TLDR: SOC 2 Type II is an independent audit that tests whether a vendor's security controls operated effectively across a period of months. HIPAA compliance is a legal obligation with no certifying authority, so what a vendor can offer is a signed Business Associate Agreement and evidence of the required safeguards.
Why does your software vendor's security become your problem?
Under HIPAA a lab handling protected health information is responsible for the vendors it shares that information with, through a Business Associate Agreement. A breach at your software provider is a breach involving your patients' data, and it is reportable.
The numbers make the point better than the principle does. In analysis of the HHS Office for Civil Rights breach portal, 35.8 percent of healthcare data breaches reported in 2025 originated at business associates rather than at providers themselves. Roughly a third of the problem arrives through vendors.
For a dental lab that is not an abstract risk. Case files carry patient identifiers, prescriptions, scans and clinical correspondence. If that sits in a vendor's cloud, the vendor's controls are part of your compliance posture whether or not anyone has looked at them.
What does SOC 2 Type II actually test?
A SOC 2 examination is performed by an independent CPA firm against the AICPA Trust Services Criteria. Type I checks whether controls are designed appropriately at a single point in time. Type II tests whether they actually operated effectively across a period, commonly three to twelve months.
The distinction between Type I and Type II is the whole value of the exercise and it is routinely blurred in sales conversations. Type I says the vendor has a policy. Type II says an auditor sampled evidence over months and found the policy was followed.
When a vendor offers you a SOC 2 report, ask four things:
- Type I or Type II? If it is Type I, it tells you far less.
- What observation period? A report covering three months is weaker evidence than one covering twelve, and a report whose period ended eighteen months ago is stale.
- Which Trust Services Criteria? Security is required. Availability, confidentiality, processing integrity and privacy are optional additions, and which ones were in scope matters.
- Were there exceptions? Reports list them. A report with noted exceptions and a remediation plan is often more informative than a clean one, because you learn how the vendor responds.
SmileShape has completed a SOC 2 Type II examination. Ask for the report under NDA and read the scope section rather than the logo.
Why HIPAA compliance cannot be certified
There is no government body or accredited scheme that certifies HIPAA compliance. The Department of Health and Human Services does not endorse certifications. What exists is a legal obligation, a set of required safeguards, and a Business Associate Agreement that puts the obligation in writing between you and your vendor.
This matters because "HIPAA certified" appears on a lot of vendor websites and means nothing in a strict sense. A vendor claiming it is either using shorthand for something real, which is fine, or does not understand the framework, which is not.
What you should actually ask for:
- A signed Business Associate Agreement. Not a promise to sign one later. The HHS sample BAA provisions are the reference point for what it should contain.
- Evidence of the administrative, physical and technical safeguards the Security Rule requires. A SOC 2 Type II report is usually the most efficient way to see this, which is why the two items travel together.
- Breach notification terms. How fast will they tell you, through which channel, and to whom.
- Subcontractor handling. Their cloud provider is your data's home too. Ask who else touches it.
SmileShape operates under HIPAA obligations and signs Business Associate Agreements with labs and clinics. That is the accurate version of the claim, and it is the version a diligence process can act on.
What neither one tells you
Neither is a statement about the product working well. SOC 2 covers security and operational controls. HIPAA covers the handling of protected health information. Whether the software is useful, whether it is a regulated device, and whether the output is any good are separate questions with separate evidence.
Labs sometimes read a SOC 2 badge as general assurance, and vendors rarely correct them. It is worth keeping the categories apart in your own evaluation, because a vendor can be excellent on one and unexamined on another.
For clinical software specifically, the device question is its own line of enquiry. SmartCAD is classified as a technician-operated design aid with mandatory human review, and it is not a diagnostic or treatment-planning tool. That is a different fact from its security posture and should be verified separately.
A short diligence sequence
- Request the SOC 2 report under NDA. Read the type, the period, the criteria in scope and the exceptions.
- Request the Business Associate Agreement and have whoever advises you on HIPAA read it, particularly the breach notification clause.
- Ask where data is stored, who the subcontractors are, and what happens to your data if you leave.
- Ask how access is controlled internally: who at the vendor can see a customer's case files, and what is logged.
- Keep the answers. Re-ask annually, because a SOC 2 report covers a period that ends.
Related reading
- a vendor security checklist for dental labs buying software
- how to evaluate AI-assisted denture design software
Frequently asked questions
What is the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether those controls operated effectively across a period, commonly three to twelve months. Type II is substantially stronger evidence.
Can a company be HIPAA certified?
No. There is no government or accredited body that certifies HIPAA compliance, and HHS does not endorse certifications. What a vendor can provide is a signed Business Associate Agreement and evidence of the safeguards the Security Rule requires.
Why does a dental lab need a Business Associate Agreement with its software vendor?
Because the vendor handles protected health information on the lab's behalf. The BAA is the written instrument that binds the vendor to HIPAA obligations and sets out breach notification terms.
How often do healthcare breaches come through vendors?
Analysis of the HHS Office for Civil Rights breach portal found 35.8 percent of healthcare data breaches reported in 2025 originated at business associates rather than at covered entities themselves.
Does SmileShape have SOC 2 Type II and sign BAAs?
Yes. SmileShape has completed a SOC 2 Type II examination and signs Business Associate Agreements with labs and clinics. Ask for the report under NDA and read the scope and observation period.
Sources
- AICPA, SOC 2 (System and Organization Controls) reporting framework
- HHS, Business Associate Contracts under the HIPAA Privacy Rule
- HHS Office for Civil Rights, Breach Portal (breaches affecting 500 or more individuals)
- HIPAA Journal, 2025 Healthcare Data Breach Report (analysis of the HHS OCR breach portal)