CROSSWALK MAPPINGVerified Data

Mapping HIPAA Security Rule to SOC 2

A practitioner-grade, domain-level crosswalk between HIPAA Security Rule and SOC 2. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

Defensible domain-level alignment based on shared technical-control concepts (logical access, monitoring, physical security). No single official crosswalk between AICPA's Trust Services Criteria and the HIPAA Security Rule is published, so treat this as directional guidance. Scope note: this pairing is against the HIPAA Security Rule only — the separate HIPAA Privacy Rule is out of scope for both the `hipaa` framework entry and this crosswalk.

Overall Confidence:moderate
Last Verified:2026-08-07

Domain Correspondences

HIPAA Security Rule
§164.312: Technical Safeguards
SOC 2
CC1–CC9: Common Criteria (Security)

Logical access and system-operations monitoring in the Common Criteria correspond to HIPAA's Technical Safeguards.

HIPAA Security Rule
§164.308: Administrative Safeguards
SOC 2
CC1–CC9: Common Criteria (Security)

Control-environment, risk-assessment, and training components of the Common Criteria correspond to HIPAA's Administrative Safeguards.

HIPAA Security Rule
§164.310: Physical Safeguards
SOC 2
CC1–CC9: Common Criteria (Security)

The physical-access portion of the Common Criteria (CC6) corresponds to HIPAA's Physical Safeguards.

HIPAA Security Rule
§164.312: Technical Safeguards
SOC 2
C1: Confidentiality

SOC 2's Confidentiality criterion and HIPAA's Technical Safeguards both center on protecting sensitive data through access control and encryption.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between HIPAA Security Rule, SOC 2, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix