What SOC 2 Type II is
SOC 2 is a reporting framework from the American Institute of CPAs for companies that store or process customer data. An independent CPA firm examines the company's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is required in every SOC 2. The other four are chosen based on the service.
There are two types. A Type I report checks whether controls are suitably designed at a single point in time. A Type II report also tests whether those controls actually operated effectively across an observation period, using samples of real evidence. Type II is the stronger signal, because it shows the controls work day to day.
SOC 2 is not a HIPAA certification, and HHS does not recognize any HIPAA certification. A SOC 2 report does not replace a BAA or a HIPAA risk analysis. It is good evidence that a vendor runs mature security controls. Rivvi has a SOC 2 Type II report and also signs a HIPAA BAA.