2026-09-21 · KeXinMaterials Editorial Team
SOC 2 Type 2 + HIPAA + GDPR SaaS / Medical Data Privacy Deep Dive Protective Case B2B Guide
SOC 2 Type 2 (SaaS / cloud trust services), HIPAA (US medical data privacy), GDPR (EU personal data) are the three primary data privacy standards. SOC 2 Type 2 attests to operating effectiveness over 6-12 months. HIPAA Privacy Rule + Security Rule + Breach Notification Rule cover US medical data. GDPR (EU) 2016/679 covers EU personal data + data subject rights + lawful basis + cross-border transfer. Below is the 2026 B2B procurement deep-dive covering scope, criteria, controls, attestation, certification, and protective case requirements.
SOC 2 Type 2 + Trust Services Criteria (TSC)
SOC 2 Type 1 + Type 2 per AICPA + Trust Services Criteria CC + A + PI + C + P. Five principles + 144+ controls.
SOC 2 Type 1: Point-in-time attestation. Auditor opinion on design of controls + their implementation as of a specific date. Faster (4-6 weeks). Suitable for initial assessment.
SOC 2 Type 2: Period attestation. Auditor opinion on design + implementation + operating effectiveness of controls over a period (typically 6 or 12 months). More rigorous + comprehensive. Required by most enterprise customers.
Trust Services Criteria (TSC) per AICPA 2017 + 2022 update: Five principles. (1) Security (Common Criteria CC). (2) Availability (A). (3) Processing Integrity (PI). (4) Confidentiality (C). (5) Privacy (P).
TSC Common Criteria (CC): 9 series (CC1 + CC2 + CC3 + CC4 + CC5 + CC6 + CC7 + CC8 + CC9). Control Environment + Risk Assessment + Communication + Information + Monitoring + Change Management + Logical + Physical + Recovery.
TSC CC1 Control Environment: Ethical values + commitment to competence + organizational structure + authority + responsibility + accountability + governance + HR practices.
TSC CC2 Communication + Information: Internal communication + external communication + information systems + quality information.
TSC CC3 Risk Assessment: Risk identification + risk analysis + risk evaluation + risk treatment + fraud risk.
TSC CC4 Monitoring: Ongoing monitoring + separate evaluations + internal audit + management review + investigation of deficiencies.
TSC CC5 Control Activities: Selection + development of controls + policies + procedures + responsibility + segregation of duties + technology infrastructure + technology controls.
TSC CC6 Logical + Physical Access Controls: Identification + authentication + authorization + access provisioning + access revocation + access review + encryption + physical access + visitor management + CCTV + intrusion detection.
TSC CC7 System Operations: Infrastructure + monitoring + configuration management + patch management + backup + recovery + incident response + vulnerability management + change management + capacity management.
TSC CC8 Change Management: Change authorization + change testing + change review + change documentation + segregation of duties.
TSC CC9 Risk Mitigation: Business interruption insurance + insurance + business continuity planning + disaster recovery + risk transfer.
TSC Availability (A): A1 (Capacity + Recovery + Backup + Environmental + Maintenance + Testing). Focus on availability commitments + system requirements.
TSC Processing Integrity (PI): PI1 (Definition + Capture + Processing + Output) + PI2 + PI3 + PI4 + PI5. Focus on processing integrity + accuracy + timeliness.
TSC Confidentiality (C): C1 (Confidential Information Identification + Protection + Disposal). Focus on confidentiality commitments + system requirements.
TSC Privacy (P): P1-P8 (Notice + Consent + Collection + Use + Retention + Disclosure + Quality + Monitoring + Enforcement). Focus on personal information commitments + system requirements.
SOC 2 + ISO 27001: Combined approach common. SOC 2 Type 2 attestation + ISO 27001 certification provides comprehensive trust services.
SOC 2 + ISO 27017 (cloud security) + ISO 27018 (PII in cloud): Combined for cloud SaaS / IaaS / PaaS services.
B2B relevance: For B2B SaaS / cloud / data center / BPO / third-party service organizations, SOC 2 Type 2 attestation is procurement requirement for enterprise customers + regulated industries.
HIPAA Privacy + Security + Breach Notification
HIPAA Privacy Rule + Security Rule + Breach Notification Rule + HITECH Act + enforcement. PHI + ePHI + BAAs + Business Associates.
HIPAA (Health Insurance Portability and Accountability Act): US federal law. Enacted 1996. Public Law 104-191. Privacy Rule + Security Rule + Breach Notification Rule + Enforcement Rule + HITECH Act (2009).
HIPAA Privacy Rule (45 CFR Part 164 Subpart E): Standards for protection of individually identifiable health information (PHI). Permitted uses + disclosures + patient rights + administrative requirements.
PHI (Protected Health Information): Individually identifiable health information. Includes demographic + health + payment + billing information + medical records + lab results + clinical notes.
HIPAA Privacy Rule Notice of Privacy Practices (NPP): Required notice provided to patients + members. Describes how PHI is used + disclosed + patient rights.
HIPAA Privacy Rule Individual Rights: Right to access PHI + right to amend PHI + right to accounting of disclosures + right to request restriction + right to confidential communications + right to opt out of fundraising.
HIPAA Security Rule (45 CFR Part 164 Subpart C): Standards for protection of electronic PHI (ePHI). Administrative + physical + technical safeguards.
HIPAA Administrative Safeguards (45 CFR § 164.308): Security management + workforce security + information access management + training + incident procedures + contingency plan + evaluation + business associate contracts.
HIPAA Physical Safeguards (45 CFR § 164.310): Facility access controls + workstation use + workstation security + device + media controls.
HIPAA Technical Safeguards (45 CFR § 164.312): Access control + audit controls + integrity + person authentication + transmission security.
Required safeguards per HIPAA Security Rule: Mandatory implementation. Audit controls + integrity + person authentication + transmission security.
Addressable safeguards per HIPAA Security Rule: Reasonable + implementation. Security awareness + training + access control + audit + authentication + encryption + transmission security.
HIPAA Breach Notification Rule (45 CFR §§ 164.400-414): Notify affected individuals + HHS Secretary + media (for breach affecting 500+ individuals) within 60 days. "Breach" defined per Rule.
Breach notification: Unsecured PHI compromised. Presumed breach unless risk assessment demonstrates low probability of compromise.
HITECH Act 2009: Strengthens HIPAA. Breach notification + business associate requirements + penalty tiers. Tier 1 (unknowing) $137-$68K per violation + Tier 2 (reasonable cause) $1.4M + Tier 3 (willful neglect corrected) $1.5M + Tier 4 (willful neglect uncorrected) $1.5M per violation + criminal penalties up to $250K + 10 years prison.
Business Associate (BA) per HIPAA: Person or organization that performs functions involving PHI on behalf of Covered Entity (CE). Examples: cloud service providers + SaaS + data processing + IT + accounting + legal + consultants + billing + cloud storage + SaaS vendors.
Business Associate Agreement (BAA) per HIPAA: Required contract between CE + BA. Defines BA obligations + safeguards + breach notification + PHI protection + audit rights + termination.
HIPAA + SOC 2 + ISO 27001: Combined approach common for medical SaaS / cloud / BPO. SOC 2 Type 2 + HIPAA Security Rule + ISO 27001 + BAA.
B2B relevance: For B2B protective cases containing PHI / ePHI + HIPAA-covered data, HIPAA Privacy + Security + Breach Notification + BAA + training + safeguards is procurement requirement for US medical data.
GDPR + ISO 27701 PIMS + CCPA + PCI DSS
GDPR (EU) 2016/679 + ISO 27701 PIMS + CCPA + PCI DSS v4.0+ global data privacy + payment security family.
GDPR (General Data Protection Regulation): EU Regulation (EU) 2016/679. Effective 25 May 2018. Replaces Directive 95/46/EC. EU-wide personal data protection.
GDPR scope: All organizations processing personal data of EU residents. Cross-border data transfer + DPO + data subject rights + lawful basis + accountability.
GDPR principles (Article 5): Lawfulness + fairness + transparency + purpose limitation + data minimization + accuracy + storage limitation + integrity + confidentiality + accountability.
GDPR data subject rights: Right to information + access + rectification + erasure (right to be forgotten) + restriction + portability + objection + automated decision-making + consent withdrawal.
GDPR lawful basis (Article 6): Consent + contract + legal obligation + vital interests + public task + legitimate interests. Special categories (Article 9) require additional condition.
GDPR special categories (Article 9): Racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data + health + sex life or sexual orientation. Generally prohibited unless explicit consent + specific conditions.
GDPR DPO (Data Protection Officer) (Article 37-39): Required for (1) Public authorities. (2) Organizations whose core activities require large-scale + systematic monitoring. (3) Organizations whose core activities involve large-scale processing of special categories.
GDPR DPIA (Data Protection Impact Assessment) (Article 35): Required if processing likely to result in high risk to rights + freedoms. Especially with new technologies + large-scale processing + systematic monitoring + sensitive data.
GDPR cross-border data transfer (Chapter V): Adequacy decision + Standard Contractual Clauses (SCCs) + Binding Corporate Rules (BCRs) + codes of conduct + certification mechanisms + derogations. EU-US Data Privacy Framework (DPF) 2023 successor to Privacy Shield.
GDPR fines: Up to EUR 20M or 4% global annual turnover (whichever higher). Tier 1 (max EUR 10M or 2% turnover) for procedural violations. Tier 2 (max EUR 20M or 4% turnover) for substantive violations.
GDPR Data Protection Officer (DPO) tasks: Inform + advise + monitor compliance + provide advice on DPIA + cooperate with supervisory authority + act as point of contact for supervisory authority + data subjects.
ISO/IEC 27701:2019: "Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines". PIMS (Privacy Information Management System). Aligned with GDPR.
ISO/IEC 27701 PIMS: Implementation + operation + monitoring + review + maintenance + improvement of PIMS. Aligned with ISO 27001 ISMS + Annex A extensions.
ISO/IEC 27701 + GDPR: ISO 27701 provides framework for implementing GDPR + other privacy laws. Controls mapped to GDPR Articles.
CCPA (California Consumer Privacy Act): California state law. Effective 1 January 2020. CCPA 2.0 (CPRA - California Privacy Rights Act) 2023. Consumer rights + business obligations.
CCPA scope: For-profit organizations meeting thresholds (annual gross $25M + 100K+ consumers + 50%+ revenue from selling personal info).
CCPA consumer rights: Right to know + right to delete + right to opt-out of sale + right to non-discrimination + right to limit use of sensitive PI (CPRA).
CCPA fines: Up to $2,500 per violation + $7,500 per intentional violation. Per California Privacy Protection Agency enforcement.
Other US state privacy laws: Virginia VCDPA (2023) + Colorado CPA (2023) + Connecticut CTDPA (2023) + Utah UCPA (2023) + Texas TDPSA (2024) + Oregon OCPA (2024) + many others.
PCI DSS v4.0 (March 2022): 12 main requirements + future-dated requirements April 2025.
PCI DSS 4.0 main: (1) Install + maintain network security controls. (2) Apply secure configurations to all system components. (3) Protect stored account data. (4) Protect cardholder data with strong cryptography during transmission. (5) Protect all systems + networks from malicious software. (6) Develop + maintain secure systems + software. (7) Restrict access to system components + cardholder data by business need to know. (8) Identify users + authenticate access to system components. (9) Restrict physical access to cardholder data. (10) Log + monitor all access to system components + cardholder data. (11) Test security of systems + networks regularly. (12) Support information security with organizational policies + programs.
PCI DSS compliance levels: Level 1 (6M+ transactions/year, full audit) + Level 2 (1M-6M, SAQ or full audit) + Level 3 (20K-1M, SAQ) + Level 4 (< 20K, SAQ).
Common B2B mistakes: (1) Missing HIPAA Privacy + Security + Breach Notification. (2) Missing GDPR + DPO + DPIA + lawful basis. (3) Missing CCPA + CPRA. (4) Missing PCI DSS v4.0. (5) Missing ISO 27701 PIMS. (6) Missing BAA for BA. (7) Missing cross-border data transfer mechanisms.
B2B recommendation: For B2B protective case with personal / medical / payment data, require HIPAA + GDPR + CCPA + PCI DSS + ISO 27701 PIMS + BAA + DPIA + lawful basis + data subject rights + breach notification + cross-border data transfer.
Key Takeaways
- SOC 2 Type 2 per AICPA is period attestation. Five Trust Services Criteria: Security (CC) + Availability (A) + Processing Integrity (PI) + Confidentiality (C) + Privacy (P). Required by enterprise customers for SaaS / cloud.
- HIPAA per US federal law. Privacy Rule + Security Rule + Breach Notification Rule + HITECH Act. PHI / ePHI. Penalties up to $1.5M per violation + criminal penalties. BAA required for Business Associates.
- GDPR per (EU) 2016/679. 7 principles + 7 data subject rights + 6 lawful bases + DPO + DPIA + cross-border data transfer. Fines up to EUR 20M or 4% global annual turnover.
- ISO/IEC 27701 PIMS aligned with ISO 27001 ISMS. Maps to GDPR. CCPA + CPRA. Many US state privacy laws (Virginia + Colorado + Connecticut + Utah + Texas + Oregon).
- PCI DSS v4.0 (March 2022) + future-dated April 2025. 12 main requirements. Levels 1-4 by transaction volume. Fines up to $100K/month + loss of merchant account.
- B2B recommendation: For B2B protective case with personal / medical / payment data, require HIPAA + GDPR + CCPA + PCI DSS + ISO 27701 + BAA + DPIA + lawful basis + data subject rights + breach notification + cross-border data transfer.
FAQ
q
a
q
a
q
a
q
a
q
a
q
a