A regional hospital network is evaluating a software provider to host patient portal data in a public cloud deployment. The hospital's compliance policy mandates independent verification that the cloud vendor's security, confidentiality, and availability controls operate effectively over a continuous 12-month monitoring period. Which of the following attestation reports should the hospital request from the vendor?
- SOC 2 Type II reportAnswer
- BSOC 2 Type I report
- CSOC 1 Type II report
- DSOC 3 report
Answer
The hospital network should request a SOC 2 Type II report.
The SOC 2 Type II report aligns with the Trust Services Criteria (security, availability, confidentiality) and assesses whether controls were operating effectively throughout a specified testing window (such as 12 months).
Step-by-Step Solution
Key Concept
Distinguishing SOC Report Scope and Attestation Types