CROSSWALK MAPPINGVerified Data

Mapping SOC 2 to HIPAA Security Rule

A practitioner-grade, domain-level crosswalk between SOC 2 and HIPAA Security Rule. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

Defensible domain-level alignment based on shared technical-control concepts (logical access, monitoring, physical security). No single official crosswalk between AICPA's Trust Services Criteria and the HIPAA Security Rule is published, so treat this as directional guidance. Scope note: this pairing is against the HIPAA Security Rule only — the separate HIPAA Privacy Rule is out of scope for both the `hipaa` framework entry and this crosswalk.

Overall Confidence:moderate
Last Verified:2026-08-07

Domain Correspondences

SOC 2
CC1–CC9: Common Criteria (Security)
HIPAA Security Rule
§164.312: Technical Safeguards

Logical access and system-operations monitoring in the Common Criteria correspond to HIPAA's Technical Safeguards.

SOC 2
CC1–CC9: Common Criteria (Security)
HIPAA Security Rule
§164.308: Administrative Safeguards

Control-environment, risk-assessment, and training components of the Common Criteria correspond to HIPAA's Administrative Safeguards.

SOC 2
CC1–CC9: Common Criteria (Security)
HIPAA Security Rule
§164.310: Physical Safeguards

The physical-access portion of the Common Criteria (CC6) corresponds to HIPAA's Physical Safeguards.

SOC 2
C1: Confidentiality
HIPAA Security Rule
§164.312: Technical Safeguards

SOC 2's Confidentiality criterion and HIPAA's Technical Safeguards both center on protecting sensitive data through access control and encryption.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between SOC 2, HIPAA Security Rule, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix