SchellmanCON is back! Join us for our virtual conference on March 6 & 7, 2025

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

SOC 2 + Additional Criteria What I Need to Know

Healthcare Assessments | SOC Examinations

What is the SOC 2?

At a high level a SOC 2 examination is a report on internal controls of a service organization related to the Trust Service Principles and Criteria (TSPs), which include:  security, availability, processing integrity, confidentiality and/or privacy. Reporting on these TSPs can provide assurance around the adequacy of your services’ security control environment.

What do you need to know about the SOC 2 additional criteria?

In addition to the TSPs, organizations can add additional criteria to the SOC 2 examination in order to align with other IT security regulations. The inclusion of this additional criteria can potentially reduce overall compliance costs and efforts for organizations by addressing multiple compliance requirements in one report, while at the same time providing customers with relevant information on the expanding compliance landscape.

According to the AICPA, the additional criteria that organizations are recommended to consider based on their services provided and can request to be added to a SOC 2 are highlighted below.

Requirements set forth in the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Administrative Simplification 45 CFR Sections 164.308-316

  • Beyond testing the general privacy criteria, some clients may require further coverage based on industry requirements, including third party review of a business’ compliance with the HIPAA 45 CFR 164.308-316 requirements.

Criteria established by an industry group

  • There is significant overlap with many companies who require a SOC 2 and some combination of the other major standards, including, but not limited to:
    • HITRUST Common Security Framework (CSF)
    • CSA’s STAR Program, specifically the STAR Attestation that includes the CCM criteria
    • ISO-27001
    • NIST SP-800-53 R4
    • COSO
    • COBIT

To find out more on SOC 2 additional criteria you should reach out to a SOC 2 provider to speak more about what additional criteria might be applicable to your compliance reporting needs.

About OLIVIA REFILE

Olivia Refile is a Senior Associate with Schellman based in Philadelphia, PA. Prior to joining BrightLine in 2015, Olivia worked as a Senior IT Risk & Compliance Analyst, specializing in Internal and external audits and IT Security Risk Assessments. Refile has over five years of experience comprised of assessing security compliance of cloud vendors, data centers and internal, and mobile and SaaS applications. Refile is now mainly dedicated to performing Service Organization Controls (SOC) examinations.