Beyond SOC 2
What is the difference between HITRUST and SOC 2?
What is the difference between HITRUST and SOC 2?
SOC 2 produces an attestation report from a CPA firm, and HITRUST produces a certification from the HITRUST Alliance. A SOC 2 report is issued by a licensed CPA firm, and the company describes its own controls against the AICPA Trust Services Criteria. A HITRUST certification is issued by the HITRUST Alliance after an authorized external assessor tests the company against fixed requirement statements in the HITRUST CSF. SOC 2 is the default ask across B2B software. HITRUST is requested mostly by large health systems and payers.
HITRUST and SOC 2 side by side
| SOC 2 | HITRUST | |
|---|---|---|
| What you receive | An attestation report with the auditor's opinion | A certification letter plus an assessment report |
| Who issues it | A licensed CPA firm | The HITRUST Alliance, after testing by an authorized external assessor and HITRUST's quality review |
| Control set | You define controls against the Trust Services Criteria | Prescriptive requirement statements from the HITRUST CSF |
| Size of scope | Varies with the controls you define and the criteria in scope | e1: 44 requirements; i1: 182 requirements; r2: risk-based, tailored to the organization |
| Validity | Type II covers a 3 to 12 month period; renewed annually | e1 and i1: one year; r2: two years with an interim assessment |
| Typical requester | Enterprise buyers in any industry | Large health systems, payers, and some healthcare partners |
| Relation to HIPAA | Can evidence HIPAA security practices; HIPAA can be added to scope | Requirements incorporate HIPAA security provisions |
The e1 and i1 counts are from HITRUST CSF version 11. HITRUST updates the CSF regularly, so the exact requirement set depends on the version in force when the assessment starts.
Which one a healthcare SaaS company needs
The order most vendors follow is SOC 2 first, HITRUST when a customer names it. SOC 2 opens enterprise deals in every vertical, including healthcare, and it can be scoped to include HIPAA-relevant controls. HITRUST becomes necessary when a specific health system or payer writes it into the vendor requirements, which is common among the largest hospital networks and less common among clinics, digital health companies, and life sciences buyers.
The HITRUST tier matters as much as the choice to pursue it. An e1 covers foundational hygiene and is a quick first step. An i1 is what many health systems accept for moderate-risk vendors. An r2 is the most demanding and the one the largest organizations ask for when a vendor handles significant volumes of PHI. Ask the customer which tier they accept before scoping anything.
How HIPAA fits with both
HIPAA is neither a report nor a certification. It is a federal law, enforced by the HHS Office for Civil Rights, and there is no official HIPAA certification from any government body. A SOC 2 report or a HITRUST certification is evidence that your security practices meet recognized standards, which helps in a customer review and in an OCR inquiry, but neither replaces the obligations HIPAA imposes directly: a risk analysis, business associate agreements, and breach notification. For background on the certification itself, see what HITRUST is and why hospitals require it.