HIPAA to SOC 2 and NIST CSF 2.0 crosswalk
One enterprise client after you finish your HIPAA programme, somebody asks for a SOC 2 report. This is the answer to “how much of what we already built counts?” — all 68 Security Rule controls against the AICPA trust services criteria and NIST CSF 2.0, with the 8 SOC 2 criteria that HIPAA does not prepare you for named at the bottom rather than left out.
Last reviewed .
What this mapping is, and what it is not.
An orientation aid, not an auditor's mapping. It shows which criteria the evidence behind each HIPAA control tends to bear on — it does not mean satisfying the HIPAA control satisfies the criterion. SOC 2 tests how a control operated across a period, which the Security Rule does not ask about, and a service auditor scopes criteria against your own system description rather than a table.
| HIPAA control | SOC 2 criteria | NIST CSF 2.0 |
|---|---|---|
| Security management process164.308(a)(1)(i) | CC5.1 Selection and development of control activitiesCC5.3 Deployment through policies and procedures | GV.PO-01 Cybersecurity policy is established and communicatedGV.RM-01 Risk management objectives are agreed |
| Risk analysis164.308(a)(1)(ii)(A) | CC3.2 Identification and analysis of risk | ID.RA-01 Vulnerabilities in assets are identified and recordedID.RA-04 Potential impacts and likelihoods are identifiedID.RA-05 Threats, vulnerabilities and impacts inform risk prioritization |
| Risk management164.308(a)(1)(ii)(B) | CC3.2 Identification and analysis of riskCC5.1 Selection and development of control activities | ID.RA-06 Risk responses are chosen, prioritized and trackedGV.RM-02 Risk appetite and tolerance are established |
| Sanction policy164.308(a)(1)(ii)(C) | CC1.1 Commitment to integrity and ethical valuesCC1.5 Accountability for responsibilities | GV.RR-04 Cybersecurity is included in human resources practices |
| Information system activity review164.308(a)(1)(ii)(D) | CC4.1 Ongoing and separate evaluationsCC7.2 Monitoring for anomalies | DE.CM-09 Computing hardware and software are monitoredDE.AE-03 Information is correlated from multiple sources |
| Assigned security responsibility164.308(a)(2) | CC1.3 Structures, reporting lines and authorityCC1.5 Accountability for responsibilities | GV.RR-02 Roles and responsibilities are established and communicated |
| Workforce security164.308(a)(3)(i) | CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of users | PR.AA-01 Identities and credentials are managedGV.RR-04 Cybersecurity is included in human resources practices |
| Authorization and/or supervision164.308(a)(3)(ii)(A) | CC6.2 Registration and authorization of users | PR.AA-05 Access permissions enforce least privilege |
| Workforce clearance procedure164.308(a)(3)(ii)(B) | CC1.4 Commitment to competence | GV.RR-04 Cybersecurity is included in human resources practices |
| Termination procedures164.308(a)(3)(ii)(C) | CC6.3 Modification and removal of access | PR.AA-01 Identities and credentials are managedPR.AA-05 Access permissions enforce least privilege |
| Information access management164.308(a)(4)(i) | CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of usersCC6.3 Modification and removal of access | PR.AA-05 Access permissions enforce least privilege |
| Isolating health care clearinghouse functions164.308(a)(4)(ii)(A) | CC6.1 Logical access security software and infrastructure | PR.IR-01 Networks and environments are protected from unauthorized access |
| Access authorization164.308(a)(4)(ii)(B) | CC6.2 Registration and authorization of users | PR.AA-05 Access permissions enforce least privilege |
| Access establishment and modification164.308(a)(4)(ii)(C) | CC6.3 Modification and removal of access | PR.AA-05 Access permissions enforce least privilege |
| Security awareness and training164.308(a)(5)(i) | CC1.4 Commitment to competenceCC2.2 Internal communication of responsibilities | PR.AT-01 Personnel are provided awareness and training |
| Security reminders164.308(a)(5)(ii)(A) | CC2.2 Internal communication of responsibilities | PR.AT-01 Personnel are provided awareness and training |
| Protection from malicious software164.308(a)(5)(ii)(B) | CC6.8 Prevention and detection of unauthorized software | PR.PS-05 Installation of unauthorized software is preventedDE.CM-09 Computing hardware and software are monitored |
| Log-in monitoring164.308(a)(5)(ii)(C) | CC7.2 Monitoring for anomalies | DE.CM-03 Personnel activity and technology usage are monitored |
| Password management164.308(a)(5)(ii)(D) | CC6.1 Logical access security software and infrastructure | PR.AA-03 Users, services and hardware are authenticated |
| Security incident procedures164.308(a)(6)(i) | CC7.3 Evaluation of security eventsCC7.4 Response to identified incidents | RS.MA-01 The incident response plan is executedGV.PO-01 Cybersecurity policy is established and communicated |
| Response and reporting164.308(a)(6)(ii) | CC7.4 Response to identified incidentsCC7.5 Recovery from identified incidents | RS.MA-02 Incident reports are triaged and validatedRS.CO-02 Internal and external stakeholders are notified of incidents |
| Contingency plan164.308(a)(7)(i) | CC9.1 Mitigation of business disruption riskA1.2 Backup, recovery and environmental protection | RC.RP-01 The recovery portion of the incident response plan is executed |
| Data backup plan164.308(a)(7)(ii)(A) | A1.2 Backup, recovery and environmental protection | PR.DS-11 Backups of data are created, protected and tested |
| Disaster recovery plan164.308(a)(7)(ii)(B) | A1.2 Backup, recovery and environmental protectionA1.3 Testing of recovery procedures | RC.RP-01 The recovery portion of the incident response plan is executed |
| Emergency mode operation plan164.308(a)(7)(ii)(C) | A1.2 Backup, recovery and environmental protection | RC.RP-04 Critical mission functions are considered during recovery |
| Testing and revision procedures164.308(a)(7)(ii)(D) | A1.3 Testing of recovery procedures | ID.IM-02 Improvements are identified from tests and exercises |
| Applications and data criticality analysis164.308(a)(7)(ii)(E) | A1.1 Capacity managementCC3.2 Identification and analysis of risk | ID.AM-05 Assets are prioritized by criticality and impact |
| Evaluation164.308(a)(8) | CC4.1 Ongoing and separate evaluations | ID.IM-01 Improvements are identified from evaluations |
| Business associate contracts and other arrangements164.308(b)(1) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contractsGV.SC-07 Risks posed by suppliers and their supply chains are monitored |
| Written contract or other arrangement164.308(b)(3) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contracts |
| Facility access controls164.310(a)(1) | CC6.4 Physical access to facilities | PR.AA-06 Physical access is managed and monitored |
| Contingency operations164.310(a)(2)(i) | CC6.4 Physical access to facilitiesA1.2 Backup, recovery and environmental protection | RC.RP-01 The recovery portion of the incident response plan is executed |
| Facility security plan164.310(a)(2)(ii) | CC6.4 Physical access to facilities | PR.AA-06 Physical access is managed and monitored |
| Access control and validation procedures164.310(a)(2)(iii) | CC6.4 Physical access to facilities | PR.AA-06 Physical access is managed and monitored |
| Maintenance records164.310(a)(2)(iv) | CC6.4 Physical access to facilities | ID.AM-08 Assets are managed through their life cycle |
| Workstation use164.310(b) | CC6.1 Logical access security software and infrastructure | PR.PS-01 Configuration management practices are established |
| Workstation security164.310(c) | CC6.4 Physical access to facilities | PR.AA-06 Physical access is managed and monitored |
| Device and media controls164.310(d)(1) | CC6.5 Disposal of physical assets containing dataCC6.7 Restricted transmission, movement and removal of information | ID.AM-08 Assets are managed through their life cycle |
| Disposal164.310(d)(2)(i) | CC6.5 Disposal of physical assets containing dataC1.2 Disposal of confidential information | ID.AM-08 Assets are managed through their life cycle |
| Media re-use164.310(d)(2)(ii) | CC6.5 Disposal of physical assets containing dataC1.2 Disposal of confidential information | ID.AM-08 Assets are managed through their life cycle |
| Accountability164.310(d)(2)(iii) | CC6.7 Restricted transmission, movement and removal of information | ID.AM-01 Inventories of hardware are maintained |
| Data backup and storage164.310(d)(2)(iv) | A1.2 Backup, recovery and environmental protection | PR.DS-11 Backups of data are created, protected and tested |
| Access control164.312(a)(1) | CC6.1 Logical access security software and infrastructure | PR.AA-05 Access permissions enforce least privilege |
| Unique user identification164.312(a)(2)(i) | CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of users | PR.AA-01 Identities and credentials are managed |
| Emergency access procedure164.312(a)(2)(ii) | CC6.1 Logical access security software and infrastructureA1.2 Backup, recovery and environmental protection | PR.AA-05 Access permissions enforce least privilege |
| Automatic logoff164.312(a)(2)(iii) | CC6.1 Logical access security software and infrastructure | PR.AA-05 Access permissions enforce least privilege |
| Encryption and decryption164.312(a)(2)(iv) | CC6.1 Logical access security software and infrastructureC1.1 Identification and protection of confidential information | PR.DS-01 Confidentiality, integrity and availability of data at rest |
| Audit controls164.312(b) | CC7.2 Monitoring for anomalies | PR.PS-04 Log records are generated and made available for monitoringDE.AE-03 Information is correlated from multiple sources |
| Integrity164.312(c)(1) | CC6.1 Logical access security software and infrastructureCC7.1 Detection of configuration changes and vulnerabilities | PR.DS-01 Confidentiality, integrity and availability of data at rest |
| Mechanism to authenticate electronic protected health information164.312(c)(2) | CC6.1 Logical access security software and infrastructure | PR.DS-01 Confidentiality, integrity and availability of data at rest |
| Person or entity authentication164.312(d) | CC6.1 Logical access security software and infrastructureCC6.2 Registration and authorization of users | PR.AA-03 Users, services and hardware are authenticated |
| Transmission security164.312(e)(1) | CC6.7 Restricted transmission, movement and removal of information | PR.DS-02 Confidentiality, integrity and availability of data in transit |
| Integrity controls164.312(e)(2)(i) | CC6.7 Restricted transmission, movement and removal of information | PR.DS-02 Confidentiality, integrity and availability of data in transit |
| Encryption164.312(e)(2)(ii) | CC6.7 Restricted transmission, movement and removal of informationC1.1 Identification and protection of confidential information | PR.DS-02 Confidentiality, integrity and availability of data in transit |
| Business associate contracts or other arrangements164.314(a)(1) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contracts |
| Business associate contracts164.314(a)(2)(i) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contracts |
| Other arrangements164.314(a)(2)(ii) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contracts |
| Business associate contracts with subcontractors164.314(a)(2)(iii) | CC9.2 Management of vendor and business partner risk | GV.SC-07 Risks posed by suppliers and their supply chains are monitored |
| Requirements for group health plans164.314(b)(1) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contracts |
| Plan sponsor implementation of safeguards164.314(b)(2)(i) | CC9.2 Management of vendor and business partner risk | GV.SC-05 Requirements are established for suppliers in contracts |
| Adequate separation supported by security measures164.314(b)(2)(ii) | CC9.2 Management of vendor and business partner riskCC6.1 Logical access security software and infrastructure | PR.AA-05 Access permissions enforce least privilege |
| Agents to implement security measures164.314(b)(2)(iii) | CC9.2 Management of vendor and business partner risk | GV.SC-07 Risks posed by suppliers and their supply chains are monitored |
| Reporting of security incidents to the group health plan164.314(b)(2)(iv) | CC7.4 Response to identified incidentsCC9.2 Management of vendor and business partner risk | RS.CO-02 Internal and external stakeholders are notified of incidents |
| Policies and procedures164.316(a) | CC5.3 Deployment through policies and procedures | GV.PO-01 Cybersecurity policy is established and communicated |
| Documentation164.316(b)(1) | CC2.1 Relevant quality informationCC5.3 Deployment through policies and procedures | GV.PO-01 Cybersecurity policy is established and communicated |
| Time limit164.316(b)(2)(i) | CC5.3 Deployment through policies and procedures | GV.PO-02 Policy is reviewed, updated and communicated |
| Availability164.316(b)(2)(ii) | CC2.2 Internal communication of responsibilities | GV.PO-01 Cybersecurity policy is established and communicated |
| Updates164.316(b)(2)(iii) | CC4.2 Communication of deficienciesCC5.3 Deployment through policies and procedures | GV.PO-02 Policy is reviewed, updated and communicated |
What HIPAA does not prepare you for
These are the SOC 2 criteria with no meaningful counterpart in the Security Rule. They are mostly governance and change management rather than security technology, which is why they surprise people: an organization with genuinely good security controls can still be a long way from a SOC 2 report.
- CC1.2
- Board or governing body oversight of internal control. HIPAA names a security official but says nothing about who oversees them.
- CC2.3
- Communication with external parties about the system and its controls. HIPAA's external communication duties are about breach notification, not about describing your controls.
- CC3.1
- Specifying objectives clearly enough to identify risks to them. HIPAA fixes the objective for you, so nobody has had to write one down.
- CC3.3
- Consideration of the potential for fraud. Outside the Security Rule entirely.
- CC3.4
- Identifying and assessing changes that could affect internal control.
- CC5.2
- General control activities over technology. HIPAA implies these; SOC 2 tests them as a distinct set.
- CC7.1
- Detecting configuration changes and scanning for vulnerabilities. HIPAA requires periodic evaluation but not continuous detection.
- CC8.1
- Change management — authorizing, designing, testing and approving changes. The single most common gap for an organization coming from HIPAA, and the one that takes longest to build.
See this filled in with your own answers.
Inside the product the same crosswalk reads from your live assessment, so each criterion shows how many of the HIPAA controls behind it you have actually evidenced — and what is still open. 14 days free, no credit card.
Common questions
- Does HIPAA compliance count toward SOC 2?
- The evidence overlaps substantially; the assessments do not. Your risk analysis, access control records, training records, vendor agreements and incident procedures all produce artifacts a service auditor will want to see. What HIPAA does not give you is proof of how each control operated across a period, which is the whole basis of a SOC 2 Type II opinion — and it says nothing about change management, board oversight or fraud consideration, which SOC 2 tests directly.
- What is the biggest gap between HIPAA and SOC 2?
- Change management. SOC 2's CC8.1 asks how changes to infrastructure, data and software are authorized, designed, tested, approved and implemented, and the Security Rule has no real counterpart — so it is almost never in place at an organization arriving from HIPAA, and it is the slowest of the gaps to build because it is a working practice rather than a document.
- Is NIST CSF the same as the HIPAA Security Rule?
- No, but they are close relatives. HHS itself has published crosswalk material between the Security Rule and the NIST framework, and the proposed Security Rule overhaul leans further toward NIST-style specificity. CSF 2.0 is broader — it adds a Govern function covering roles, policy and supply chain that HIPAA touches only lightly — and it is voluntary guidance rather than a regulation.
- Can I use this mapping in an audit?
- Not as evidence, no. It is an orientation aid for working out what you already have. A service auditor scopes criteria against your own system description and the commitments you make to your customers, not against a published table — and no mapping can tell them whether your control operated effectively. Use it to plan; expect your auditor to derive their own.
Keep reading
- Vendor compliance checkerVerdicts on the tools small healthcare organizations actually run.
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA compliance checklistEvery requirement, in order, with the evidence that proves it.
- Free HIPAA readiness scoreTwelve questions, each citing its regulation, scored in your browser.
- HIPAA training requirementsWho must be trained, how often, and what proof to keep.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- How we researchSourcing, review cadence and corrections policy.
- About the teamThe compliance officers, clinicians and security people behind the research.
Looking for the software rather than the explanation? Vanta alternative.
A planning aid based on the AICPA 2017 trust services criteria and NIST CSF 2.0, offered as general information rather than legal advice. Mapping a HIPAA control to a criterion does not mean satisfying one satisfies the other, and no published table substitutes for the scoping your own service auditor will do.