Harper
← All Posts

Insights

The Illusion of Certificates

SOC 2, HIPAA, and HITRUST are NOT vendor contract compliance. Many vendors incorrectly believe this, exposing their enterprise customers to massive hidden risk.

By Dominic CischkeFebruary 4, 20261 min read

The Illusion of Certificates

SOC 2, HIPAA, and HITRUST are NOT vendor contract compliance.

But many vendors (we've talked to) incorrectly believe this and it exposes their enterprise customers to massive hidden risk.

On the surface it's an easy misconception to form, but when you dig deep you find how stark the difference is.

The Difference

These certifications directly cover an extremely limited set of contract requirements.

And in most cases of any overlap, it is topical at best.

A prime (but certainly not unique) example of this is background check requirements.

The SOC 2 background check "requirement" is usually something along the lines of: "The company performs background checks on prospective personnel prior to their first day of work." That's it.

And how about the enterprise contract? I've personally managed contracts where just the personnel background check obligations are 3+ pages of full contract text naming incredibly specific check types and ongoing cadences.

Addressing Risk

When vendors solely trust in certifications, they're wildly out of compliance with MOST of the contract. And this is happening across vendors today.

When vendors think this way, their enterprise partners bear incredible risk too. And enterprises have few useful tools at their disposal to ensure these vendors are fully compliant.

Harper helps resolve this pervasive vendor misconception and provides enterprises with the granular visibility they need to manage vendor risk.

Harper integrates directly with your vendors to help them organize and track compliance with every exact contract requirement in a purpose-built platform.

Enterprise vendor compliance teams then have this real-time data available in their Harper instance to instantly oversee, analyze, and take action across the entire vendor network.

You've got more important work to do than reminding vendors of contract obligations and chasing vendor documents. Let Harper unlock your team to focus on their most important work.

Request a Demo

Frequently asked questions

Is SOC 2 the same as vendor contract compliance?
No. SOC 2 attests to a limited set of controls at a point in time. A vendor contract typically contains 150+ specific, ongoing obligations - background-check cadences, exclusion-list monitoring, insurance and additional-insured requirements, SLAs, and more - that a SOC 2 report does not cover.
Does HIPAA or HITRUST prove a vendor is compliant with its contract?
No. HIPAA and HITRUST address privacy and security safeguards, not the full scope of a commercial contract. Overlap with contract requirements is topical at best, so a certified vendor can still be out of compliance with most of its contractual obligations.
How can an enterprise verify true vendor contract compliance?
By tracking every discrete contract obligation as a monitored, evidence-backed task rather than relying on a certificate. Harper integrates with vendors to track each requirement and gives the enterprise real-time visibility into network-wide compliance.

Sources

  1. AICPA - SOC suite of services (SOC 2)
  2. U.S. HHS - HIPAA for Professionals
  3. HITRUST Alliance
  4. HHS OIG - Exclusions Program (LEIE)

About the author

Dominic Cischke

Co-Founder, Harper

Co-founder of Harper. Spent thousands of hours managing regional and national healthcare vendor contracts before building Harper to fix vendor compliance.

Other Posts

August 10, 2026 · Insights

Inside 540 Obligations Across Real Healthcare Contracts

Health plans and their vendors file real contracts with the SEC - including Omada's agreement with Cigna. We counted every binding clause in seven of them: 540 obligations across 49,892 words, and a CMS contract form that does not match the regulation it cites.

July 21, 2026 · Insights

You Already Have a CLM. Why Do You Need Harper?

A contract lifecycle manager tells you what you agreed to. It cannot tell you whether it is still true. That gap, between the signed contract and the live obligation, is the job Harper does, and the reason the two belong together.

July 14, 2026 · Insights

The Unexplored Frontier of Contract Compliance

The cost of building software has collapsed, and the number of vendors every organization must trust is about to reorder. Compliance is the bottleneck, and continuous contract enforcement is the frontier no one has claimed yet.

June 16, 2026 · Insights

What Vendor Contract Management Looks Like in a World With AI

For decades a contract has been a document you sign and file. With AI, it becomes a live system that knows its own obligations and whether they are being met - and the work inverts from reading everything to reviewing the exceptions.

May 5, 2026 · Product

Meet Harper

Vendor compliance is mostly reading contracts and chasing paper. Harper does both, so the person who owns it can stop keeping plates spinning.

February 2, 2026 · Insights

The Problem With Looming Audits

It's not a matter of if you'll get audited, but a matter of when. The problem lies at the very beginning: vendors lack proper tooling to organize compliance efforts.

January 28, 2026 · Company

Announcing Harper

We're excited to publicly announce Harper: a new way for health plans and systems to oversee, analyze, and boost vendor contract compliance.