In the first post in this series, we mapped out three common paths teams take after earning SOC 2: defense and government, general regulated enterprise, and healthcare. Healthcare deserves its own deeper look, because the sequencing decisions carry more weight here than in most other markets. Get the order wrong, and a team either certifies on a shaky foundation or spends six figures on assurance no buyer asked for.
If your company handles protected health information (PHI), or your product touches a workflow that does, SOC 2 got you into diligence conversations. It doesn't decide what comes next.
Two frameworks do that: HIPAA and HITRUST, both operating inside a regulatory environment that's actively shifting in 2026.
Why Healthcare Doesn't Play by the Generic Rules
For a fintech vendor or a general enterprise SaaS company, the next framework after SOC 2 is a market decision. Buyers ask for ISO 27001 or GDPR alignment, and the team weighs deal size against the lift.
Healthcare works differently. The moment a company creates, receives, maintains, or transmits PHI, HIPAA becomes a legal obligation rather than a market choice, whether that company is a hospital system, a digital health startup, or a vendor three steps removed from the patient. Treating HIPAA as an optional add-on next to SOC 2 is the most common mistake healthcare teams make.
HIPAA Is the Baseline, and It’s Shifting
HIPAA has three enforceable pieces: the Privacy Rule, which governs how PHI can be used and disclosed; the Security Rule, which sets administrative, physical, and technical safeguards for electronic PHI (ePHI); and the Breach Notification Rule, which sets the clock on disclosure after an incident. SOC 2 already covers a meaningful share of the Security Rule's ground. Access controls, encryption, monitoring, and incident response overlap heavily. The real work is mapping what a team already has against HIPAA's specific safeguards and closing what's missing, not rebuilding the security program from scratch.
Here's the part most post-SOC 2 planning misses: HIPAA's Security Rule is mid-overhaul. HHS published a Notice of Proposed Rulemaking in January 2025, the first substantive rewrite since 2013, and it would eliminate the "addressable" category entirely. Today, some safeguards are required and others are addressable, meaning a team can implement an equivalent alternative or document why a control doesn't apply. Under the proposed rule, nearly everything becomes mandatory: multi-factor authentication, encryption of ePHI at rest and in transit, and stricter breach reporting timelines all move from best practice to requirement.
The rule isn't final yet. Federal regulators pushed the target for finalization to July 2027, back from an original spring 2026 date, after a coalition of more than 100 hospital and provider groups asked HHS to withdraw it. Even with pushback, no proposal on the table walks the safeguards back, so building to the stricter draft now is the safer bet for any team that wants to avoid a second remediation project once a final rule lands.
Where HITRUST Fits and When It's Worth the Spend
HITRUST is where healthcare buyers go when HIPAA readiness alone isn't a strong enough signal. It's a certifiable framework, assessed by an independent third party, and it pulls requirements from HIPAA, NIST, ISO 27001, and more into one control set. Large health systems, payers, and increasingly pharmacy benefit managers (PBMs) treat it as a prerequisite, not a differentiator.
HITRUST comes in three tiers, and picking the wrong one is the second most common mistake teams make:
- e1, the entry-level assessment, covers roughly 44 controls, runs $35,000 to $50,000, and carries a one-year validity. It suits early-stage vendors that need baseline assurance fast.
- i1 covers around 182 controls, runs $70,000 to $120,000, and is the tier most health plan and hospital system contracts actually mean when they say "HITRUST required."
- r2 is the full risk-based assessment. It scores 200-plus controls against maturity, not just implementation, runs $100,000 to $500,000 or more, and carries a two-year certification with a required interim assessment at year one. Federal contractors, PBMs, and the most demanding payers ask for this tier specifically.
Many teams over-scope. A vendor selling into mid-market health systems rarely needs r2 readiness bolted onto a company that's never completed a certifiable assessment before. Confirm which tier the buyer's contract language actually requires before a dollar goes toward the assessment.
The Sequencing That Works
The teams that get this right follow a consistent order:
- Map every place PHI enters, moves through, or leaves the environment, including subprocessors and any workflow that touches a covered entity's data.
- Get HIPAA operational first. Map SOC 2 controls against the Security Rule's safeguards, close the gaps, and document the administrative pieces SOC 2 doesn't touch, like Notice of Privacy Practices and business associate agreements.
- Hold on HITRUST until a specific deal or buyer contract requires it, then confirm the exact tier before scoping the assessment.
- Layer in ISO 27001 only when global expansion or enterprise trust outside health care specifically is also part of the growth plan.
Reverse steps two and three, and a team ends up certifying a control environment that hasn't been operationalized yet. That pattern is exactly what drives corrective action findings mid-assessment, which can add one to four months to a HITRUST timeline.
What This Looks Like in Practice
Take a digital health startup that earned SOC 2 to close its first enterprise contracts, then entered diligence with a regional hospital network. The security review centered on two things: whether PHI was handled correctly at every step, and whether the startup could produce a credible HITRUST roadmap.
The hospital's contract language specified i1, not r2. That single detail changed the scope of the project by roughly $150,000 and four to six months. The startup mapped its existing SOC 2 controls into HIPAA's Security Rule safeguards, closed the gaps in about ten weeks, and used that operational baseline to scope i1 readiness with a clear view of what evidence already existed and what still needed to be built. SOC 2 opened the conversation. A HIPAA-first sequence, followed by the right HITRUST tier, closed it.
Common Mistakes to Avoid
A few patterns show up again and again in healthcare post-SOC 2 planning:
- Pursuing HITRUST before HIPAA is operationally solid, which means certifying on gaps instead of a real control environment.
- Assuming a buyer wants r2 when the contract language actually says i1, then over-scoping the assessment as a result.
- Treating business associate agreements as static paperwork instead of a control that needs the same ongoing monitoring as any other safeguard.
- Ignoring the proposed HIPAA Security Rule changes now and treating them as a future problem, when the direction of the rule is already clear.
Building the Healthcare Compliance Roadmap with Drata
None of this has to mean separate audits in separate silos. Drata maps HIPAA and HITRUST controls against the evidence a team is already collecting for SOC 2, so nobody recreates documentation every time a new health system or payer asks for a different credential. Centralized evidence, continuous control monitoring, and cross-framework mapping mean the HIPAA work a team does this quarter carries directly into the next HITRUST assessment, instead of starting over.
Ready to build your healthcare compliance roadmap? Schedule your demo with the Drata team.

