Digital Health
ISO 27001
SOC 2
Case Study: How a Digital Health Company Prepared for ISO 27001 and SOC 2 Together
A story-style case study on how one digital health company used internal audit, shared evidence, risk mapping, and a SharePoint ISMS workspace to prepare for ISO 27001 and SOC 2 together.
Case Study Note
This is a fictionalized composite case study based on common challenges faced by digital health and HealthTech companies preparing for ISO 27001, SOC 2, hospital security reviews, and client evidence requests. It is designed as an educational story, not as a claim about one specific client.
Quick Answer
Can a digital health company prepare for ISO 27001 and SOC 2 together?
Yes. A digital health company can prepare for ISO 27001 and SOC 2 together by building one control and evidence program.
The same internal audit can review risk management, access control, vendor reviews, cloud security, incident response, backups, logging, change management, AI governance, support ticket handling, corrective actions, and management reporting.
Bottom line: one mapped evidence program can support ISO 27001 readiness, SOC 2 readiness, hospital reviews, client questionnaires, and leadership decisions.
Canadian Cyber Digital Health Readiness Support
Prepare for ISO 27001 and SOC 2 Without Duplicating Work
Canadian Cyber helps digital health and HealthTech companies build one internal audit and evidence readiness program for both ISO 27001 and SOC 2.
We support patient data reviews, cloud evidence, vendor reviews, AI governance, access reviews, corrective actions, management reporting, and SharePoint ISMS workspaces.
The Starting Point
The digital health company was growing fast.
Its platform helped clinics manage patient intake, appointment workflows, provider communication, care coordination tasks, and follow-up documentation.
The product team was shipping new features. The sales team was speaking with larger healthcare buyers. The support team was handling more client tickets.
Then the security requests started arriving.
Buyers Asked For
The Company
The company was a mid-stage digital health vendor.
It served clinics, care teams, healthcare administrators, and provider organizations.
Its Platform Handled
The company was not careless. It had security controls. The problem was that evidence existed in pieces.
The Pressure Point
The company’s sales pipeline changed.
Smaller clients had accepted basic security questionnaires. Larger healthcare buyers did not.
The sales team needed faster answers. The security team needed better evidence. Leadership needed one plan.
Practical rule: when HealthTech buyers become larger, security evidence becomes part of the sales process.
The First Mistake: Treating ISO 27001 and SOC 2 as Separate Projects
At the beginning, the company created two folders.
One folder was called ISO 27001. The other was called SOC 2.
Soon, the same documents started appearing in both folders.
Access reviews, vendor records, policies, cloud screenshots, backup evidence, and incident response records were copied twice.
The better question became:
“What controls and evidence support both?”
The Shared Control Map
The team built a shared control map.
It connected ISO 27001, SOC 2, internal audit questions, evidence owners, and actual proof.
| Control Area | ISO 27001 Use | SOC 2 Use | Evidence |
|---|---|---|---|
| Access Control | ISMS access control evidence. | Logical access evidence. | Access reviews, MFA reports, offboarding records. |
| Vendor Risk | Supplier controls. | Vendor and subservice organization evidence. | Vendor register, risk reviews, contracts. |
| Incident Response | Incident management. | Incident response evidence. | IR plan, tabletop report, lessons learned. |
| Backup and Recovery | Availability and continuity controls. | Availability evidence. | Backup reports and restore tests. |
| Change Management | Controlled changes. | Change control evidence. | Change tickets and approvals. |
| Corrective Actions | Continual improvement. | Remediation evidence. | Finding tracker and closure proof. |
The Internal Audit Turning Point
The company decided to run an internal audit before chasing certification or SOC 2 readiness.
The goal was not to pass perfectly. The goal was to find gaps before clients, auditors, or hospital reviewers found them.
The Internal Audit Tested
Finding 1: Scope Was Not Clear Enough
The ISO 27001 scope described the business generally.
The SOC 2 system boundary described the platform differently.
This created confusion during evidence collection and hospital questionnaire responses.
What Internal Audit Found
- Support systems were not clearly included.
- APIs were not clearly included.
- AI tools were not clearly included.
- Vendor-supported services were unclear.
- Cloud architecture was not linked to the ISMS scope.
How They Fixed It
The company created one scope and boundary document.
It included the core platform, cloud infrastructure, databases, APIs, patient workflows, support ticketing, vendors, backups, logs, AI tools under review, and internal teams supporting the platform.
Practical rule: HealthTech companies should align ISO 27001 scope and SOC 2 system boundaries before collecting evidence.
Finding 2: Patient Data Flows Were Partly Informal
The company knew where the main application stored patient data.
But internal audit asked a wider question:
“Where else can patient data appear?”
Patient Data Could Appear In
The company built a patient data flow map.
The map became a single source of truth for hospital reviews, SOC 2 readiness, and ISO 27001 risk assessment.
Finding 3: Access Reviews Were Too Basic
The company had user access exports.
But exports alone did not prove review.
| What Was Missing | How They Fixed It |
|---|---|
| Reviewer sign-off. | Added reviewer, date, and approval fields. |
| Exception notes. | Tracked exceptions found and actions taken. |
| Removal evidence. | Linked removal tickets and screenshots. |
| Vendor users. | Included vendor and contractor access in review scope. |
Need to Prepare for ISO 27001 and SOC 2 Together?
Canadian Cyber helps digital health and HealthTech companies align internal audit, evidence mapping, SharePoint ISMS workspaces, patient data reviews, vendor access reviews, AI governance reviews, and corrective action tracking.
For senior advisory support, view Waqar Mehboob’s profile.
Finding 4: Vendor Evidence Was Collected but Not Reviewed
The company had vendor contracts and security reports.
But the internal audit asked who reviewed them, whether the scope was relevant, and whether follow-up actions were created.
The New Vendor Review Form Tracked
Practical rule: uploading a vendor report is not the same as reviewing vendor risk.
Finding 5: Backup Evidence Did Not Prove Recovery
The company had backup reports.
Backups were running.
But restore testing was not documented.
| Restore Test Field | Why It Helped |
|---|---|
| System tested | Showed which systems could recover. |
| Data type | Showed whether patient data systems were included. |
| Result | Showed whether the test passed or failed. |
| Follow-up action | Turned issues into corrective actions. |
Finding 6: Logs Were Collected but Not Reviewed
Cloud tools generated logs. Application systems generated logs. Admin actions generated logs. API systems generated logs.
But the evidence did not clearly show that logs were reviewed.
The New Log Review Process Defined
Finding 7: AI Tools Were Outside the Main Audit Scope
The company used AI in small ways.
Support used AI to draft response templates. Admin teams used AI for meeting summaries. Developers used AI coding assistance.
Product was also exploring AI-assisted workflow features.
The AI Governance Register Tracked
Finding 8: Corrective Actions Were Not Centralized
Audit notes were in one file. Security tasks were in another tool. Vendor follow-ups were in email.
There was no single corrective action view.
| Corrective Action Field | Purpose |
|---|---|
| Finding ID | Creates traceability. |
| Framework mapping | Shows whether ISO 27001, SOC 2, or both are affected. |
| Root cause | Helps fix the actual issue. |
| Closure evidence | Prevents findings from closing without proof. |
The SharePoint ISMS Workspace
The company already used Microsoft 365.
So it built a structured SharePoint ISMS workspace instead of using scattered folders, screenshots, email threads, and chat messages.
Libraries
- Policies and Procedures.
- Published Documents.
- ISO 27001 Evidence.
- SOC 2 Evidence.
- Patient Data Evidence.
- Vendor Evidence.
- AI Governance Evidence.
- Client-Ready Evidence Room.
Lists
- Risk Register.
- Statement of Applicability.
- SOC 2 Evidence Map.
- Vendor Register.
- AI Tool Register.
- Access Review Tracker.
- Corrective Action Tracker.
- Audit Calendar.
Practical rule: a SharePoint ISMS should not be a folder dump. It should be a structured evidence workspace.
The Management Review Moment
After internal audit, leadership finally had a clear view.
Compliance stopped looking like a document chase. It became a business readiness program.
Leadership Could See
The Outcome
The company did not become audit-ready overnight.
But within a focused readiness cycle, it made major improvements.
| Before | After |
|---|---|
| ISO 27001 and SOC 2 handled separately. | Shared evidence map for both frameworks. |
| Evidence stored in scattered folders. | SharePoint ISMS workspace. |
| Access exports without decisions. | Access tracker with sign-off and removals. |
| Vendor reports stored without conclusions. | Vendor review notes and risk ratings. |
| Backup reports only. | Restore test evidence. |
| AI tools informal. | AI governance register. |
| Corrective actions scattered. | Central tracker with verification. |
| Client reviews were stressful. | Client-ready evidence pack. |
Lessons for Other Digital Health Companies
Align ISO 27001 scope and SOC 2 system boundaries early.
Review support, vendors, logs, backups, APIs, and AI tools.
Do not collect the same evidence twice.
Access reviews should show decisions, removals, exceptions, and sign-off.
AI governance should not wait until external auditors ask.
Leadership needs visibility into risks, findings, owners, and blockers.
Practical Checklist
| Checklist Item | Ready? |
|---|---|
| Define ISO 27001 scope. | |
| Define SOC 2 system boundary. | |
| Map shared controls. | |
| Create one evidence register. | |
| Document patient data flows. | |
| Review support ticket data handling. | |
| Review access and privileged access. | |
| Review vendor and subprocessor risk. | |
| Review cloud security evidence. | |
| Review backup and restore evidence. | |
| Review AI governance evidence. | |
| Track corrective actions. | |
| Verify closure evidence. | |
| Prepare management review. |
How Canadian Cyber Helps
Canadian Cyber helps digital health and HealthTech companies prepare for ISO 27001 and SOC 2 together without duplicating effort.
We help organizations build one internal audit and evidence readiness program that supports certification readiness, SOC 2 readiness, hospital security reviews, and client trust.
Senior Advisory Support
Canadian Cyber also provides senior advisory support for digital health readiness, ISO 27001 internal audit, SOC 2 readiness, SharePoint ISMS workspaces, AI governance, corrective actions, and vCISO oversight.
Frequently Asked Questions
Can a digital health company prepare for ISO 27001 and SOC 2 together?
Yes. Many control areas overlap, including access control, vendor risk, incident response, backups, logging, change management, risk management, security awareness, and corrective actions. One internal audit program can support both when evidence is mapped clearly.
Is ISO 27001 the same as SOC 2?
No. ISO 27001 is an international information security management system standard. SOC 2 is an assurance report for service organizations based on controls relevant to trust services categories such as security, availability, processing integrity, confidentiality, and privacy.
What should HealthTech companies audit first?
They should start with scope, patient data flows, access control, privileged access, vendor risk, cloud security, incident response, backup and restore evidence, logging, change management, AI governance, and corrective actions.
Can the same evidence support ISO 27001 and SOC 2?
Yes. Access reviews, vendor reviews, incident response records, restore tests, log review tickets, risk registers, policies, security training, change tickets, and corrective actions can often support both frameworks when properly mapped.
Should AI tools be included in readiness work?
Yes. AI tools should be included when they affect patient data, clinical workflows, support tickets, admin workflows, product features, software development, or client data.
Why use SharePoint for evidence management?
SharePoint can help organize policies, evidence libraries, risk registers, access reviews, vendor records, AI governance records, corrective actions, and client-ready evidence packs using metadata, permissions, ownership, and dashboards.
Can Canadian Cyber help with both ISO 27001 and SOC 2?
Yes. Canadian Cyber helps digital health and HealthTech companies with ISO 27001 internal audits, SOC 2 readiness, evidence mapping, SharePoint ISMS implementation, AI governance reviews, cloud and vendor control reviews, corrective action tracking, and vCISO support.
Takeaway
The digital health company did not prepare for ISO 27001 and SOC 2 by creating two separate compliance programs.
It prepared by building one stronger security evidence system.
Internal audit helped the team see what was working, what was missing, and what needed proof.
The biggest lesson was simple: ISO 27001 and SOC 2 may be different frameworks, but many practical HealthTech controls overlap.
When controls are audited once, mapped properly, and stored in a structured evidence workspace, digital health companies can support certification readiness, SOC 2 readiness, hospital reviews, client questionnaires, and business growth.
Ready to Prepare for ISO 27001 and SOC 2 Together?
Canadian Cyber can help your digital health company prepare for ISO 27001 and SOC 2 without duplicating audit work.
We provide ISO 27001 internal audits, SOC 2 readiness assessments, evidence mapping, patient data reviews, cloud security reviews, vendor access reviews, AI governance reviews, SharePoint ISMS workspaces, corrective action tracking, vCISO services, ISO 42001 readiness, ISO 27017, ISO 27018, and cybersecurity assessments.
Stay Connected With Canadian Cyber
Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, SOC 2 readiness, digital health security, HealthTech evidence mapping, patient data protection, AI governance, SharePoint ISMS, cloud security, vendor risk, vCISO services, ISO 42001, ISO 27017, ISO 27018, and certification readiness.
