SOC 2 Explained: Type I vs. Type II for Telehealth Security
SOC 2 Type II
telehealth security
HIPAA compliance

SOC 2 Explained: Type I vs. Type II for Telehealth Security

SOC 2 Type II tests a vendor’s security controls over time. Learn what it covers, how it differs from HIPAA, and what to verify.

Bask Health Team
Bask Health Team
09/29/2026

SOC 2 is one of the security terms telehealth vendors frequently put on pricing pages, sales decks, and security questionnaires, but the label alone tells you less than many buyers assume. A SOC 2 examination is an independent assessment of a service organization’s controls against criteria established by the AICPA, giving customers a way to evaluate whether a vendor’s security claims are backed by an external assurance process rather than marketing language alone.

For healthcare operators, SOC 2 also needs to be understood separately from HIPAA. HIPAA governs specific privacy and security obligations around protected health information, while SOC 2 examines a broader set of controls at a service organization. Bask’s guide to HIPAA-compliant telehealth software goes deeper into the healthcare-specific requirements; this article focuses on what SOC 2 actually tells you about a technology vendor.

That distinction matters when a telehealth company selects a HIPAA-compliant telehealth platform or any other infrastructure that may handle patient records, intake responses, provider activity, prescriptions, payments, and other sensitive information. Asking whether a vendor “has SOC 2” is a useful starting point, but stronger due diligence asks what type of report exists, what period it covers, and what controls were actually examined.

What Is SOC 2?

SOC stands for System and Organization Controls. SOC 2 is part of the AICPA’s broader SOC suite of services, which CPAs use to provide assurance about controls at service organizations.

The AICPA’s official SOC Suite of Services resource describes SOC 2 examinations as addressing controls relevant to security, availability, processing integrity, confidentiality, or privacy. Those areas are based on the AICPA’s Trust Services Criteria.

In plain language, SOC 2 helps answer a question every telehealth operator should be asking:

Has an independent auditor examined the controls behind this vendor’s technology and operations?

That is different from a vendor simply publishing a security policy.

A SOC 2 examination may look at controls relating to areas such as:

  • Access management
  • System monitoring
  • Change management
  • Incident-related processes
  • Risk management
  • Data protection
  • Availability controls
  • Confidentiality safeguards
  • Processing controls
  • Privacy-related controls

Not every SOC 2 report necessarily covers every Trust Services category beyond the required security criteria, which is why the scope of the actual report matters.

The Five Trust Services Categories

SOC 2 reporting is built around the AICPA’s Trust Services Criteria. The categories provide a useful mental model for understanding what a SOC 2 examination can address.

Trust Services CategoryWhat It Generally Addresses
SecurityProtection against unauthorized access and other security risks
AvailabilityWhether systems are available as committed or agreed
Processing IntegrityWhether system processing is complete, valid, accurate, timely, and authorized
ConfidentialityProtection of information designated as confidential
PrivacyHow personal information is collected, used, retained, disclosed, and disposed of

Security is foundational to SOC 2, while the other categories may be included depending on the organization’s system, commitments, and scope.

This is one reason the statement “We’re SOC 2 compliant” is not enough for serious vendor evaluation. Two vendors can both reference SOC 2 while having reports with different scope, periods, systems, and criteria.

SOC 2 Type I vs. Type II

The most important distinction for a buyer is often whether the vendor has a Type I or Type II report.

Both involve an independent examination, but they answer different questions.

SOC 2 Type ISOC 2 Type II
Examines control design at a specified point in timeExamines controls over a specified period
Helps show that relevant controls were designed and in placeAlso evaluates whether those controls operated effectively during the period
Provides a snapshotProvides evidence across time
Useful as an initial assurance signalGenerally gives buyers stronger operating evidence

A simple analogy helps.

Imagine a company says it requires employees to use a particular security process.

A Type I examination can help assess whether the control is designed and in place at the specified date.

A Type II examination goes further by examining the operation of controls across the reporting period.

That difference matters because security is not a one-day event.

Why Type II Is a Stronger Vendor Signal

A security control can look excellent on paper and still fail operationally.

A company might have policies requiring restricted access, monitoring, approvals, or logging, but the more meaningful question is whether those processes actually function consistently as the organization operates.

That is the value of the Type II structure: it adds an operating-effectiveness dimension over a period rather than limiting the examination to a point-in-time view.

For a telehealth operator evaluating a long-term technology vendor, that evidence is particularly relevant because the vendor will not handle sensitive systems for one day. The relationship may last for years.

Think of It as Snapshot vs. Track Record

Type I asks approximately:

Are the controls appropriately designed and in place at this point?

Type II adds:

Did the controls operate effectively during the period examined?

That does not mean a Type II report guarantees that a vendor can never experience a security incident, nor does it eliminate the customer’s own due diligence. It does mean the vendor has gone through a more extensive assurance process around the controls included in the report.

SOC 2 Is an Audit Framework, Not a Government Security Law

Another common misunderstanding is treating SOC 2 as a regulation.

It is not.

SOC 2 is an assurance framework developed through the AICPA. Organizations voluntarily undergo SOC examinations, usually because customers, enterprise buyers, partners, or risk teams want independent evidence about their controls.

HIPAA is fundamentally different.

The U.S. Department of Health and Human Services explains that the HIPAA Security Rule establishes national standards for protecting electronic protected health information and requires regulated entities to implement appropriate administrative, physical, and technical safeguards.

So while both SOC 2 and HIPAA can involve security controls, they exist for different reasons and operate differently.

SOC 2 vs. HIPAA

For telehealth companies, the distinction is easier to understand side by side.

SOC 2HIPAA
Independent assurance frameworkU.S. federal healthcare law and regulations
Developed through the AICPAAdministered and enforced under federal law
Relevant to service organizations across industriesApplies to covered entities and business associates in healthcare contexts
Examines controls within the defined report scopeEstablishes legal requirements for protecting PHI/ePHI
Produces an auditor’s reportDoes not produce a universal government “HIPAA certification”
Voluntary in the sense that organizations choose to undergo the examinationMandatory when the law applies

A telehealth platform can therefore have a SOC 2 report and still need to satisfy applicable HIPAA obligations.

Likewise, saying that a platform is HIPAA compliant does not tell you whether an independent CPA has examined its controls through a SOC 2 engagement.

Why Telehealth Vendors Benefit From Both

Telehealth platforms often sit at the intersection of healthcare regulation and technology risk.

A platform may store or transmit patient data while also operating cloud infrastructure, connected tools such as a CRM, authentication systems, APIs, employee access controls, administrative tools, audit logs, and other systems that customers depend on.

HIPAA addresses legal obligations around protected health information when it applies.

SOC 2 gives customers another form of assurance by examining defined organizational and technology controls.

The two therefore complement one another rather than replace one another.

For a telehealth buyer, seeing both can answer two different due-diligence questions:

  • HIPAA: Is the vendor structured to meet the healthcare-specific obligations that apply to its role?
  • SOC 2: Has an independent auditor examined specified controls around the vendor’s systems and operations?

That is a much more useful framework than asking which acronym is “better.”

What SOC 2 Does Not Tell You Automatically

The presence of SOC 2 in a vendor’s footer or sales deck should not end the security conversation.

A buyer still does not know:

  • Whether the report is Type I or Type II
  • What system is actually covered
  • Which Trust Services Criteria are included
  • What reporting period applies
  • Whether there were identified exceptions
  • Whether important subprocessors are included or carved out
  • Whether the report is current
  • Whether the controls relevant to your intended use case are actually in scope

This is why sophisticated buyers ask for more than a logo.

The SOC 2 Vendor Due-Diligence Checklist

Instead of asking only “Are you SOC 2 compliant?”, ask questions that reveal what the assurance actually covers.

Question to AskWhy It Matters
Is the report Type I or Type II?Determines whether you are looking at a point-in-time or period-based examination
What period does the report cover?Shows how current the evidence is
Which system or services are in scope?Prevents assuming the report covers products it does not
Which Trust Services Criteria are included?Clarifies the exact areas examined
Who performed the examination?SOC examinations are performed by qualified independent CPA firms
Were exceptions identified?Helps you understand control-testing results
Are subprocessors or subservice organizations included?Reveals dependencies outside the vendor itself
Can our security team review the report?Lets your own reviewers evaluate scope and findings

This checklist turns SOC 2 from a marketing checkbox into a practical vendor-management tool.

Ask for the Report, Not Just the Badge

SOC 2 reports contain considerably more useful information than a vendor’s public security page.

Depending on the report, buyers may be able to understand the system description, applicable criteria, management assertions, auditor opinion, controls, tests performed, and test results.

Because SOC 2 reports can contain sensitive details about systems and controls, vendors may restrict access and require an NDA before sharing them.

That is normal.

What matters is whether a serious prospective customer can obtain enough evidence to perform appropriate due diligence.

A vendor unwilling to explain whether its report is Type I or Type II, what period it covers, or what environment it applies to gives buyers much less useful assurance than one that can clearly describe its report scope.

A Simple SOC 2 Trust Ladder

Not every SOC 2 claim provides the same amount of information.

A useful way to think about vendor transparency is as a ladder:

Level 1: “We Are Secure”

This is a claim, not independent assurance.

Level 2: “We Are SOC 2 Compliant”

Better, but still incomplete. You still don't know the report type, scope, period, or criteria.

Level 3: “We Have a SOC 2 Type II Report”

More useful because the buyer now knows the examination covered operating effectiveness over a reporting period.

Level 4: Report Scope Is Clearly Explained

The vendor can explain:

  • Which environment is covered
  • Which criteria are included
  • What period was examined
  • Who conducted the examination

Level 5: Qualified Buyers Can Review the Report

Security and compliance teams can evaluate the actual report rather than relying entirely on vendor claims.

For enterprise telehealth buyers, the higher levels make vendor due diligence substantially more useful.

SOC 2 Does Not Eliminate Your Own Security Review

A SOC 2 Type II report is valuable evidence, but it should not replace the rest of the vendor-review process.

Organizations still need to understand how the product will be used, which information it will handle, how users authenticate, how access is managed, what integrations are enabled, and what contractual responsibilities exist between the parties.

For healthcare specifically, security review may also include:

  •  Business Associate Agreements where required
  • HIPAA-related safeguards
  • Data encryption
  • Authentication controls
  • User permissions
  • Audit logging
  • Incident-response responsibilities
  • Data retention and deletion
  • Third-party integrations
  • Business continuity
  • Vendor access to patient information

SOC 2 can strengthen that review by providing independent assurance evidence, but it does not answer every healthcare-specific question.

Security Features vs. Security Assurance

This distinction is particularly useful when comparing telehealth platforms.

A vendor can list many security features:

  • MFA
  • Encryption
  • Audit logging
  • Access controls
  • Monitoring
  • Backups

Those features matter, but feature lists tell you what the vendor says exists.

Independent assurance provides a different layer of evidence.

Bask’s security overview describes measures including encryption at rest and in transit, administrative access control, two-factor authentication, system monitoring, logging and alerting, identity and device management, and information governance.

The distinction is useful for buyers: security controls are the mechanisms themselves, while SOC 2 provides an independent examination framework for evaluating defined controls.

How Bask Health Handles SOC 2 and Security

Bask Health maintains SOC 2 Type II controls as part of a broader security and compliance stack that also includes HIPAA and LegitScript compliance, multi-factor authentication, audit logging, and telehealth-certification assistance.

That combination matters because telehealth security is not one control or one badge. Healthcare operators need infrastructure that addresses access, activity visibility, patient-data protection, and healthcare-specific compliance requirements together.

Bask’s security page describes the safeguards behind that stack, from encryption and access control to monitoring, logging, and governance. These protections apply across every Bask plan, alongside the platform’s built-in doctor networks, pharmacy fulfillment, and payment processing, so more than 250 U.S. telehealth companies run on the same security foundation.

For a buyer conducting formal due diligence, the same principle applies to Bask as to any other vendor: ask for the current SOC 2 Type II report and review its scope and period. Prospects with security review questions can contact the Bask team.

What to Ask Before Choosing a Telehealth Platform

SOC 2 should be one part of the broader security conversation, and one row in any telehealth platform comparison.

Before committing to infrastructure, a telehealth operator should be able to get clear answers to questions such as:

  • Does the vendor have SOC 2 Type I or Type II?
  • How current is the report?
  • What services are within scope?
  • Can your security team review the report?
  • Does the vendor support MFA?
  • Are user activities logged?
  • How is sensitive data protected?
  • Will the vendor sign an appropriate BAA when required?
  • How are permissions managed?
  • What happens when a user leaves your organization?
  • How does the vendor manage security incidents?
  • Which third-party systems participate in the service?

The point is not to create the longest possible questionnaire. It is to distinguish vendors that can demonstrate mature security operations from vendors that answer every question with another marketing claim.

FAQs

What is SOC 2?

SOC 2 is an independent assurance examination that evaluates controls at service organizations against the AICPA’s Trust Services Criteria. The criteria address security and can also address availability, processing integrity, confidentiality, and privacy depending on the scope of the engagement.

SOC 2 is not a government regulation and should not be confused with HIPAA.

What’s the difference between SOC 2 Type I and Type II?

A Type I report evaluates control design as of a specified date. A Type II report also evaluates how the controls operated over a specified reporting period.

For vendor due diligence, Type II generally provides more evidence about how controls function in practice because the examination considers operating effectiveness over time rather than only a point-in-time design assessment.

Is SOC 2 the same as HIPAA compliance?

No.

SOC 2 is an independent assurance framework developed through the AICPA, while HIPAA is federal healthcare law and regulation governing protected health information when it applies.

A telehealth technology provider may therefore need to address HIPAA obligations while also undergoing SOC 2 examinations to provide customers with broader assurance about its controls.

What should I ask a telehealth vendor for to verify its SOC 2 status?

Ask whether the report is Type I or Type II, the period it covers, which services and systems are in scope, which Trust Services Criteria apply, and whether your security team can review the report.

Do not rely solely on a SOC 2 badge or a sentence on the vendor’s website.

Does Bask Health have SOC 2 Type II certification?

More accurate terms are SOC 2 Type II report, examination, or attestation, rather than “certification.”

Bask Health maintains SOC 2 Type II controls as part of its broader security and compliance posture, alongside HIPAA and LegitScript compliance, MFA, and audit logging. Buyers conducting formal security due diligence can request the current report to confirm its scope, period, and the Trust Services Criteria it covers.

Conclusion

SOC 2 matters because vendor security claims are easy to make and harder to verify.

A SOC 2 examination introduces independent assurance into that conversation, while the difference between Type I and Type II tells buyers whether they are looking at a point-in-time assessment or evidence that controls were tested across a reporting period.

For telehealth businesses, SOC 2 should not be treated as a substitute for HIPAA. The two address different questions: HIPAA establishes healthcare-specific legal requirements for protecting PHI, while SOC 2 provides an assurance framework for examining defined controls at a service organization.

The strongest due diligence therefore goes beyond asking whether a vendor “has SOC 2.” Ask which type, what scope, which period, and what the actual report says.

A logo tells you a vendor completed a process. The report tells you what was actually examined.

References

1.     AICPA & CIMA. (n.d.). System and Organization Controls: SOC suite of services. https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

2.     U.S. Department of Health and Human Services. (n.d.). The HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/index.html

3.     U.S. Department of Health and Human Services. (n.d.). Business associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html

Schedule a Demo

Talk to an expert about your data security needs. Discuss your requirements, learn about custom pricing, or request a product demo.

Sales

Speak to our sales team about plans, pricing, enterprise contracts, and more.