Solutions Who We Serve Insights & Events About Contact
Published on September 18, 2026 6 min read

Five Healthcare IT HIPAA Compliance Options

Latin American female scientist working at a laboratory doing research using a computer - STEM concepts

Summary: Health tech companies have several avenues for demonstrating compliance with HIPAA, but some are more appropriate and attainable for certain businesses than others. It is important to choose the right compliance path, as the wrong ones can cost you extra time, money, and business.

If you sell technology into healthcare, sooner or later a customer will ask you to prove the data you hold is secure. What customers ask for varies widely. One covered entity wants a HIPAA attestation. The next wants a SOC 2 report. A large health system may accept nothing short of HITRUST certification.

Choosing the wrong report is an expensive unknown. You can spend a year and serious budget on an assessment no customer asked for, or when you win a contract, you cannot support it with the report you already have. The right choice depends on how much protected health information (PHI) you handle, who your customers are, and what their own contracts obligate them to collect from you.

There are typically five ways to demonstrate compliance with HIPAA fundamentals that increase in complexity and cost depending on the report type:

  • HIPAA attestation or HITRUST e1
  • SOC 2 reporting
  • SOC 2 + HIPAA
  • SOC 2 + HITRUST or HITRUST i1
  • HITRUST CSF r2

In this article, we walk through each of the reporting frameworks and where each one fits, in order of cost and complexity.

Table 1: How to demonstrate compliance with HIPAA fundamentals

Table 1: How to demonstrate compliance with HIPAA fundamentals

1. HIPAA attestation or HITRUST e1

  • HIPAA Attestation: A HIPAA attestation report is the easiest and most cost-effective assurance reporting to achieve. It is appropriate for small technology service providers with applications used in healthcare that have minimal interaction with electronic protected health information (ePHI). If you are a startup and a customer is requesting evidence of HIPAA compliance, this is your best reporting option.
  • e1 (Essentials): e1 covers 44 controls of foundational cyber hygiene, scored on “implemented” maturity only, and it requires a fully validated assessment every year. It is the lowest-cost HITRUST tier and fits low-risk Business Associates (BAs): small vendors touching minimal PHI, no ePHI storage, single-product SaaS platforms, and subcontractors a covered entity wants baseline comfort on rather than deep assurance.

2. SOC 2 reporting

The next step up is the SOC 2 report. SOC 2 reporting is built on the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (TSC): Security, Availability, Confidentiality, Processing Integrity, and Privacy. Security is always in scope, and the other four are added based on what your customers need. If your business is classified as a true Business Associate (BA) and a customer or covered entity makes a general request for a compliance report, a SOC 2 report will likely meet their needs.

3. SOC 2 + HIPAA

SOC 2 reporting is highly adaptable, and auditors can incorporate objective criteria from other compliance reporting standards. These are referred to as SOC 2 + (Plus) reports. Consider SOC 2 + HIPAA if you serve health insurance providers. Although there is significant overlap between the Trust Services Criteria and the HIPAA/HITECH criteria, SOC 2 + HIPAA represents a step up in cost and complexity from a basic SOC 2 report.

4. SOC 2 + HITRUST or HITRUST i1

  • SOC 2 + HITRUST: For many organizations, a HITRUST Common Security Framework (CSF) certification may be the goal; however, it may not be a practical solution at their current level of maturity. SOC 2 + HITRUST is considerably easier and more cost-effective to achieve than a HITRUST validated assessment and certification. Use it when a customer asks for a SOC 2 report plus evidence that you meet HITRUST requirements. It suits BAs that count multiple significant payers or providers among their customers.
  • i1 (Implemented): i1 covers 182 threat-adaptive controls, also scored on “implemented” only, and it is refreshed each year against current threats. It requires a full, validated assessment in year one and rapid recertification in year two. It fits mid-market BAs with moderate PHI volume, including billing and revenue cycle management (RCM) firms, care coordination platforms, and IT managed service providers. It is often the negotiated middle ground when a covered entity asks for HITRUST but r2 is out of proportion to the scope of your work.

5. HITRUST CSF r2 validated assessment and certification

HITRUST CSF is a widely adopted security and privacy framework across industries globally. It is a comprehensive and prescriptive set of controls that meet the requirements of multiple regulatory and compliance reporting standards, including ISO/IEC 27001 and HIPAA. HITRUST r2 is the most comprehensive and complex of the HITRUST assessments, and it is what large health systems and payers often expect.

The HITRUST CSF r2 (risk-based) validated assessment has a tailored scope (about 385 controls on average, drawn from a library of more than 2,000) that focuses on the policy, procedure, and implemented maturity levels. It requires a full, validated assessment in year one and an interim assessment in year two. It fits high-risk, high-volume BAs: clearinghouses, electronic health record (EHR) and cloud hosting providers, large third-party administrators (TPAs), and anyone processing PHI at scale or facing customer contracts, requests for proposal (RFPs), or downstream subcontractor obligations that specify r2.

Due to its cost and complexity, organizations typically take on r2 when a customer specifically asks for it, most often a large payer or health system (e.g., hospitals and insurance companies) that makes certification a condition of the contract.

Final thoughts

As a BA, you are expected to hold the same line on data security as the customers you serve, which means privacy and security belong in your business model rather than bolted on when a request arrives. The wrong compliance path can cost you time, budget, and deals you were otherwise ready to win.

Start from the demand side. Ask your largest customers what they will require at renewal, read your contracts and open RFPs for a named framework, and size the report to the volume of PHI you handle. If a large health system is in your pipeline, plan for r2 well ahead of the deadline.

Evaluate your options for attaining and demonstrating HIPAA compliance, then reach out to Aprio for help identifying and navigating the compliance avenue of your choice. Aprio is a Top 20 CPA firm with a practice that has specialists in healthcare IT and deep experience in HIPAA attestation reporting, SOC 2, ISO 27001, ISO 27701, and HITRUST CSF validated assessment and certification. To learn more about how Aprio can help your business select, establish, and scale your security and compliance program, contact us today.

How we can help

Aprio can help you choose the right reporting path, then establish and scale the program behind it, across HIPAA attestation, SOC 2, ISO 27001, ISO 27701, and HITRUST CSF validated assessment and certification. Connect with us

Latin American female scientist working at a laboratory doing research using a computer - STEM concepts