A practitioner-grade, domain-level crosswalk between SOC 2 and HIPAA Security Rule. Understand how these compliance standards overlap to streamline your audit programs.
Defensible domain-level alignment based on shared technical-control concepts (logical access, monitoring, physical security). No single official crosswalk between AICPA's Trust Services Criteria and the HIPAA Security Rule is published, so treat this as directional guidance. Scope note: this pairing is against the HIPAA Security Rule only — the separate HIPAA Privacy Rule is out of scope for both the `hipaa` framework entry and this crosswalk.
Logical access and system-operations monitoring in the Common Criteria correspond to HIPAA's Technical Safeguards.
Control-environment, risk-assessment, and training components of the Common Criteria correspond to HIPAA's Administrative Safeguards.
The physical-access portion of the Common Criteria (CC6) corresponds to HIPAA's Physical Safeguards.
SOC 2's Confidentiality criterion and HIPAA's Technical Safeguards both center on protecting sensitive data through access control and encryption.
Use our interactive crosswalk matrix to explore mappings between SOC 2, HIPAA Security Rule, and 10 other compliance frameworks simultaneously.
Open Interactive Matrix