SOC 2 for Healthcare Companies: A 2026 Guide
A complete 2026 guide to SOC 2 for healthcare companies. Learn how SOC 2 maps to HIPAA, prioritize Trust Services Criteria, and prepare for your audit.
By Peter Korpak · Reviewed against our methodology · Last updated
Last verified · how we verify
Thoropass is a specialist SOC 2 audit firm in New York, NY, USA that charges $25K–$70K for Type II audits with 4–10 month timelines. Founded in 2019, they hold 8 accreditations and specialize in B2B SaaS, FinTech, HealthTech, and 2 more. Their pricing is above average compared to the specialist average of $18.491K–$52.655K.
Free. Anonymous until you pick.
Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.
of Specialist firms charge more for Type II
of Specialist firms have longer minimum timelines
certifications (tier avg: 4)
Side-by-side pricing, timeline, and certification counts for the 5 closest-priced peers in the specialist tier.
| Thoropass | Prescient Security | Moore Kingston Smith | Accedere | Audit Advantage Group | CAS Assurance | |
|---|---|---|---|---|---|---|
| Type II Cost | $25K–$70K | $20K–$75K | $25K–$70K | $25K–$70K | $25K–$70K | $25K–$70K |
| Type I Cost | $15K–$50K | $12K–$35K | $15K–$50K | $15K–$50K | $15K–$50K | $15K–$50K |
| Timeline | 4–10 mo | 3–9 mo | 3–9 mo | 4–10 mo | 4–10 mo | 4–10 mo |
| Team Size | 200-250 | 300–400 | 5–15 | 20–200 | 20–200 | 20–200 |
| Certifications | 8 | 17 | 3 | 3 | 1 | 2 |
| Founded | 2019 | 2018 | 2016 | 2017 | 2015 | 2018 |
For buyers in B2B SaaS and FinTech, Thoropass fits the specialist profile when timeline (4–10 months) and Type II pricing ($25K–$70K) align with what specialist firms typically deliver. Their 8 active accreditations — including CPA Firm (Laika Compliance LLC dba Thoropass Assurance), PCI DSS QSAC, HITRUST Authorized External Assessor — extend that fit beyond pure SOC 2 into adjacent compliance frameworks.
First-time SOC 2 / ISO 27001 / HIPAA / PCI / HITRUST seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit, eliminating the handoff between Vanta/Drata-style automation and a separate CPA firm. Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle. Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing.
The only end-to-end cybersecurity auditor. Bundles a proprietary GRC platform with in-house CPA, PCI QSAC, and HITRUST assessor under one roof. Same auditor from Day 1 through report issuance (no handoff between readiness vendor and audit firm). First Pass AI pre-screens evidence, cutting secondary auditor requests up to 80%. 1,000+ customers, 500+ audits annually, $98M raised through Series C (Fin Capital led). AICPA Peer Review 'Pass' rating (achieved twice, most recently December 2025). Inc. 5000 honoree for 2nd consecutive year (351% three-year growth). Founded 2019; rebranded from Laika in March 2023.
of 5 criteria match. Get a personalized quote
Thoropass is the rare compliance vendor that owns both ends of the SOC 2 problem: the GRC platform you use to prepare for the audit, AND the licensed CPA firm that signs the audit report. Most of the market splits these roles (Vanta/Drata/Secureframe handle automation and refer you to a separate auditor like Schellman or A-LIGN). Thoropass argues that handoff is the friction.
Founded in 2019 and rebranded from Laika in March 2023, Thoropass is headquartered in New York with an EMEA hub in London. The firm has raised $98M across four rounds (most recently a $50M Series C led by Fin Capital in November 2022, with J.P. Morgan Growth Equity, Centana, and Canapi participating). It now serves 1,000+ organizations, completes 500+ audits annually, and was named to the Inc. 5000 for a second consecutive year in 2025 with 351% three-year growth.
The licensed audit firm is Laika Compliance, LLC dba Thoropass Assurance, registered with the AICPA and recently the recipient of an AICPA Peer Review “Pass” rating for the second time (December 2025). Thoropass is also a PCI QSA Company (QSAC) and an AICPA Authorized HITRUST External Assessor, claiming to be the first automated compliance solution to earn HITRUST assessor status.
This is the core of Thoropass’s positioning. Three things follow from owning both sides:
Same auditor from Day 1 to the stamp. No transition meeting from your readiness vendor to a separate audit firm. The auditor who scopes your environment is the same one signing the report.
First Pass AI pre-screens evidence. Launched in January 2025, this AI layer programmatically checks evidence completeness and accuracy before it reaches the auditor. Thoropass claims this cuts secondary auditor requests up to 80% and reduces manual QA time by 95%.
Shared evidence across frameworks. SOC 2 + ISO 27001 + PCI + HITRUST use the same control set with one collection cycle. For companies pursuing two or more frameworks, this eliminates redundant evidence work.
The platform also supports companies who don’t want to switch GRC tools. Since 2025, the audit module is available standalone for customers already on Vanta, Drata, or Secureframe, and the platform offers “Our GRC or yours” interop.
The AICPA issued a Peer Reviewer Alert in December 2022 about self-review threats when compliance automation platforms also have audit affiliates. Thoropass has addressed this publicly: evidence flows through standardized APIs reviewed and approved by auditors before deployment, and the licensed CPA firm operates under AICPA Code of Professional Conduct standards. They’ve now passed two AICPA peer reviews with the “Pass” rating, the highest available.
This matters because the rest of the market sometimes raises independence concerns about platform-plus-audit firms. Two peer review passes (2022 and 2025) is the strongest counter-evidence available.
Thoropass markets coverage across 30+ frameworks total with control-mapping that lets a single evidence set satisfy several reports.
Worth noting what’s missing: no FedRAMP capability, no StateRAMP, no CMMC Level 2 C3PAO status. Companies targeting federal authorizations will need a 3PAO partner.
Sam Li, Co-Founder & CEO. UVA Computer Science, Harvard MBA. Previously co-founder and CTO of Zinc Platform (YC-backed insurtech), with stints at Google, Goldman Sachs, and Cambridge Associates. Named a 2026 EY Entrepreneur Of The Year New York finalist.
Eva Pittas, Co-Founder, President & COO. Spent 20+ years at Citigroup as Managing Director of IT Risk & Control and Vendor Management for the Institutional Clients Group. Founded BRCG, a boutique fintech compliance consultancy, before Laika/Thoropass. NYU Stern.
Austin Ogilvie, Co-Founder & Executive Chairman. Background in data science and ML, previously at Alteryx.
Dicken Chaplin, CFO. Joined December 2022. Previously CFO at Turbonomic, where he grew revenue from $20M to $200M+, leading to a $2B acquisition by IBM.
Leith Khanafseh, Managing Partner, Assurance & Compliance Products. Previously led infosec audits at Coalfire for major cloud service providers, plus Big 4 experience.
Chris Biero, Senior Director, Head of SOC. 10+ years in GRC across startups and Fortune 500 firms.
Thoropass does not publish a rate card. Aggregated third-party data:
Pricing model is annual subscription, custom-quoted, tiered by frameworks pursued, company size/complexity, and support level. The platform-plus-audit bundle is the most common engagement, but the audit module is also sold standalone for companies already on a different GRC tool.
Thoropass markets “SOC 2 in weeks, not quarters” with 62% faster time to audit completion vs. traditional process. Customer-reported timelines back this up:
The firm reports 80%+ of technical control evidence is auto-collected via integrations, and the First Pass AI layer reduces audit overhead by ~80%.
Named customers from public case studies:
G2 rating: 4.7/5 across 435+ reviews, with 74.7% in the Small-Business segment.
Critical feedback from G2 reviews surfaces a recurring set of complaints: UI can be clunky, limited bulk-edit options, occasional integration breakage, and slower performance at scale. Buyers weighing Thoropass should pressure-test the workflow against their specific cloud stack before committing.
Thoropass occupies a category of one in the SOC 2 market: the only company that ships a GRC platform AND signs the audit report. For first-time buyers pursuing multiple frameworks who value speed and fixed pricing over brand prestige, the bundle is compelling and the AICPA Peer Review track record answers the obvious independence question.
Where it gets tighter: if you already love your current GRC tool, the standalone audit module is a viable path, but you lose the workflow advantages that justify the bundle. If your buyers demand a Big-4 brand on the audit report, Thoropass is the wrong choice. And if you’re heading toward FedRAMP or CMMC Level 2 in the next 12-18 months, you’ll need a different partner anyway.
For early-to-mid-stage SaaS, fintech, and healthtech with one vendor needed, fast turnaround required, and predictable fixed pricing preferred, Thoropass is one of the most differentiated options in the specialist auditor market.
"Some of the best money I ever spent. Thoropass and being compliant ended up helping us close our second-largest customer."
"Thoropass combines readiness, evidence management, and auditor interaction in a single platform. The ability to collaborate with the auditor directly in-platform reduces friction and prevents duplicative work."
"For the past month, we've told our customers we're in the process of getting our SOC 2 and ISO 27001. Having the reports in our hands alleviates any concern from our customers."
"With no prior knowledge, Thoropass laid out an easy-to-understand road map. Setting attainable goals with reasonable timetable made the process extremely easy with multiple team members."
5 industries — Specialist average: 5
8 certifications — Specialist average: 4
Thoropass Audit Lifecycle Platform (First Pass AI, Trust Center, Access Review Automation, 100+ integrations)
Thoropass SOC 2 Type I audits typically range from $15K to $50K. Type II audits range from $25K to $70K. This is above average for specialist firms — the specialist tier average is $18.491K–$52.655K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.
A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.
Tell us your scope. Thoropass replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.
Want to compare first? See 55 similar specialist firms · or have us get 3 quotes instead
A complete 2026 guide to SOC 2 for healthcare companies. Learn how SOC 2 maps to HIPAA, prioritize Trust Services Criteria, and prepare for your audit.
SOC 2 for fintech: which TSC apply, what auditors focus on for payment data, and how a clean report unlocks enterprise deals.
Best SOC 2 compliance software for fintech in 2026. Compare platforms that cover SOC 2 + PCI-DSS + SOX — built for neobanks, payment processors, and BaaS.