HITRUST,SOC 2

SOC 2, HITRUST Certification, and SOC 2 + HITRUST

Choosing the Right Assurance Strategy

For healthcare technology companies, SaaS providers, and business associates, the right assurance strategy starts with the deliverable customers require and the risks the organization needs to address.

SOC 2, HITRUST Certification, and SOC 2 + HITRUST serve different assurance needs. Some organizations need both a SOC 2 report and separate HITRUST certification. A common control environment can support these outcomes while reducing duplicated work.

Key Takeaways

  • SOC 2 evaluates controls against the applicable AICPA Trust Services Criteria and results in a CPA attestation report.
  • HITRUST e1, i1, and r2 offer distinct assessment and certification options with different assurance depth and methodologies.
  • SOC 2 + HITRUST remains an available reporting model for appropriately licensed CPA firms. It incorporates defined HITRUST CSF criteria into SOC 2 reporting; it does not confer HITRUST Certification.

What Is HITRUST Certification?

HITRUST issues certification after an applicable validated assessment and its review and certification process. Certification applies to the assessed scope and depends on meeting the relevant requirements.

The HITRUST CSF harmonizes security, regulatory, and industry sources into a common framework. Its mappings help organize overlapping obligations; assessment type and applicable factors determine the requirements evaluated. A mapping alone does not establish compliance with every source.

Understanding HITRUST e1, i1, and r2

  • e1 Essentials: A focused assessment of foundational cybersecurity practices for baseline assurance needs.
  • i1 Implemented: A broader, threat-adaptive assessment emphasizing implemented controls and a standardized core requirement set.
  • r2 Risk-Based: The most comprehensive of these options, with requirements tailored to applicable risk factors and a broader evaluation of control maturity.

All three assessment types use HITRUST’s maturity scoring approach. e1 and i1 focus on the implemented maturity level; r2 evaluates additional dimensions. Choose according to risk, scope, and the recipient’s accepted assessment type, rather than treating the options as different sizes of the same audit. 

What Is SOC 2?

SOC 2 is a CPA examination of a service organization’s system and controls against applicable AICPA Trust Services Criteria. Security is included; Availability, Processing Integrity, Confidentiality, and Privacy are included as relevant to the engagement’s scope and objectives.

A Type I report addresses control design at a specified date. A Type II report also addresses operating effectiveness over a defined period. Confirm which outcome the customer requires.

What Is SOC 2 + HITRUST?

SOC 2 + HITRUST is an existing reporting model that may be issued by CPA firms licensed to use the HITRUST CSF. It incorporates defined HITRUST CSF requirements as additional criteria alongside the applicable AICPA Trust Services Criteria in a SOC 2 engagement.

The issuing CPA firm should determine the suitable criteria, scope, and reporting approach under applicable AICPA guidance. The report should identify the HITRUST CSF criteria covered. 

This report does not confer HITRUST e1, i1, or r2 certification. Organizations requiring certification must complete the applicable HITRUST Assurance Program process.

Comparing the Assurance Outcomes

Compare the criteria, process, and deliverables within the proposed scope. TSC means Trust Services Criteria

Attribute SOC 2 HITRUST Certification SOC 2 + HITRUST
Criteria Applicable AICPA Trust Services Criteria HITRUST CSF requirements for the selected assessment Applicable TSC plus defined HITRUST CSF criteria
Assurance process CPA attestation examination HITRUST Assurance Program validated assessment and review CPA attestation examination
Who performs the work CPA firm Authorized External Assessor validates; HITRUST reviews CPA firm appropriately licensed to use the CSF
Final deliverable and issuer SOC 2 report issued by a CPA firm Certification issued by HITRUST if requirements are met SOC 2 + HITRUST report issued by a CSF-licensed CPA firm
Engagement structure Type I or Type II e1, i1, or r2; not SOC report types SOC examination with additional HITRUST CSF criteria; reporting follows AICPA guidance
Control evaluation Design; Type II also tests operating effectiveness e1/i1 emphasize implementation; r2 adds maturity depth SOC examination addressing the specified additional criteria
HITRUST certification No Yes, on successful completion and HITRUST approval No
Typical objective Meet customer SOC 2 reporting needs Meet a specified HITRUST certification requirement Meet customer SOC 2 needs with agreed HITRUST CSF coverage

Which Should Your Organization Choose?

  • Start with the required deliverable. If a customer requires HITRUST Certification, confirm the accepted assessment type and scope and pursue that certification.
  • If a customer requires SOC 2, confirm the system scope, Trust Services Categories, report type, and reporting period. Use SOC 2 + HITRUST when additional CSF coverage serves an agreed need, and the customer accepts that report.
  • If customers require both SOC 2 and HITRUST Certification, plan for both outcomes and coordinate controls and evidence. A combined SOC report does not replace the separate certification.
  • If the request is unclear, resolve it with the recipient before buying an assessment. Then compare readiness, effort, timing, and ongoing maintenance against the agreed objective.

Licensing and Reporting Requirements

HITRUST’s clarification to Accorian distinguishes the assessed entity’s license, commercial CSF use, and the CPA firm’s reporting responsibilities.

The assessed entity

The assessed entity must hold a HITRUST CSF license when the CSF is incorporated into a SOC 2 engagement. It can obtain that license by downloading the CSF from HITRUST’s website or through MyCSF. A full MyCSF subscription is not required solely for SOC 2 + HITRUST. Applicable license terms still govern use.

The CPA firm and External Assessor

Commercial users of the HITRUST CSF need appropriate licensing. Authorized External Assessor status satisfies this requirement for External Assessors, and Accorian holds that status. The CPA firm issuing a SOC 2 + HITRUST report must also be appropriately licensed to use the CSF.

In her clarification, HITRUST’s Kayla Christian stated that she was not aware of additional HITRUST-specific affiliation requirements between an Authorized External Assessor organization and an affiliated CPA attest entity beyond appropriate licensing. This does not establish automatic license coverage for an affiliate; confirm the licensing applicable to each participating entity.

Report structure and professional guidance

According to that clarification, HITRUST does not prescribe SOC 2 + HITRUST report templates, opinion language, implementation guidance, or reporting structure. CPA firms should use applicable AICPA guidance and meet their professional and independence obligations. 

Where HIPAA Fits?

HIPAA obligations and customer assurance requirements are separate considerations. HIPAA itself does not mandate HITRUST Certification. A healthcare customer, payer, provider, or business partner may nevertheless require it contractually, including a particular assessment type and scope.

Neither SOC 2 nor HITRUST Certification replaces an organization’s responsibility to meet applicable HIPAA requirements. HITRUST’s mappings can support a compliance program, but they do not turn a certification into a blanket determination of HIPAA compliance. HHS does not recognize private Security Rule certifications as relieving an organization of its legal obligations. 

When Should You Choose HITRUST Certification?

Pursue HITRUST Certification when a customer requires it or its assurance model fits your risk and market needs. Healthcare relationships and sensitive data can make it valuable, but do not automatically determine the assessment type.

Confirm the accepted e1, i1, or r2 assessment, required system scope, and deadline. r2 offers deeper, risk-based assurance where warranted; e1 or i1 may meet other needs.

When Does SOC 2 + HITRUST Make Sense?

Consider SOC 2 + HITRUST when a customer accepts a SOC 2 report with defined HITRUST CSF coverage. This can suit healthcare technology vendors serving customers with different assurance expectations.

Clarify ambiguous requests for “HITRUST alignment” before scoping the work: the recipient may mean certification, specific control coverage, or other evidence. If standalone SOC 2 meets the need, additional criteria should serve an agreed business purpose.

Can You Pursue Both SOC 2 and HITRUST Certification?

Yes. Coordinate the SOC 2 examination and HITRUST certification assessment around a common control environment while planning for their distinct deliverables.

Maintain a common control library with named owners and requirement mappings. Centralize dated evidence with clear system scope, identify framework-specific gaps early, and coordinate testing windows where practical.

For example, one access-review process may support both engagements. A team can maintain a common record of reviewers, access populations, decisions, and completed removals. Each examiner or assessor still evaluates whether the population, review frequency, period, and evidence meet the applicable requirements. Additional evidence or testing may be needed.

Control reuse, evidence reuse, and reliance on another auditor’s work are different decisions. Qualifying third-party reports, including SOC 2 Type II reports, may support a HITRUST assessment under its reliance requirements. The assessor must evaluate applicability and the required supporting information; reuse does not automatically eliminate further testing. 

A SOC 2 control may not fully address a corresponding HITRUST requirement. Differences in scope, specificity, evidence, or methodology can require additional implementation, documentation, or testing. Start with a requirement-level gap analysis.

Cost, Timeline, and Readiness

Plan around scope, existing control maturity, evidence readiness, remediation, internal resources, and customer deadlines. Allow for the SOC 2 Type II reporting period and applicable HITRUST implementation and review requirements. Budget for professional services, licensing, and tools relevant to the chosen engagement. Coordinated work can reduce duplication, but savings and completion dates depend on the actual gaps and assessment requirements.

How Accorian Helps Organizations Prepare

Accorian helps organizations build a multi-framework compliance strategy across HITRUST, SOC 2, HIPAA, ISO 27001, and other security requirements. The goal is a sustainable control environment that supports the assurance outcomes customers need.

Our support spans HITRUST e1, i1, and r2 readiness and assessment preparation; SOC 2 readiness; control mapping; risk assessment and remediation; security and penetration testing; third-party risk management; policy development; and continuous compliance.

Accorian is a HITRUST Authorized External Assessor organization; Accorian Assurance is the affiliated CPA attest entity. Each engagement should define advisory, assessment, and attestation roles, confirm licensing, and preserve required professional independence.

Supporting a common control environment with GORICO

GORICO connects controls to obligations, evidence, risks, and remediation activities, helping teams coordinate multiple assurance efforts. It centralizes controls, evidence, assessments, and workflows, with direct HITRUST MyCSF integration for teams using MyCSF. 

Build One Program for Multiple Assurance Needs

The strategic question is how to build a security and compliance program that supports multiple customer and regulatory obligations without repeatedly recreating the same work. Start with clear assurance requirements, maintain a common control environment, and preserve the distinctions between each report and certification.

CONTACT US

 

Frequently Asked Questions

1. Is HITRUST better than SOC 2?

Neither is universally better. They provide different assurance outcomes. Choose based on recipient expectations, scope, risk, and the evidence or certification required.

2. Does SOC 2 + HITRUST make an organization HITRUST Certified?

No. It is a SOC reporting model incorporating defined HITRUST CSF criteria. HITRUST Certification requires the applicable validated assessment, HITRUST review, and certification decision.

3. Is a full MyCSF subscription required for SOC 2 + HITRUST?

No. The assessed entity needs a HITRUST CSF license, obtainable through the CSF download from HITRUST’s website or through MyCSF. Commercial users, including the issuing CPA firm, need appropriate licensing for their use.

4. Is HITRUST required for healthcare companies?

HIPAA itself does not require HITRUST Certification. Customers or partners may impose contractual requirements. Neither SOC 2 nor HITRUST removes applicable HIPAA obligations.

5. Can an organization have SOC 2 and HITRUST at the same time?

Yes. Plan for the separate outcomes and coordinate overlapping controls and evidence, subject to each engagement’s requirements.

References

Licensing source: Kayla Christian, Director of Customer Success, HITRUST, in correspondence with Sean Dowling about SOC 2 + HITRUST. This correspondence supports the HITRUST-specific licensing, affiliation, and reporting clarification.

HITRUST assessments and certifications

AICPA and CIMA System and Organization Controls resources

HHS guidance on Security Rule certification

HITRUST Assessment Handbook section 12.3 on third-party reliance

GORICO by Accorian

HITRUST e1 assessment and maturity scoring guidance

Plan Your Assurance Strategy

Connect with Accorian to evaluate your customer requirements, identify gaps, and develop a coordinated HITRUST and SOC 2 roadmap.

Related Articles