SOC 2 for healthcare SaaS, PHI-aware.
Healthcare buyers scrutinize PHI handling, BAAs, and privacy controls beyond what a standard Security-only report covers. Skadi scopes SOC 2 Type II with Confidentiality — and Privacy where warranted — to satisfy hospital and payer procurement, with a control library mapped directly to the HIPAA Security Rule so you maintain one program, not two.
Audit challenges we solve for you.
Health systems and payers want proof PHI is protected in transit, at rest, in analytics warehouses, and in backups — with access reviews and encryption evidence to match.
Every vendor with PHI access needs a BAA executed before onboarding. Missing, lapsed, or verbally-agreed BAAs are among the most common findings in healthcare transitions.
Teams end up running parallel programs and answering the same questions twice. We map SOC 2 controls to HIPAA Security Rule §164.308/310/312 so one evidence set serves both.
Breach notification timelines under HIPAA are unforgiving. Your playbook, tabletop evidence, and post-incident records must stand up to OCR-style scrutiny — not just internal review.
Controls that matter most for your business.
Role-based access to PHI, break-glass with justification, quarterly reviews signed by owners, and evidence access is scoped to job function — not team-wide by default.
TLS 1.2+ in transit, AES-256 at rest across databases, warehouses, backups, and object storage — with KMS-managed keys, rotation evidence, and separated custodianship.
Immutable logs of who accessed which PHI record and when, retention aligned to HIPAA (6 years) and customer contracts, and evidence logs are periodically reviewed.
Live BAA inventory with expiry tracking, security review before onboarding, and monitoring evidence for every sub-processor with PHI access. Re-execution before term expiry.
Playbook that meets HIPAA breach notification timelines (60-day outer bound; state laws often shorter), tabletop evidence, and postmortem records with root-cause and remediation.
Documented retention schedules by data type, evidence of secure disposal (including in backups and analytics stores), and controls that PHI is deleted when contracts end or windows expire.
Onboarding and annual HIPAA training completed by 100% of workforce with access to PHI, with completion evidence maintained across the observation window.
Backup, disaster recovery, and emergency mode operation plans — with a tested restoration during the window (the control most often missed).
What actually fails in this vertical.
Real deviations we see in SOC 2 Type II fieldwork — and what your platform and security teams should fix before the observation window starts.
New vendor onboarded, PHI flows to them, BAA still 'in legal review.' The gap is both a HIPAA violation and a SOC 2 vendor-management exception.
- BAA register with executed date per PHI vendor
- Vendor-onboarding ticket blocked until BAA is signed
- Data-flow diagram showing every path PHI takes
- Latest HIPAA / HITRUST attestation from each PHI vendor
Prod snapshots restored to staging for debugging. De-identify (Safe Harbor or Expert Determination) before any lower environment sees the data — no exceptions.
- De-identification runbook + tool config (Safe Harbor rules)
- Sample de-identified dataset with reviewer sign-off
- Policy prohibiting raw PHI outside production
- Access-log evidence of non-prod environments
§164.312(b) requires review of activity, not just capture. Weekly or monthly review with signed evidence — otherwise the control exists but does not operate.
- Log-review runbook and cadence policy
- Signed review reports for the window
- SIEM dashboard export showing anomalies triaged
- Ticket log for follow-ups from reviews
Enterprise health customers now expect BYOK or CMK. Absent that, KMS key rotation must be scheduled and evidenced during the window.
- KMS key policy with rotation cadence enabled
- CloudTrail / KMS rotation events for the window
- BYOK/CMK design doc if offered
- Encryption standard policy with algorithm + rotation rules
Broad AD/Okta groups indirectly grant PHI access. Explicit, minimum-necessary access reviewed with the group owner every quarter.
- PHI role definition doc with minimum-necessary rationale
- Group membership export with reviewer sign-off
- Quarterly access-review report
- Ticket for revocations post-review
60-day notification obligation documented but never rehearsed. Tabletop the workflow with legal and comms and retain the outcome.
- Breach-notification policy referencing 60-day rule
- Tabletop exercise report with participants + dated
- Communication templates for OCR, patients, media
- Incident-response ticket template with notification checklist
SOC 2 as a HIPAA proxy for procurement
HIPAA has no formal certification. Buyers evaluating healthtech vendors have historically had to trust a self-attestation, which is why SOC 2 Type II with strong Confidentiality (and Privacy where applicable) has become the practical shorthand for HIPAA-ready. It gives hospital CISOs and payer risk teams an independent, attested evidence package instead of a claim on a slide.
Mapping controls once, satisfying both frameworks
About 70% of HIPAA Security Rule safeguards overlap with SOC 2 Trust Services Criteria: access control, audit controls, integrity, transmission security, contingency planning. We produce a formal mapping so your team maintains one control library and one evidence set — not two parallel programs with duplicated work and duplicated evidence requests.
The BAA program that actually holds up
A BAA on file is only the beginning. Auditors and OCR both look for a program: an inventory that reflects reality, security review completed before PHI access is granted, notification obligations flowed down, and re-execution before expiry. We build the program on top of your existing procurement flow so it is not an owned-by-no-one spreadsheet.
When you also need HITRUST
Some large payers and academic medical centers still require HITRUST specifically. It is a heavier framework and 3–5x the cost of SOC 2. We are honest about when HITRUST is genuinely required (usually large payer or federal contracts) and when SOC 2 with Privacy will actually satisfy the buyer — most of the time it will.
Questions we hear from teams like yours.
Ready to scope your SOC 2 Type II?
Book a call and we'll walk you through timeline, scope, and pricing for your company.