CompyMax

HIPAA to SOC 2 and NIST CSF 2.0 crosswalk

One enterprise client after you finish your HIPAA programme, somebody asks for a SOC 2 report. This is the answer to “how much of what we already built counts?” — all 68 Security Rule controls against the AICPA trust services criteria and NIST CSF 2.0, with the 8 SOC 2 criteria that HIPAA does not prepare you for named at the bottom rather than left out.

Last reviewed .

What this mapping is, and what it is not.

An orientation aid, not an auditor's mapping. It shows which criteria the evidence behind each HIPAA control tends to bear on — it does not mean satisfying the HIPAA control satisfies the criterion. SOC 2 tests how a control operated across a period, which the Security Rule does not ask about, and a service auditor scopes criteria against your own system description rather than a table.

HIPAA Security Rule controls mapped to SOC 2 criteria and NIST CSF 2.0 subcategories
HIPAA controlSOC 2 criteriaNIST CSF 2.0
Security management process164.308(a)(1)(i)CC5.1 Selection and development of control activitiesCC5.3 Deployment through policies and proceduresGV.PO-01 Cybersecurity policy is established and communicatedGV.RM-01 Risk management objectives are agreed
Risk analysis164.308(a)(1)(ii)(A)CC3.2 Identification and analysis of riskID.RA-01 Vulnerabilities in assets are identified and recordedID.RA-04 Potential impacts and likelihoods are identifiedID.RA-05 Threats, vulnerabilities and impacts inform risk prioritization
Risk management164.308(a)(1)(ii)(B)CC3.2 Identification and analysis of riskCC5.1 Selection and development of control activitiesID.RA-06 Risk responses are chosen, prioritized and trackedGV.RM-02 Risk appetite and tolerance are established
Sanction policy164.308(a)(1)(ii)(C)CC1.1 Commitment to integrity and ethical valuesCC1.5 Accountability for responsibilitiesGV.RR-04 Cybersecurity is included in human resources practices
Information system activity review164.308(a)(1)(ii)(D)CC4.1 Ongoing and separate evaluationsCC7.2 Monitoring for anomaliesDE.CM-09 Computing hardware and software are monitoredDE.AE-03 Information is correlated from multiple sources
Assigned security responsibility164.308(a)(2)CC1.3 Structures, reporting lines and authorityCC1.5 Accountability for responsibilitiesGV.RR-02 Roles and responsibilities are established and communicated
Workforce security164.308(a)(3)(i)CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of usersPR.AA-01 Identities and credentials are managedGV.RR-04 Cybersecurity is included in human resources practices
Authorization and/or supervision164.308(a)(3)(ii)(A)CC6.2 Registration and authorization of usersPR.AA-05 Access permissions enforce least privilege
Workforce clearance procedure164.308(a)(3)(ii)(B)CC1.4 Commitment to competenceGV.RR-04 Cybersecurity is included in human resources practices
Termination procedures164.308(a)(3)(ii)(C)CC6.3 Modification and removal of accessPR.AA-01 Identities and credentials are managedPR.AA-05 Access permissions enforce least privilege
Information access management164.308(a)(4)(i)CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of usersCC6.3 Modification and removal of accessPR.AA-05 Access permissions enforce least privilege
Isolating health care clearinghouse functions164.308(a)(4)(ii)(A)CC6.1 Logical access security software and infrastructurePR.IR-01 Networks and environments are protected from unauthorized access
Access authorization164.308(a)(4)(ii)(B)CC6.2 Registration and authorization of usersPR.AA-05 Access permissions enforce least privilege
Access establishment and modification164.308(a)(4)(ii)(C)CC6.3 Modification and removal of accessPR.AA-05 Access permissions enforce least privilege
Security awareness and training164.308(a)(5)(i)CC1.4 Commitment to competenceCC2.2 Internal communication of responsibilitiesPR.AT-01 Personnel are provided awareness and training
Security reminders164.308(a)(5)(ii)(A)CC2.2 Internal communication of responsibilitiesPR.AT-01 Personnel are provided awareness and training
Protection from malicious software164.308(a)(5)(ii)(B)CC6.8 Prevention and detection of unauthorized softwarePR.PS-05 Installation of unauthorized software is preventedDE.CM-09 Computing hardware and software are monitored
Log-in monitoring164.308(a)(5)(ii)(C)CC7.2 Monitoring for anomaliesDE.CM-03 Personnel activity and technology usage are monitored
Password management164.308(a)(5)(ii)(D)CC6.1 Logical access security software and infrastructurePR.AA-03 Users, services and hardware are authenticated
Security incident procedures164.308(a)(6)(i)CC7.3 Evaluation of security eventsCC7.4 Response to identified incidentsRS.MA-01 The incident response plan is executedGV.PO-01 Cybersecurity policy is established and communicated
Response and reporting164.308(a)(6)(ii)CC7.4 Response to identified incidentsCC7.5 Recovery from identified incidentsRS.MA-02 Incident reports are triaged and validatedRS.CO-02 Internal and external stakeholders are notified of incidents
Contingency plan164.308(a)(7)(i)CC9.1 Mitigation of business disruption riskA1.2 Backup, recovery and environmental protectionRC.RP-01 The recovery portion of the incident response plan is executed
Data backup plan164.308(a)(7)(ii)(A)A1.2 Backup, recovery and environmental protectionPR.DS-11 Backups of data are created, protected and tested
Disaster recovery plan164.308(a)(7)(ii)(B)A1.2 Backup, recovery and environmental protectionA1.3 Testing of recovery proceduresRC.RP-01 The recovery portion of the incident response plan is executed
Emergency mode operation plan164.308(a)(7)(ii)(C)A1.2 Backup, recovery and environmental protectionRC.RP-04 Critical mission functions are considered during recovery
Testing and revision procedures164.308(a)(7)(ii)(D)A1.3 Testing of recovery proceduresID.IM-02 Improvements are identified from tests and exercises
Applications and data criticality analysis164.308(a)(7)(ii)(E)A1.1 Capacity managementCC3.2 Identification and analysis of riskID.AM-05 Assets are prioritized by criticality and impact
Evaluation164.308(a)(8)CC4.1 Ongoing and separate evaluationsID.IM-01 Improvements are identified from evaluations
Business associate contracts and other arrangements164.308(b)(1)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contractsGV.SC-07 Risks posed by suppliers and their supply chains are monitored
Written contract or other arrangement164.308(b)(3)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contracts
Facility access controls164.310(a)(1)CC6.4 Physical access to facilitiesPR.AA-06 Physical access is managed and monitored
Contingency operations164.310(a)(2)(i)CC6.4 Physical access to facilitiesA1.2 Backup, recovery and environmental protectionRC.RP-01 The recovery portion of the incident response plan is executed
Facility security plan164.310(a)(2)(ii)CC6.4 Physical access to facilitiesPR.AA-06 Physical access is managed and monitored
Access control and validation procedures164.310(a)(2)(iii)CC6.4 Physical access to facilitiesPR.AA-06 Physical access is managed and monitored
Maintenance records164.310(a)(2)(iv)CC6.4 Physical access to facilitiesID.AM-08 Assets are managed through their life cycle
Workstation use164.310(b)CC6.1 Logical access security software and infrastructurePR.PS-01 Configuration management practices are established
Workstation security164.310(c)CC6.4 Physical access to facilitiesPR.AA-06 Physical access is managed and monitored
Device and media controls164.310(d)(1)CC6.5 Disposal of physical assets containing dataCC6.7 Restricted transmission, movement and removal of informationID.AM-08 Assets are managed through their life cycle
Disposal164.310(d)(2)(i)CC6.5 Disposal of physical assets containing dataC1.2 Disposal of confidential informationID.AM-08 Assets are managed through their life cycle
Media re-use164.310(d)(2)(ii)CC6.5 Disposal of physical assets containing dataC1.2 Disposal of confidential informationID.AM-08 Assets are managed through their life cycle
Accountability164.310(d)(2)(iii)CC6.7 Restricted transmission, movement and removal of informationID.AM-01 Inventories of hardware are maintained
Data backup and storage164.310(d)(2)(iv)A1.2 Backup, recovery and environmental protectionPR.DS-11 Backups of data are created, protected and tested
Access control164.312(a)(1)CC6.1 Logical access security software and infrastructurePR.AA-05 Access permissions enforce least privilege
Unique user identification164.312(a)(2)(i)CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of usersPR.AA-01 Identities and credentials are managed
Emergency access procedure164.312(a)(2)(ii)CC6.1 Logical access security software and infrastructureA1.2 Backup, recovery and environmental protectionPR.AA-05 Access permissions enforce least privilege
Automatic logoff164.312(a)(2)(iii)CC6.1 Logical access security software and infrastructurePR.AA-05 Access permissions enforce least privilege
Encryption and decryption164.312(a)(2)(iv)CC6.1 Logical access security software and infrastructureC1.1 Identification and protection of confidential informationPR.DS-01 Confidentiality, integrity and availability of data at rest
Audit controls164.312(b)CC7.2 Monitoring for anomaliesPR.PS-04 Log records are generated and made available for monitoringDE.AE-03 Information is correlated from multiple sources
Integrity164.312(c)(1)CC6.1 Logical access security software and infrastructureCC7.1 Detection of configuration changes and vulnerabilitiesPR.DS-01 Confidentiality, integrity and availability of data at rest
Mechanism to authenticate electronic protected health information164.312(c)(2)CC6.1 Logical access security software and infrastructurePR.DS-01 Confidentiality, integrity and availability of data at rest
Person or entity authentication164.312(d)CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of usersPR.AA-03 Users, services and hardware are authenticated
Transmission security164.312(e)(1)CC6.7 Restricted transmission, movement and removal of informationPR.DS-02 Confidentiality, integrity and availability of data in transit
Integrity controls164.312(e)(2)(i)CC6.7 Restricted transmission, movement and removal of informationPR.DS-02 Confidentiality, integrity and availability of data in transit
Encryption164.312(e)(2)(ii)CC6.7 Restricted transmission, movement and removal of informationC1.1 Identification and protection of confidential informationPR.DS-02 Confidentiality, integrity and availability of data in transit
Business associate contracts or other arrangements164.314(a)(1)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contracts
Business associate contracts164.314(a)(2)(i)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contracts
Other arrangements164.314(a)(2)(ii)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contracts
Business associate contracts with subcontractors164.314(a)(2)(iii)CC9.2 Management of vendor and business partner riskGV.SC-07 Risks posed by suppliers and their supply chains are monitored
Requirements for group health plans164.314(b)(1)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contracts
Plan sponsor implementation of safeguards164.314(b)(2)(i)CC9.2 Management of vendor and business partner riskGV.SC-05 Requirements are established for suppliers in contracts
Adequate separation supported by security measures164.314(b)(2)(ii)CC9.2 Management of vendor and business partner riskCC6.1 Logical access security software and infrastructurePR.AA-05 Access permissions enforce least privilege
Agents to implement security measures164.314(b)(2)(iii)CC9.2 Management of vendor and business partner riskGV.SC-07 Risks posed by suppliers and their supply chains are monitored
Reporting of security incidents to the group health plan164.314(b)(2)(iv)CC7.4 Response to identified incidentsCC9.2 Management of vendor and business partner riskRS.CO-02 Internal and external stakeholders are notified of incidents
Policies and procedures164.316(a)CC5.3 Deployment through policies and proceduresGV.PO-01 Cybersecurity policy is established and communicated
Documentation164.316(b)(1)CC2.1 Relevant quality informationCC5.3 Deployment through policies and proceduresGV.PO-01 Cybersecurity policy is established and communicated
Time limit164.316(b)(2)(i)CC5.3 Deployment through policies and proceduresGV.PO-02 Policy is reviewed, updated and communicated
Availability164.316(b)(2)(ii)CC2.2 Internal communication of responsibilitiesGV.PO-01 Cybersecurity policy is established and communicated
Updates164.316(b)(2)(iii)CC4.2 Communication of deficienciesCC5.3 Deployment through policies and proceduresGV.PO-02 Policy is reviewed, updated and communicated

What HIPAA does not prepare you for

These are the SOC 2 criteria with no meaningful counterpart in the Security Rule. They are mostly governance and change management rather than security technology, which is why they surprise people: an organization with genuinely good security controls can still be a long way from a SOC 2 report.

CC1.2
Board or governing body oversight of internal control. HIPAA names a security official but says nothing about who oversees them.
CC2.3
Communication with external parties about the system and its controls. HIPAA's external communication duties are about breach notification, not about describing your controls.
CC3.1
Specifying objectives clearly enough to identify risks to them. HIPAA fixes the objective for you, so nobody has had to write one down.
CC3.3
Consideration of the potential for fraud. Outside the Security Rule entirely.
CC3.4
Identifying and assessing changes that could affect internal control.
CC5.2
General control activities over technology. HIPAA implies these; SOC 2 tests them as a distinct set.
CC7.1
Detecting configuration changes and scanning for vulnerabilities. HIPAA requires periodic evaluation but not continuous detection.
CC8.1
Change management — authorizing, designing, testing and approving changes. The single most common gap for an organization coming from HIPAA, and the one that takes longest to build.

See this filled in with your own answers.

Inside the product the same crosswalk reads from your live assessment, so each criterion shows how many of the HIPAA controls behind it you have actually evidenced — and what is still open. 14 days free, no credit card.

Common questions

Does HIPAA compliance count toward SOC 2?
The evidence overlaps substantially; the assessments do not. Your risk analysis, access control records, training records, vendor agreements and incident procedures all produce artifacts a service auditor will want to see. What HIPAA does not give you is proof of how each control operated across a period, which is the whole basis of a SOC 2 Type II opinion — and it says nothing about change management, board oversight or fraud consideration, which SOC 2 tests directly.
What is the biggest gap between HIPAA and SOC 2?
Change management. SOC 2's CC8.1 asks how changes to infrastructure, data and software are authorized, designed, tested, approved and implemented, and the Security Rule has no real counterpart — so it is almost never in place at an organization arriving from HIPAA, and it is the slowest of the gaps to build because it is a working practice rather than a document.
Is NIST CSF the same as the HIPAA Security Rule?
No, but they are close relatives. HHS itself has published crosswalk material between the Security Rule and the NIST framework, and the proposed Security Rule overhaul leans further toward NIST-style specificity. CSF 2.0 is broader — it adds a Govern function covering roles, policy and supply chain that HIPAA touches only lightly — and it is voluntary guidance rather than a regulation.
Can I use this mapping in an audit?
Not as evidence, no. It is an orientation aid for working out what you already have. A service auditor scopes criteria against your own system description and the commitments you make to your customers, not against a published table — and no mapping can tell them whether your control operated effectively. Use it to plan; expect your auditor to derive their own.

A planning aid based on the AICPA 2017 trust services criteria and NIST CSF 2.0, offered as general information rather than legal advice. Mapping a HIPAA control to a criterion does not mean satisfying one satisfies the other, and no published table substitutes for the scoping your own service auditor will do.