 and HIPAA Compliance: Overlap, Gaps, and Which Comes First

Every healthcare SaaS thinks they need HIPAA first. Most actually need SOC 2 first, then bolt on HIPAA. This guide walks through exactly why—and where the two frameworks protect different things.


Do you need SOC 2, HIPAA, or both?

The answer depends on who your buyers are. If you're selling to hospitals, clinics, or any entity handling Protected Health Information (PHI), you need HIPAA full stop. But if you're building a patient communication app used by a clinic (not the clinic itself), your buyers—enterprise DevOps teams, security directors, CTOs—will ask for SOC 2 first.

Here's the distinction: SOC 2 audits your infrastructure and controls. HIPAA regulates how you handle patient data specifically. A clinic with SOC 2 feels safe about your uptime and security. A clinic with HIPAA feels safe about your patient data handling. Most don't ask for both at once; they ask for SOC 2 as the baseline, then—if they touch PHI—they layer HIPAA on top.

Where SOC 2 and HIPAA overlap

Both frameworks cover similar ground:

  • Encryption in transit and at rest — SOC 2 requires "encryption in transit" (HTTPS) and "encryption of sensitive data at rest." HIPAA requires the same, with explicit language around PHI.
  • Access controls — both demand role-based access, audit logging, and periodic recertification of who has access to what.
  • Audit logging and monitoring — SOC 2 requires 90 days of logs; HIPAA requires 6 years of audit trails for PHI.
  • Vulnerability management — both require you to scan for, track, and remediate known vulnerabilities.
  • Incident response — both require a documented process to detect, report, and respond to security incidents.

The overlap is roughly 60–65%. If you've built SOC 2 Type II controls, you're halfway to HIPAA. But "halfway" is still real work—HIPAA layers on PHI-specific rules that SOC 2 doesn't touch.

Where they diverge: HIPAA's extras

HIPAA adds these requirements that SOC 2 doesn't enforce:

  • Business Associate Agreements (BAAs) — your customers must sign a BAA before they send you PHI. No BAA = no legal right to process their data. SOC 2 has no equivalent.
  • Minimum necessary — you must limit access to PHI to only what's needed for the job. SOC 2 requires access controls, but not the "minimum necessary" framing.
  • Workforce security — HIPAA mandates background checks and role-based access training for anyone with PHI access. SOC 2 requires access controls but doesn't mandate background checks.
  • Breach notification — HIPAA requires you to notify affected individuals if more than 500 records are breached. Notify HHS. Notify the press. SOC 2 requires incident response; HIPAA escalates it.
  • Portable media and devices — HIPAA has explicit rules around USB drives, laptops, and portable equipment containing PHI (encryption required, disposal tracked). SOC 2 doesn't single these out.
  • Sanctions — HIPAA requires you to have a written policy for what happens when an employee violates HIPAA. SOC 2 doesn't require this formalization.

Which framework your HealthTech buyer leads with

Most HealthTech CTOs ask for SOC 2 first. Here's why:

  1. Broader applicability — SOC 2 works for any cloud SaaS, not just healthcare. A CTO evaluating three vendor options will use SOC 2 as the common yardstick.
  2. Faster procurement gate — SOC 2 Type II takes 6 months to audit and 3 months to get the report. HIPAA takes longer if you're new to it (assessment + remediation + audit + certification).
  3. Lower cost entry — SOC 2 Type II is roughly $40–60K. HIPAA assessment + remediation + audit can run $80–150K depending on your stack.
  4. Risk assumption — if your platform is SOC 2 Type II attested, the risk of a breach (data theft, ransomware, uptime failure) is substantially lower. That de-risks the clinical use case.

Once SOC 2 is in place, if the buyer actually handles PHI (schedules, notes, imaging), the conversation shifts to HIPAA. At that point, you're adding controls on top of an existing security posture, not building from scratch.

SOC 2 Type II vs. HIPAA audit timeline

PhaseSOC 2 Type IIHIPAA
Gap assessment2–3 weeks3–4 weeks
Remediation8–12 weeks12–16 weeks (PHI-specific rules add time)
Observation window6 months (required)1 year (implied; CMS expects annual audit)
Audit3–4 weeks4–6 weeks (more intensive on PHI flows)
Report delivery6–10 weeks after audit ends8–12 weeks after audit ends
Total elapsed~10 months~14–18 months

The 6-month SOC 2 observation window and HIPAA's annual expectation mean they often run in parallel—you don't wait for SOC 2 to finish before starting HIPAA remediation.

Procurement checklist: Do they ask for HIPAA or SOC 2?

If a buyer says, "We need HIPAA," they usually mean one of two things:

  1. "We handle PHI and need proof you're compliant" → You need full HIPAA.
  2. "We're a healthcare org and our security team wants compliance proof" → They likely start with SOC 2, then layer HIPAA if they touch PHI internally.

Ask the clarifying question: "Do you process or store patient health information through our platform, or do you use our software to manage clinical workflows?"

  • If they process PHI → HIPAA required.
  • If they use your software as a tool but don't send you PHI → SOC 2 is the gate.

Most venture-backed HealthTech platforms live in that second bucket. Clinics buy workflow software; they don't delegate data handling to it.

Building both: the efficient sequence

If you know you'll need both:

  1. Start with SOC 2 — it's faster, cheaper, and serves as the security foundation.
  2. Run HIPAA assessment in parallel — identify gaps specific to PHI handling (BAAs, breach notification procedures, workforce training).
  3. Layer HIPAA controls on top of SOC 2 infrastructure — encryption, logging, and access controls are already there; you're adding BAAs, policies, and PHI-specific workflows.
  4. Audit both in sequence — SOC 2 first (need the 6-month observation window), then HIPAA (12 months later, building on SOC 2's foundation).

This approach means you're SOC 2 Type II attested in month 10, and HIPAA-ready (audit-pending) by month 20. Doing them sequentially would take 24+ months.


Frequently Asked Questions

Q: If we're SOC 2 Type II compliant, can we claim we're HIPAA-ready? Not quite. SOC 2 Type II proves your infrastructure is secure. HIPAA requires additional proofs: BAAs signed with patients or their custodians, breach notification procedures, workforce training on PHI handling, and annual audit cycles. You'll pass the infrastructure part of HIPAA but fail the operational part.

Q: Which compliance framework costs more? SOC 2 Type II typically runs $40–60K (assessment, remediation, audit, report). HIPAA runs $80–150K because it touches legal agreements (BAAs), workforce training, and PHI-specific audit procedures. If you do both, expect $120–180K total (not double, because some work overlaps).

Q: Do we need a BAA if we're just hosting customer data, not processing it? Yes. HIPAA's definition of "processing" includes hosting, accessing, or storing PHI—even if you don't read or analyze it. If patient data lands on your servers, you need a BAA before it does.

Q: How often do we need to audit SOC 2 and HIPAA? SOC 2 Type II audit is once per year, reporting on 12 months of controls. HIPAA audit expectations are annual (though regulations don't mandate it like SOC 2 does). Both require continuous monitoring in between.

Q: Can we get HIPAA without SOC 2? Technically, yes. But smart procurement teams will ask for SOC 2 first anyway—it's the industry-standard proof of secure infrastructure. Adding HIPAA alone looks like you're cutting corners on the baseline.


Ready to Sequence SOC 2 and HIPAA?

If you're building healthcare SaaS, the right sequence is: SOC 2 Type II first (foundational security), then HIPAA on top (if you handle PHI). Both have different timelines, compliance officers, and audit costs. Get the sequencing wrong and you'll spend 2 years chasing audit cycles instead of 14 months.

Schedule a scoping call →