Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

SOC 2 + Additional Criteria What I Need to Know

Healthcare Assessments | SOC Examinations

What is the SOC 2?

At a high level a SOC 2 examination is a report on internal controls of a service organization related to the Trust Service Principles and Criteria (TSPs), which include:  security, availability, processing integrity, confidentiality and/or privacy. Reporting on these TSPs can provide assurance around the adequacy of your services’ security control environment.

What do you need to know about the SOC 2 additional criteria?

In addition to the TSPs, organizations can add additional criteria to the SOC 2 examination in order to align with other IT security regulations. The inclusion of this additional criteria can potentially reduce overall compliance costs and efforts for organizations by addressing multiple compliance requirements in one report, while at the same time providing customers with relevant information on the expanding compliance landscape.

According to the AICPA, the additional criteria that organizations are recommended to consider based on their services provided and can request to be added to a SOC 2 are highlighted below.

Requirements set forth in the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Administrative Simplification 45 CFR Sections 164.308-316

  • Beyond testing the general privacy criteria, some clients may require further coverage based on industry requirements, including third party review of a business’ compliance with the HIPAA 45 CFR 164.308-316 requirements.

Criteria established by an industry group

  • There is significant overlap with many companies who require a SOC 2 and some combination of the other major standards, including, but not limited to:
    • HITRUST Common Security Framework (CSF)
    • CSA’s STAR Program, specifically the STAR Attestation that includes the CCM criteria
    • ISO-27001
    • NIST SP-800-53 R4
    • COSO
    • COBIT

To find out more on SOC 2 additional criteria you should reach out to a SOC 2 provider to speak more about what additional criteria might be applicable to your compliance reporting needs.

About OLIVIA REFILE

Olivia Refile is a Senior Associate with Schellman based in Philadelphia, PA. Prior to joining BrightLine in 2015, Olivia worked as a Senior IT Risk & Compliance Analyst, specializing in Internal and external audits and IT Security Risk Assessments. Refile has over five years of experience comprised of assessing security compliance of cloud vendors, data centers and internal, and mobile and SaaS applications. Refile is now mainly dedicated to performing Service Organization Controls (SOC) examinations.