Skip to main content
Compliance
HITRUST
SOC 2
HIPAA
Vendor Risk
Security Review
Healthcare SaaS
Certification
Compliance

HITRUST vs SOC 2 vs HIPAA: What US Hospitals Actually Ask a Health-Tech Vendor For (2026)

By Garvita Amin, Co-Founder & CTO, VertiComply

October 1, 2026

13 min read

Share this article

HITRUST vs SOC 2 vs HIPAA: a comparison of the law, the audit report and the certification that US hospitals ask health-tech vendors for

The first time a hospital’s security team reviews your product, the questionnaire will ask some version of the same question: are you HIPAA compliant, do you have a SOC 2, are you HITRUST certified? The three sound like alternatives. They are not. HIPAA is a law you must follow, SOC 2 is an audit report you can choose to get, and HITRUST is a certification you can choose to earn. This guide explains what each one is, what a US health system actually expects from a vendor at each stage, and which one to spend money on first. For the detail of a SOC 2 audit itself, see our SOC 2 Type II guide for healthcare SaaS.

1. The Short Answer

HIPAA is mandatory if you handle protected health information for a covered entity. SOC 2 and HITRUST are optional ways to prove your security to customers. In practice, for a US health-tech company selling to providers:

  • Everyone needs a working HIPAA program: a risk analysis, the Security Rule safeguards, policies, training, and signed business associate agreements (BAAs). There is no certificate to buy.
  • Most vendors selling to hospitals will be asked for a SOC 2 Type II report. It is the most widely accepted security report across all industries, so it also serves non-healthcare buyers.
  • Some vendors will be asked for HITRUST, usually by large health systems and payers, and usually when the vendor stores or processes significant volumes of patient data.

If you are early and have no hospital customers yet, build the HIPAA program properly, then get SOC 2. Start HITRUST when a specific buyer requires it in writing, or when your target market is clearly large systems and payers.

2. What Each One Actually Is

These three are different kinds of thing, which is why comparing them feature by feature confuses people.

HIPAASOC 2HITRUST
What it isA federal law and its regulations (Privacy, Security and Breach Notification Rules)An attestation report on your controls, under AICPA standardsA certifiable control framework (the HITRUST CSF) and assurance program
Mandatory?Yes, for covered entities and their business associatesNo. A market expectationNo. A market expectation, stronger in healthcare
Who checks itHHS Office for Civil Rights, after a complaint or breachAn independent CPA firmA HITRUST-authorised External Assessor, then HITRUST’s own quality review
What you getNothing. You are compliant or exposedA report (Type I: one date; Type II: a period, usually 6–12 months)A certification report at e1, i1 or r2 level
Healthcare-specific?YesNoBuilt for healthcare, now used more widely
RenewalOngoing; risk analysis reviewed regularlyAnnually, with a new audit periode1 and i1 yearly; r2 every two years with an interim review at one year
What hospitals use it forThe legal floor, written into the BAAProof your controls work, read by the security teamA standard assurance that lets them skip much of their own questionnaire
There is no official HIPAA certification HHS has said plainly that no standard requires a covered entity to “certify” compliance with the Security Rule, that it does not endorse or recognise private “HIPAA certifications,” and that such certifications do not protect an organisation from a later finding of a violation (HHS FAQ). A “HIPAA certified” badge tells a hospital reviewer you paid for a course or a third-party review. It is not what they are asking for.

3. What a Hospital Security Review Asks For

When a US health system considers a vendor that will touch patient data, the request usually arrives as a bundle. The exact contents vary by organisation, but expect most of these:

  1. A security questionnaire. Often the health system’s own, sometimes a standard one such as the Shared Assessments SIG. Expect anything from fifty to several hundred questions on access control, encryption, logging, incident response, backups and subcontractors.
  2. Your BAA, or theirs. Many large systems insist on their own paper. Read the breach-notification window and the indemnity clauses carefully. Our BAA vs HIPAA explainer covers what the agreement must contain.
  3. Evidence of independent assurance. This is where SOC 2 or HITRUST comes in. A current report can replace a large share of the questionnaire, and some systems will accept it instead of the questionnaire altogether.
  4. A recent penetration test summary from an independent firm.
  5. Policies, typically information security, incident response, and access management, plus proof of workforce training.
  6. Architecture and data-flow details: where PHI is stored, which cloud and region, which subprocessors touch it, and how data is returned or destroyed when the contract ends.

The reason HITRUST matters to some buyers is that it standardises step 3. A group of health-system and payer security leaders, now organised as the Health 3rd Party Trust Initiative (Health3PT), has adopted the HITRUST assurance program as its recommended methodology, with the stated aim of reducing proprietary questionnaires and one-off assessments. If your target customers are in that group, or behave like it, HITRUST will come up early.

The HIPAA Security Rule may get stricter HHS proposed a major update to the Security Rule in a notice of proposed rulemaking issued in December 2024. It would make encryption and multi-factor authentication required, and would require vulnerability scanning at least every six months and a penetration test at least every twelve months (HHS fact sheet). As of October 2026 it has not been finalised. Hospital questionnaires already ask about most of these controls, so build them now regardless.

4. Which to Get First, by Stage and Buyer

The right order depends less on your company’s size than on who signs your contracts.

Your situationWhat to haveWhat to plan next
Pre-revenue, pilots with small practicesA real HIPAA program: risk analysis, safeguards, policies, BAAs with every vendor that touches PHISOC 2 readiness: pick a compliance tool, start operating controls
Selling to clinics and mid-size groupsHIPAA program, plus SOC 2 Type I if a buyer needs a report nowSOC 2 Type II as soon as an observation period can close
First regional health systemSOC 2 Type II, recent pen test, completed questionnaire, BAAAsk the buyer directly whether HITRUST will be required at renewal
Large health systems, IDNs and payersSOC 2 Type II, and HITRUST if they require it; often r2Keep both current; plan r2 interim assessments
Low-risk tools with little or no PHI (scheduling, marketing, analytics on de-identified data)HIPAA basics where any PHI flows, SOC 2 if buyers askHITRUST e1 if a buyer wants a healthcare-native signal at low cost

One rule holds across all of them: get the requirement in writing before you scope anything. “We prefer HITRUST” in a sales call and “HITRUST r2 required at contract signature” in a procurement document are very different budgets.

5. HITRUST e1, i1 or r2: Choosing the Level

HITRUST offers three validated assessments, all of which can lead to certification. Work done for a lower level can be carried into a higher one, so starting at e1 is not wasted effort.

AssessmentRequirementsValid forGood fit
e1 (essentials)43 core controls1 yearStartups and lower-risk vendors that need foundational, healthcare-recognised assurance
i1 (implemented)182 control requirements1 yearVendors with an established security program and moderate risk
r2 (risk-based)Tailored to your risk factors; the largest set2 years, with an interim assessment at year oneVendors handling large volumes of PHI for large systems and payers

Figures are from HITRUST’s assessment overview. The framework behind all three, the HITRUST CSF, is updated several times a year; version 11.9 was released in September 2026. HITRUST sets deadlines after which new e1 and i1 assessments must use the current version, so check which version your assessor will use before you start.

The most common mistake is choosing the level before understanding the driver. If a health system’s contract will require r2, an e1 certificate will not satisfy it, however good it is. Ask.

6. Cost and Timeline: Typical Ranges

None of these have list prices. The ranges below are industry estimates for a small-to-mid-size health-tech company, and your scope, existing maturity and choice of firm will move them substantially.

Typical external costTypical time to first report
HIPAA programNo audit fee. Costs are tooling, a risk analysis (internal or outsourced), training and legal review of BAAsOngoing; a credible baseline in weeks to a few months
SOC 2 Type IAudit fees from around 15,000 USD for a Security-only scopeA few months, mostly readiness work
SOC 2 Type IICommonly 15,000–80,000+ USD in audit fees, plus a compliance tool and internal timeRoughly 8 months once controls are operating (a 6-month window plus fieldwork)
HITRUST e1Commonly tens of thousands of USD including assessor feesOften 3–4 months
HITRUST r2Commonly 150,000 USD or more in the first year, all inCommonly 9–18 months for a company without an existing program

The SOC 2 figures match our detailed SOC 2 cost breakdown. For every option, the cost line teams under-estimate is internal engineering and operations time: collecting evidence, fixing gaps, and answering the assessor.

7. One Controls Program, Three Outputs

The three overlap heavily. HITRUST was built partly to harmonise HIPAA with other frameworks, and SOC 2’s Security criteria cover much of the same ground. The efficient approach is one controls program that produces evidence for all three, not three parallel projects.

The controls that do the most work across all three:

  • Risk analysis. Required by HIPAA, expected by both SOC 2 and HITRUST. Do it properly once and update it on a schedule.
  • Access control: unique user IDs, least privilege, MFA, timely removal of leavers, quarterly access reviews.
  • Audit logging of who accessed which records, kept tamper-resistant. See our guide to what HIPAA audit logs must capture.
  • Encryption at rest and in transit. See our PHI encryption requirements guide.
  • Vendor management: a list of subprocessors, BAAs with each one that touches PHI, and a review of their own reports.
  • Incident response: a written plan, a tabletop exercise, and breach-notification timelines that match your BAAs.
  • Change management: code review, approvals and deployment records.

Two things save real money. First, inheritance: if your cloud provider holds its own SOC 2 report or HITRUST certification, the controls it is responsible for (physical security, much of the infrastructure) can be relied on or inherited rather than tested again. Second, shared fieldwork: many assessment firms are both CPA firms and HITRUST External Assessors, so evidence collected once can serve both engagements if you plan the timing together.

8. Six Mistakes That Stall Hospital Deals

  1. Leading with a “HIPAA certified” badge. Hospital reviewers know there is no such thing. It can cost you credibility with the exact person deciding whether to approve you.
  2. Offering your cloud provider’s SOC 2 as your own. AWS’s report covers AWS. The reviewer needs one that covers your company, your application and your people.
  3. A report whose scope misses the product being bought. A SOC 2 that covers your corporate IT but not the platform the hospital will use does not answer their question. Check the system description section before you send it.
  4. Letting a report go stale. SOC 2 reports are generally treated as current for about twelve months after the period ends. If yours is older, expect to be asked for a bridge letter or a newer report.
  5. Starting HITRUST on a hunch. It is the most expensive option. Start it because a buyer requires it, or because your market clearly does.
  6. Treating the questionnaire as paperwork. Answers become contractual representations in many agreements. A “yes” to MFA everywhere that is really “yes, mostly” is a liability in a breach investigation.

9. Where VertiComply Fits

VertiComply generates healthcare applications with the technical safeguards these frameworks test: role-based access control, audit logging of record access, and encrypted connections. Those are a large share of the technical controls a SOC 2 or HITRUST assessor will look at, and having them designed in from the start is much cheaper than retrofitting them.

What we do not do is give you a certification. A SOC 2 report or a HITRUST certification covers your organisation: your policies, your people, your access reviews, your incident response, and the way you operate the system over time. A generated application is one input to that, and no software product can substitute for the rest. Our compliance framework pages explain which controls we generate and which remain your responsibility.

To see where you stand before paying an auditor, our free readiness checkers cover SOC 2, HITRUST and HIPAA. If you are at the stage of building the program from scratch, start with HIPAA for startups and our HIPAA compliance checklist.

10. Frequently Asked Questions

What is the difference between HITRUST and SOC 2?

SOC 2 is an attestation report issued by a CPA firm under AICPA standards, describing how well your controls meet the Trust Services Criteria; it is used across all industries. HITRUST is a certification against the HITRUST CSF, a prescriptive control framework built for healthcare that maps to HIPAA, NIST, ISO 27001 and others. SOC 2 is more widely requested; HITRUST is more often required by large US health systems and payers.

Is there an official HIPAA certification?

No. HHS does not certify organisations for HIPAA compliance and does not recognise private “HIPAA certifications.” HIPAA requires periodic evaluation of your safeguards, which an outside firm can perform, but no certificate proves compliance or protects you from a later finding by the Office for Civil Rights.

Do hospitals require SOC 2 from vendors?

Many do, particularly for vendors that store or process patient data. Requirements vary by health system: some accept a completed security questionnaire for low-risk vendors, many ask for a SOC 2 Type II report, and some large systems and payers require HITRUST certification. Ask for the requirement in writing early in the sales process.

Do I need HITRUST if I already have SOC 2?

Only if a customer requires it. SOC 2 Type II satisfies many health systems. HITRUST becomes necessary when a large system or payer makes it a contract condition, which is more common for vendors handling large volumes of PHI. If you expect to need both, plan them together so evidence can be shared.

Does SOC 2 cover HIPAA?

Not by itself. A SOC 2 report shows your controls meet the Trust Services Criteria, which overlap heavily with HIPAA’s Security Rule, but it does not assess HIPAA-specific requirements such as BAAs, the Privacy Rule or breach-notification procedures. Some firms offer a SOC 2 with additional HIPAA criteria mapped in, often called SOC 2+ HIPAA.

Which HITRUST assessment should a startup get?

Usually e1, the essentials assessment with 43 core controls and a one-year certification, unless a customer has specified i1 or r2. Work from an e1 carries forward into i1 and r2, so it is a reasonable first step when a healthcare-specific signal is needed at lower cost.

How long does HITRUST certification take?

It varies with the level and your starting point. Industry estimates put an e1 at around three to four months, and an r2 at roughly nine to eighteen months for a company without an existing security program, including remediation. HITRUST’s own quality review after the assessor submits adds time at the end.

What security documents should a health-tech startup have ready for a hospital review?

A completed security questionnaire, a signed or ready-to-sign BAA, a SOC 2 report or a plan and timeline for one, a recent independent penetration test summary, core security policies, proof of workforce HIPAA training, and a data-flow description listing where PHI is stored and which subprocessors touch it.

Last reviewed 1 October 2026. Cost and timeline figures are typical industry ranges, not quotes. HITRUST assessment details and CSF versions change frequently, so check HITRUST’s current documentation before scoping. Nothing here is legal advice.


Share this article:

Build Compliant Healthcare Apps in Minutes

VertiComply generates production-ready code with HIPAA, GDPR, and SOC 2 compliance built in.

Related Articles

Continue reading about healthcare compliance and development

Compliance
12 min read
How to Build a HIPAA-Compliant Healthcare App Without Code in 2026

Which no-code platforms sign BAAs, ship audit logs, and pass HIPAA out-of-the-box. Real comparison of 7 builders, with PHI-handling gotchas flagged.

Read article

Compliance
14 min read
SOC 2 Type II for Healthcare SaaS: What the Audit Actually Tests

What a SOC 2 Type II audit actually tests in a healthcare SaaS, what it costs in 2026, how long the observation window really runs, and the six findings that fail healthcare teams most often.

Read article

Compliance
5 min read
How to Build a Compliant Healthcare App in 2026

The 7 phases to ship a HIPAA-compliant healthcare app in 2026: architecture, vendor BAAs, audit logs, encryption, breach response — with real timelines and costs.

Read article

© 2026 VertiComply. All rights reserved.