These three get discussed together and are fundamentally different kinds of thing. One is federal law, one is a contractual standard imposed by private companies, and one is a voluntary audit report you commission about yourself.
Understanding which category each falls into explains most of what follows — who enforces it, what happens when you fail, and what evidence you need.
The essential distinction
HIPAA is federal law. It protects health information, it is enforced by the HHS Office for Civil Rights, and non-compliance carries civil and in some cases criminal penalties. You do not choose to be subject to it — you are, if you handle protected health information as a covered entity or business associate.
PCI-DSS is a contractual standard set by the card brands. It protects payment card data. Enforcement comes from your acquiring bank through your merchant agreement, via fees, rate increases, or loss of card acceptance. It is not law, but the consequences are commercially real.
SOC 2 is an attestation report produced by an independent CPA firm under AICPA standards. Nobody requires it by law. Customers require it, which is a different kind of compulsion and increasingly a decisive one for businesses selling to larger organisations.
One consequence worth stating plainly: you cannot be "HIPAA certified" or "PCI certified" in the way vendors sometimes claim. There is no certification for either. You can be assessed, you can attest, and you can hold a SOC 2 report — but a vendor advertising HIPAA certification is describing something that does not exist.
What each actually protects
- HIPAA — protected health information. Anything identifying an individual and relating to their health, care, or payment for care. Narrow in subject, broad in the systems it reaches.
- PCI-DSS — cardholder data. The card number, cardholder name, expiry, service code, and separately the sensitive authentication data which must never be stored.
- SOC 2 — whatever you define. You select which Trust Services Criteria apply: Security is mandatory, and Availability, Processing Integrity, Confidentiality and Privacy are optional additions.
That flexibility is the most misunderstood aspect of SOC 2. Two reports can both be clean and cover very different ground, which is why reading the scope section matters more than seeing that a report exists.
What proof each requires
This is where the practical differences concentrate.
HIPAA requires documented internal processes: a risk analysis, policies, training records, Business Associate Agreements, incident procedures. There is no routine external audit — you produce this if OCR asks, typically after a complaint or a breach. The burden is continuous documentation rather than periodic examination.
PCI-DSS requires an annual self-assessment questionnaire for most small merchants, plus quarterly external vulnerability scans where applicable, submitted to your acquiring bank. Larger merchants require an on-site assessment by a Qualified Security Assessor.
SOC 2 requires an audit by a licensed CPA firm. A Type I report examines whether controls are suitably designed at a point in time. A Type II examines whether they operated effectively over a period, usually three to twelve months. Type II is what customers generally want, and it takes considerably longer to obtain because you must run the controls before you can be audited on them.
Where they overlap
Substantially, which is the useful news. A business subject to more than one framework is not doing the work several times.
Controls that satisfy all three:
- Access control and least privilege
- Multi-factor authentication
- Encryption at rest and in transit
- Logging and monitoring
- Vulnerability and patch management
- Incident response planning
- Security awareness training
- Vendor and third-party risk management
- Backup and recovery
- Physical security
The practical approach is to build a single control set covering the union of your obligations, then map it to each framework rather than running parallel programmes. The mapping exercise is where most of the duplicated effort gets eliminated.
Which apply to you
- Handling health information — HIPAA, and the definition of business associate is broader than most businesses assume. IT providers with access to systems containing ePHI are business associates.
- Taking card payments — PCI-DSS, with no volume threshold below which it stops applying.
- Selling services to businesses that ask about your security — SOC 2 becomes a commercial requirement well before anyone mandates it.
- Tax preparation, lending, or arranging finance — the FTC Safeguards Rule, which sits alongside these three and applies to a wider range of businesses than expected.
- Holding personal data about New York residents — the SHIELD Act imposes security requirements independent of sector.
Multiple frameworks applying simultaneously is normal rather than exceptional. A medical billing company handling health data, taking card payments, and selling to hospital systems is subject to all three plus state law.
Where to start
If more than one applies, start with HIPAA or the Safeguards Rule where relevant, because they are legal obligations with regulatory consequences. Then PCI-DSS, structuring your payment architecture to minimise scope. Then SOC 2 when a customer requires it, at which point most of the control work is already done.
SOC 2 last is deliberate. It is the most expensive, it is voluntary, and the controls it examines are largely the ones the other frameworks already required. Businesses that build properly for their legal obligations find the SOC 2 audit substantially easier than those approaching it cold.