Skip to main content
Plain-English Compliance Guide

SOC 2 vs. HIPAA: which do you actually need?

Two of the most-requested compliance frameworks in the US — and the source of a lot of confusion. They protect different things, for different reasons, and which one applies to you usually comes down to one question: what data do you touch, and who's asking?

The 30-second answer: If you handle protected health information (PHI) for a healthcare provider, plan, or their vendors, HIPAA is a legal requirement. If an enterprise customer is asking how you protect their data before they'll sign, they almost always mean SOC 2. Plenty of companies — especially health-tech SaaS — end up needing both.

The core difference

People treat SOC 2 and HIPAA as interchangeable "security stamps." They're not. One is a voluntary report you choose to produce to win business; the other is federal law you're obligated to follow.

SOC 2

Driven by your customers
  • An attestation report issued by a licensed CPA firm under AICPA standards — not a government "certification."
  • Built around five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
  • Voluntary — but enterprise buyers frequently require it before they'll sign.
  • Common for B2B SaaS and any company storing or processing customer data in the cloud.

HIPAA

Driven by federal law
  • A US law (Privacy, Security, and Breach Notification Rules) enforced by HHS — mandatory, with real penalties.
  • Applies to "covered entities" (providers, health plans) and their "business associates" (vendors touching PHI).
  • There is no official government HIPAA "certificate" — compliance is an ongoing obligation, not a one-time pass.
  • Common for clinics, health-tech, billing companies, and any vendor handling patient data.

Who needs SOC 2

You're probably looking at SOC 2 if any of these sound familiar:

  • A prospect's security or procurement team sent you a questionnaire — or asked for "your SOC 2" — during the sales process.
  • You sell software or a service that stores, processes, or transmits your customers' data.
  • You're moving upmarket and bigger deals keep stalling at the security review.

SOC 2 comes in two flavors: Type I (your controls are designed properly at a point in time) and Type II (they actually operated effectively over a period, usually 3–12 months). Enterprise buyers generally want Type II.

Who needs HIPAA

HIPAA isn't optional and it isn't customer-driven — it's triggered by the data itself. You're in scope if:

  • You're a healthcare provider, health plan, or healthcare clearinghouse (a "covered entity").
  • You're a vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf (a "business associate") — e.g., a SaaS tool used by a clinic, a billing service, or a cloud host.
  • If you're a business associate, you'll typically be asked to sign a Business Associate Agreement (BAA) before you can handle PHI.

Can you need both? Often, yes.

A health-tech SaaS company is the classic case: HIPAA applies because you handle PHI, and your enterprise hospital customers ask for SOC 2 before they'll buy. The good news is the work overlaps heavily — access control, encryption, logging, vendor management, and incident response satisfy requirements on both sides. Build the controls once, map them to both frameworks, and you avoid doing the work twice.

Quick decision guide

  • Handle PHI for healthcare? → HIPAA is mandatory. Start there.
  • Enterprise customers gating deals on security? → You need SOC 2.
  • Health-tech selling to providers? → Plan for both; build controls once and map them.
  • Neither yet, but growing? → A readiness checklist now saves a scramble later.
One honest caveat: readiness is not certification. A checklist or a readiness pack gets you organized and closes obvious gaps — but a SOC 2 report still requires an independent CPA firm, and HIPAA is an ongoing legal obligation, not a one-time badge. Anyone selling you an instant "SOC 2 certificate" is selling something that doesn't exist.

Where to start — free

Before you spend a dollar, find out where you actually stand. These take a few minutes and need no email:

SOC 2 Readiness Checklist

15 checks across all five Trust Services Criteria. See your gaps before an auditor does.

Open the Checklist →

Vendor Risk Inventory

List every vendor that touches your data and confirm you have a signed DPA or BAA.

Open the Template →

Ready to move faster? The SOC 2 Readiness Pack and HIPAA Compliance Pack ($147 each) give you the full mapped checklist plus policy templates — or grab a free NIST-aligned policy template to start. Want a human read on your situation? Book a free Risk Snapshot call.