Website Security
What Is SOC 2, and Does Your Practice's Website Vendor Need It?

SOC 2 is one of the clearest signals that a vendor protects your data. Here is what it means, how it differs from HIPAA, and what to ask your web partner.
Your practice runs on outside vendors. Your website is hosted somewhere. Your appointment requests flow through a form tool. Your files sit in the cloud. Every one of those companies touches information about your patients, and you are trusting all of them to handle it responsibly. The natural question is: how would you actually know if they do?
One of the clearest answers in the technology world is a SOC 2 report. You have probably seen vendors advertise that they are "SOC 2 compliant" without explaining what that means or whether it matters for a small practice. This guide breaks it down in plain English: what SOC 2 is, what it proves, how it relates to HIPAA, and whether your website vendor actually needs it.
What SOC 2 is
SOC 2 stands for System and Organization Controls 2. It is a framework created by the American Institute of Certified Public Accountants, the AICPA, for evaluating how a service organization protects the data it handles. You can read the AICPA's own overview of the SOC suite of services.
The important thing to understand is that SOC 2 is not a self-declared badge. A company cannot simply announce it is SOC 2 compliant. An independent auditor examines the company's systems and controls and issues a formal report on whether those controls are designed well and actually working. When a vendor hands you a SOC 2 report, they are handing you an outside expert's assessment, not their own marketing claim.
The five Trust Services Criteria
SOC 2 evaluates a company against up to five areas, known as the Trust Services Criteria. Security is required in every report; the others are included based on what the company does.
- Security. Is the system protected against unauthorized access, both physical and digital? This is the foundation and is always assessed.
- Availability. Is the system reliably up and accessible, with the monitoring and backups to keep it that way?
- Processing integrity. Does the system do what it is supposed to, completely and accurately, without silently corrupting or losing data?
- Confidentiality. Is information that should stay private, such as patient or business data, restricted to the right people?
- Privacy. Is personal information collected, used, retained, and disposed of responsibly?
For a practice, the Security and Confidentiality criteria are usually the most relevant, because they speak directly to whether patient information is protected against exposure.
Type I versus Type II
There are two flavors of SOC 2 report, and the difference matters.
- Type I looks at whether the controls are designed properly at a single point in time. It is a snapshot.
- Type II looks at whether those controls actually operated effectively over a period of time, often six months to a year. It is a track record.
A Type II report is the stronger signal, because anyone can look good on a single day. Type II shows the controls held up under real conditions over months. When a vendor says they are SOC 2 certified, it is fair to ask which type, and how recent the report is.
How SOC 2 relates to HIPAA
These two are easy to confuse, and vendors sometimes blur them on purpose. They overlap, but they are not the same thing, and one does not replace the other.
HIPAA is a healthcare-specific law with legal force, focused on protected health information. SOC 2 is a voluntary framework that applies to service organizations in any industry, focused on the controls a company runs. A vendor can be SOC 2 audited and still not be an appropriate HIPAA business associate, and vice versa. Crucially, a SOC 2 report is not a substitute for a signed Business Associate Agreement, which HIPAA requires whenever a vendor handles PHI. If you want the full picture on the healthcare side, see our guide on what a HIPAA-compliant website really means.
The good news is that the underlying safeguards line up well. The controls a SOC 2 audit checks for map closely to what the HIPAA Security Rule expects, and to widely used standards like the NIST Cybersecurity Framework. A vendor that runs on SOC 2 infrastructure and will sign a BAA is usually a good sign on both fronts.
Does your website vendor actually need SOC 2?
Here is the honest answer many agencies will not give you. A solo web designer or small studio is very unlikely to hold their own SOC 2 report. A full SOC 2 audit is expensive and time-consuming, and it is aimed at platforms and software companies that store data at scale, not individual builders. So if that is your yardstick, almost no one who builds practice websites would pass.
What matters far more is the infrastructure your vendor builds on and the choices they make with your data. The hosting platforms, databases, and cloud services underneath a well-built site are very often SOC 2 audited themselves. A security-minded builder chooses those compliant foundations, configures them correctly, signs BAAs where PHI is involved, and can explain exactly how your patients' information is protected.
The right question is not "do you personally have a SOC 2 report," but "do you build on SOC 2 and HIPAA-ready infrastructure, and can you prove how my patients' data is handled?"
What to ask a vendor
Whether you are choosing a web partner, a scheduling tool, or a hosting provider, these questions cut through the marketing:
- Is the platform or infrastructure you rely on SOC 2 audited, and is it Type I or Type II?
- Where is my data stored, and who has access to it?
- Will you sign a Business Associate Agreement for anything that touches patient information?
- How is data encrypted, both while it moves and while it sits at rest?
- What happens to my data if we ever stop working together?
A vendor who takes security seriously will have ready answers. Vague responses, or a rush to change the subject, tell you what you need to know.
Where Trustform stands
Trustform Digital is built around exactly this mindset. The founder's background is in security and cloud architecture, holding the CISSP certification, so security is not an afterthought bolted onto a finished site. It is the starting point. That means building on compliant, well-audited infrastructure, configuring it carefully, and being able to walk you through precisely how your patients' data is protected. You can read more about that approach on our security page and about the person behind it on the about page.
If you want a straight answer about whether your current setup and its vendors are handling patient data responsibly, book a free call or get a tailored recommendation. It is a good thing to know for certain rather than assume.
Share this article
Jody Hartwell
Jody writes about building secure, modern, HIPAA-conscious websites and better patient experiences for dental, medical, and legal practices.
Trustform Digital
Secure, HIPAA-conscious websites that book more patients
We design fast, secure websites and local SEO for dental, medical, and legal practices, built and protected by a CISSP-certified developer. From dental website design and medical practice websites to local SEO and HIPAA-conscious patient tools, we build around exactly what your practice needs.


