The first time a hospital’s security team reviews your product, the questionnaire will ask some version of the same question: are you HIPAA compliant, do you have a SOC 2, are you HITRUST certified? The three sound like alternatives. They are not. HIPAA is a law you must follow, SOC 2 is an audit report you can choose to get, and HITRUST is a certification you can choose to earn. This guide explains what each one is, what a US health system actually expects from a vendor at each stage, and which one to spend money on first. For the detail of a SOC 2 audit itself, see our SOC 2 Type II guide for healthcare SaaS.
1. The Short Answer
HIPAA is mandatory if you handle protected health information for a covered entity. SOC 2 and HITRUST are optional ways to prove your security to customers. In practice, for a US health-tech company selling to providers:
- Everyone needs a working HIPAA program: a risk analysis, the Security Rule safeguards, policies, training, and signed business associate agreements (BAAs). There is no certificate to buy.
- Most vendors selling to hospitals will be asked for a SOC 2 Type II report. It is the most widely accepted security report across all industries, so it also serves non-healthcare buyers.
- Some vendors will be asked for HITRUST, usually by large health systems and payers, and usually when the vendor stores or processes significant volumes of patient data.
If you are early and have no hospital customers yet, build the HIPAA program properly, then get SOC 2. Start HITRUST when a specific buyer requires it in writing, or when your target market is clearly large systems and payers.
2. What Each One Actually Is
These three are different kinds of thing, which is why comparing them feature by feature confuses people.
| HIPAA | SOC 2 | HITRUST | |
|---|---|---|---|
| What it is | A federal law and its regulations (Privacy, Security and Breach Notification Rules) | An attestation report on your controls, under AICPA standards | A certifiable control framework (the HITRUST CSF) and assurance program |
| Mandatory? | Yes, for covered entities and their business associates | No. A market expectation | No. A market expectation, stronger in healthcare |
| Who checks it | HHS Office for Civil Rights, after a complaint or breach | An independent CPA firm | A HITRUST-authorised External Assessor, then HITRUST’s own quality review |
| What you get | Nothing. You are compliant or exposed | A report (Type I: one date; Type II: a period, usually 6–12 months) | A certification report at e1, i1 or r2 level |
| Healthcare-specific? | Yes | No | Built for healthcare, now used more widely |
| Renewal | Ongoing; risk analysis reviewed regularly | Annually, with a new audit period | e1 and i1 yearly; r2 every two years with an interim review at one year |
| What hospitals use it for | The legal floor, written into the BAA | Proof your controls work, read by the security team | A standard assurance that lets them skip much of their own questionnaire |
3. What a Hospital Security Review Asks For
When a US health system considers a vendor that will touch patient data, the request usually arrives as a bundle. The exact contents vary by organisation, but expect most of these:
- A security questionnaire. Often the health system’s own, sometimes a standard one such as the Shared Assessments SIG. Expect anything from fifty to several hundred questions on access control, encryption, logging, incident response, backups and subcontractors.
- Your BAA, or theirs. Many large systems insist on their own paper. Read the breach-notification window and the indemnity clauses carefully. Our BAA vs HIPAA explainer covers what the agreement must contain.
- Evidence of independent assurance. This is where SOC 2 or HITRUST comes in. A current report can replace a large share of the questionnaire, and some systems will accept it instead of the questionnaire altogether.
- A recent penetration test summary from an independent firm.
- Policies, typically information security, incident response, and access management, plus proof of workforce training.
- Architecture and data-flow details: where PHI is stored, which cloud and region, which subprocessors touch it, and how data is returned or destroyed when the contract ends.
The reason HITRUST matters to some buyers is that it standardises step 3. A group of health-system and payer security leaders, now organised as the Health 3rd Party Trust Initiative (Health3PT), has adopted the HITRUST assurance program as its recommended methodology, with the stated aim of reducing proprietary questionnaires and one-off assessments. If your target customers are in that group, or behave like it, HITRUST will come up early.
4. Which to Get First, by Stage and Buyer
The right order depends less on your company’s size than on who signs your contracts.
| Your situation | What to have | What to plan next |
|---|---|---|
| Pre-revenue, pilots with small practices | A real HIPAA program: risk analysis, safeguards, policies, BAAs with every vendor that touches PHI | SOC 2 readiness: pick a compliance tool, start operating controls |
| Selling to clinics and mid-size groups | HIPAA program, plus SOC 2 Type I if a buyer needs a report now | SOC 2 Type II as soon as an observation period can close |
| First regional health system | SOC 2 Type II, recent pen test, completed questionnaire, BAA | Ask the buyer directly whether HITRUST will be required at renewal |
| Large health systems, IDNs and payers | SOC 2 Type II, and HITRUST if they require it; often r2 | Keep both current; plan r2 interim assessments |
| Low-risk tools with little or no PHI (scheduling, marketing, analytics on de-identified data) | HIPAA basics where any PHI flows, SOC 2 if buyers ask | HITRUST e1 if a buyer wants a healthcare-native signal at low cost |
One rule holds across all of them: get the requirement in writing before you scope anything. “We prefer HITRUST” in a sales call and “HITRUST r2 required at contract signature” in a procurement document are very different budgets.
5. HITRUST e1, i1 or r2: Choosing the Level
HITRUST offers three validated assessments, all of which can lead to certification. Work done for a lower level can be carried into a higher one, so starting at e1 is not wasted effort.
| Assessment | Requirements | Valid for | Good fit |
|---|---|---|---|
| e1 (essentials) | 43 core controls | 1 year | Startups and lower-risk vendors that need foundational, healthcare-recognised assurance |
| i1 (implemented) | 182 control requirements | 1 year | Vendors with an established security program and moderate risk |
| r2 (risk-based) | Tailored to your risk factors; the largest set | 2 years, with an interim assessment at year one | Vendors handling large volumes of PHI for large systems and payers |
Figures are from HITRUST’s assessment overview. The framework behind all three, the HITRUST CSF, is updated several times a year; version 11.9 was released in September 2026. HITRUST sets deadlines after which new e1 and i1 assessments must use the current version, so check which version your assessor will use before you start.
The most common mistake is choosing the level before understanding the driver. If a health system’s contract will require r2, an e1 certificate will not satisfy it, however good it is. Ask.
6. Cost and Timeline: Typical Ranges
None of these have list prices. The ranges below are industry estimates for a small-to-mid-size health-tech company, and your scope, existing maturity and choice of firm will move them substantially.
| Typical external cost | Typical time to first report | |
|---|---|---|
| HIPAA program | No audit fee. Costs are tooling, a risk analysis (internal or outsourced), training and legal review of BAAs | Ongoing; a credible baseline in weeks to a few months |
| SOC 2 Type I | Audit fees from around 15,000 USD for a Security-only scope | A few months, mostly readiness work |
| SOC 2 Type II | Commonly 15,000–80,000+ USD in audit fees, plus a compliance tool and internal time | Roughly 8 months once controls are operating (a 6-month window plus fieldwork) |
| HITRUST e1 | Commonly tens of thousands of USD including assessor fees | Often 3–4 months |
| HITRUST r2 | Commonly 150,000 USD or more in the first year, all in | Commonly 9–18 months for a company without an existing program |
The SOC 2 figures match our detailed SOC 2 cost breakdown. For every option, the cost line teams under-estimate is internal engineering and operations time: collecting evidence, fixing gaps, and answering the assessor.
7. One Controls Program, Three Outputs
The three overlap heavily. HITRUST was built partly to harmonise HIPAA with other frameworks, and SOC 2’s Security criteria cover much of the same ground. The efficient approach is one controls program that produces evidence for all three, not three parallel projects.
The controls that do the most work across all three:
- Risk analysis. Required by HIPAA, expected by both SOC 2 and HITRUST. Do it properly once and update it on a schedule.
- Access control: unique user IDs, least privilege, MFA, timely removal of leavers, quarterly access reviews.
- Audit logging of who accessed which records, kept tamper-resistant. See our guide to what HIPAA audit logs must capture.
- Encryption at rest and in transit. See our PHI encryption requirements guide.
- Vendor management: a list of subprocessors, BAAs with each one that touches PHI, and a review of their own reports.
- Incident response: a written plan, a tabletop exercise, and breach-notification timelines that match your BAAs.
- Change management: code review, approvals and deployment records.
Two things save real money. First, inheritance: if your cloud provider holds its own SOC 2 report or HITRUST certification, the controls it is responsible for (physical security, much of the infrastructure) can be relied on or inherited rather than tested again. Second, shared fieldwork: many assessment firms are both CPA firms and HITRUST External Assessors, so evidence collected once can serve both engagements if you plan the timing together.
8. Six Mistakes That Stall Hospital Deals
- Leading with a “HIPAA certified” badge. Hospital reviewers know there is no such thing. It can cost you credibility with the exact person deciding whether to approve you.
- Offering your cloud provider’s SOC 2 as your own. AWS’s report covers AWS. The reviewer needs one that covers your company, your application and your people.
- A report whose scope misses the product being bought. A SOC 2 that covers your corporate IT but not the platform the hospital will use does not answer their question. Check the system description section before you send it.
- Letting a report go stale. SOC 2 reports are generally treated as current for about twelve months after the period ends. If yours is older, expect to be asked for a bridge letter or a newer report.
- Starting HITRUST on a hunch. It is the most expensive option. Start it because a buyer requires it, or because your market clearly does.
- Treating the questionnaire as paperwork. Answers become contractual representations in many agreements. A “yes” to MFA everywhere that is really “yes, mostly” is a liability in a breach investigation.
9. Where VertiComply Fits
VertiComply generates healthcare applications with the technical safeguards these frameworks test: role-based access control, audit logging of record access, and encrypted connections. Those are a large share of the technical controls a SOC 2 or HITRUST assessor will look at, and having them designed in from the start is much cheaper than retrofitting them.
What we do not do is give you a certification. A SOC 2 report or a HITRUST certification covers your organisation: your policies, your people, your access reviews, your incident response, and the way you operate the system over time. A generated application is one input to that, and no software product can substitute for the rest. Our compliance framework pages explain which controls we generate and which remain your responsibility.
To see where you stand before paying an auditor, our free readiness checkers cover SOC 2, HITRUST and HIPAA. If you are at the stage of building the program from scratch, start with HIPAA for startups and our HIPAA compliance checklist.
10. Frequently Asked Questions
What is the difference between HITRUST and SOC 2?
SOC 2 is an attestation report issued by a CPA firm under AICPA standards, describing how well your controls meet the Trust Services Criteria; it is used across all industries. HITRUST is a certification against the HITRUST CSF, a prescriptive control framework built for healthcare that maps to HIPAA, NIST, ISO 27001 and others. SOC 2 is more widely requested; HITRUST is more often required by large US health systems and payers.
Is there an official HIPAA certification?
No. HHS does not certify organisations for HIPAA compliance and does not recognise private “HIPAA certifications.” HIPAA requires periodic evaluation of your safeguards, which an outside firm can perform, but no certificate proves compliance or protects you from a later finding by the Office for Civil Rights.
Do hospitals require SOC 2 from vendors?
Many do, particularly for vendors that store or process patient data. Requirements vary by health system: some accept a completed security questionnaire for low-risk vendors, many ask for a SOC 2 Type II report, and some large systems and payers require HITRUST certification. Ask for the requirement in writing early in the sales process.
Do I need HITRUST if I already have SOC 2?
Only if a customer requires it. SOC 2 Type II satisfies many health systems. HITRUST becomes necessary when a large system or payer makes it a contract condition, which is more common for vendors handling large volumes of PHI. If you expect to need both, plan them together so evidence can be shared.
Does SOC 2 cover HIPAA?
Not by itself. A SOC 2 report shows your controls meet the Trust Services Criteria, which overlap heavily with HIPAA’s Security Rule, but it does not assess HIPAA-specific requirements such as BAAs, the Privacy Rule or breach-notification procedures. Some firms offer a SOC 2 with additional HIPAA criteria mapped in, often called SOC 2+ HIPAA.
Which HITRUST assessment should a startup get?
Usually e1, the essentials assessment with 43 core controls and a one-year certification, unless a customer has specified i1 or r2. Work from an e1 carries forward into i1 and r2, so it is a reasonable first step when a healthcare-specific signal is needed at lower cost.
How long does HITRUST certification take?
It varies with the level and your starting point. Industry estimates put an e1 at around three to four months, and an r2 at roughly nine to eighteen months for a company without an existing security program, including remediation. HITRUST’s own quality review after the assessor submits adds time at the end.
What security documents should a health-tech startup have ready for a hospital review?
A completed security questionnaire, a signed or ready-to-sign BAA, a SOC 2 report or a plan and timeline for one, a recent independent penetration test summary, core security policies, proof of workforce HIPAA training, and a data-flow description listing where PHI is stored and which subprocessors touch it.
Last reviewed 1 October 2026. Cost and timeline figures are typical industry ranges, not quotes. HITRUST assessment details and CSF versions change frequently, so check HITRUST’s current documentation before scoping. Nothing here is legal advice.