Digital Trust in Perinatal Healthcare and Aligning HIPAA, NIST, and SOC 2
- Aug 3
- 8 min read
Updated: 2 days ago
Motise Miles is a mental wellness advocate, holistic coach, and doula who guides the human race through healing with intuitive wisdom, Spiritual Alignment, and HIPAA-informed care, blending nurturing gardening principles, witty insight, and grounded confidence while encouraging others to water the mind and bloom with intention.
In healthcare, client data can include administrative records such as intake notes, birth preferences, grounding practices, vitals, health history, insurance details, and postpartum mental health evaluations. In doula work, those details may come forward in quiet moments, during an intake conversation, a late-night text about anxiety, a discussion about a prior birth experience, or a planning session about who should be present in the room. This information is uniquely sensitive and heavily protected because it often combines identity, family structure, mental health, trauma, and birth experiences in one record.

As maternal healthcare expands through digital health applications, virtual coaching platforms, Medicaid connected services, and integrated electronic health records, compliance must develop alongside care delivery. For a doula organization, privacy may show up in very ordinary choices, how an intake form is stored, who can see a client’s support plan, or how a referral is sent. Data protection becomes part of the care model itself, a way to preserve trust, reduce institutional risk, and safeguard the dignity of confidentiality between clients and doulas. Governance, risk, and compliance frameworks give healthcare organizations, technology developers, and community based care teams a practical structure for building systems that are resilient, auditable, and worthy of that trust.
One compliance mission, three trust frameworks
A comprehensive cybersecurity posture depends on understanding how HIPAA, NIST, and SOC 2 complement one another without serving the same purpose. HIPAA answers the legal question, “What protected health information must we safeguard, and what are we required to do?” NIST answers the implementation question, “How do we organize people, processes, and technology to reduce risk?” SOC 2 answers the assurance question, “Can we show partners and stakeholders that selected controls are designed and operating as intended?” Together, they move an organization from obligation to implementation to evidence.
The most effective way to read these frameworks is as a sequence rather than as separate compliance checklists. HIPAA establishes the legal duty to protect health information, NIST helps translate that duty into operating controls, and SOC 2 gives external stakeholders evidence that selected controls are functioning over time.
The legislative foundation of healthcare privacy dates to 1996, when the U.S. Congress passed the Health Insurance Portability and Accountability Act. The Health Information Technology for Economic and Clinical Health Act of 2009 later strengthened HIPAA’s privacy, security, enforcement, and breach notification structure during the shift from paper records to digital systems. HIPAA establishes administrative, physical, and technical safeguards, requires formal Business Associate Agreements when vendors handle protected health information, and sets notification obligations after breaches of unsecured protected health information. In practical terms, HIPAA creates the legal floor for privacy and security. It requires organizations to know where protected health information is stored, who can access it, how it is transmitted, and what must happen if it is compromised. However, HIPAA does not prescribe every technical design decision. It tells covered entities and business associates what obligations they must meet while leaving the detailed engineering design of those safeguards to implementation.
NIST as the technical blueprint
After HIPAA defines the compliance duties, healthcare organizations still need a practical way to turn those duties into reliable privacy practices. That implementation role is served by the National Institute of Standards and Technology, a nonregulatory agency of the U.S. Department of Commerce. NIST’s Cybersecurity Framework, first released in 2014 and updated through CSF 2.0 in 2024, provides a widely used model for organizing cybersecurity governance, risk management, and control assessment, including through related publications such as NIST Special Publication 800-53A. NIST is useful because it turns compliance requirements into a repeatable approach to daily practice that leaders, engineers, compliance teams, doulas, and care coordinators can understand together.
NIST helps convert legal and governance requirements into everyday security habits. Its CSF 2.0 core functions, Govern, Identify, Protect, Detect, Respond, and Recover, encourage organizations to move toward ongoing care for the systems that hold client information. In a maternal healthcare technology environment, these functions translate into concrete daily practices:
Govern: Assigning clear accountability for all privacy and cybersecurity decisions.
Identify: Maintaining visibility into which systems, vendors, records, devices, and workflows handle client information.
Protect: Implementing technical and administrative safeguards, including access limits, encryption, secure configurations, and workforce training.
Detect: Monitoring systems for unusual activity, such as repeated failed logins or unexpected downloads.
Respond: Executing structured plans to investigate incidents, communicate appropriately, and contain potential harm.
Recover: Restoring operational services efficiently while strengthening safeguards following a disruption.
Behind the scenes, system logs, application activity, and network alerts can be reviewed through centralized monitoring tools. These capabilities help teams notice potential problems earlier and respond in ways that better protect families, care teams, and the organization. Where HIPAA establishes the legal obligation, and NIST helps shape day-to-day protections, SOC 2 supplies the independent assurance often requested by health systems, payers, and other partners.
The American Institute of Certified Public Accountants developed SOC 2 reporting to evaluate controls at service organizations relevant to security, availability, processing integrity, confidentiality, or privacy. Through a SOC 2 examination, an independent CPA firm assesses whether scoped controls are suitably designed and, for Type II reports, whether they operate effectively over a defined review period. For emerging software platforms and specialized birth applications seeking integration with health system networks, a successful SOC 2 report can demonstrate that the organization is building privacy and security practices with care and consistency. SOC 2 helps a hospital, payer, partner, or community organization see that the platform is not merely promising to protect data, it has documented controls, tested processes, and evidence that those controls are being followed over time.
That sequence matters in perinatal health because one digital care model may involve clients, doulas, clinicians, care coordinators, billing teams, cloud vendors, and hospital systems. Each participant may have a different role in collecting, using, transmitting, or protecting sensitive information, so the organization needs the full progression, clear obligations, practical implementation, and credible evidence that protections are working.
Operationalizing governance across the care lifecycle
Operational governance is the human and administrative side of cybersecurity. It turns high-level requirements into daily routines that help care teams protect families consistently across the care lifecycle. In practice, this is the work that helps a team answer simple but important questions, "Who should see this note? How should this referral be sent? What should happen if a phone is lost or a password is shared?" Written policies state that only authorized users can view client records, and the operational program determines who approves access, how often permissions are reviewed, how staff is trained, and how questions or exceptions are handled with care.
Effective programs maintain a current inventory of executed Business Associate Agreements for cloud hosting providers, scheduling tools, messaging services, and third-party application programming interfaces that handle client data. Workforce training reinforces daily privacy practices by covering HIPAA requirements, state-specific privacy obligations, social engineering risks, and phishing defense. In this operational layer, the focus is supportive accountability, making sure responsibilities are clear, decisions are documented, and privacy practices can be repeated consistently without placing unnecessary burdens on the people providing care.
Engineering controls that preserve trust
Engineering controls are the behind-the-scenes safeguards that help carry governance decisions into the systems themselves. If operational governance decides who should have access, engineering determines how that access is granted, restricted, encrypted, monitored, and revoked. These safeguards reduce the risk of unauthorized exposure, interception, alteration, or loss of client records by building privacy expectations into the architecture of databases, applications, devices, and data exchanges.
Encryption protects data at rest across databases and mobile devices by making information unreadable without the proper safeguards in place. Secure transmission protects information in motion, such as when an intake form, referral, billing document, or claims-related file moves between a doula organization, a Medicaid system, a health plan, or a care partner. For Michigan doulas, the MDHHS Doula Initiative website is especially important because it connects families, doulas, and providers to the Doula Registry, Medicaid enrollment steps, billing guidance, continuing education resources, and policy updates. These details may sound administrative, but they support very human moments, a client completing a form from home, a doula reviewing birth preferences before a visit, or a care coordinator sending information to families. Centralized logging and audit trails help organizations document access, notice unusual activity, and respond if something does not look right. When these defenses operate together, they help make privacy promises real in the tools and workflows people use every day.
Security as a standard of compassionate care
Technical security and data privacy are part of client safety, emotional comfort, and organizational integrity. Perinatal care involves some of the most personal information a family may ever share, which makes privacy a necessary component of trauma-informed care. Trauma-informed systems aim to reduce fear, preserve choice, and avoid preventable harm. Cybersecurity supports that standard by mitigating the chance that sensitive stories, diagnoses, preferences, or support needs are exposed outside the circle of care.
As information moves from intake forms to virtual care portals, billing systems, and clinical databases, transparent data management helps clients understand how their information is collected, protected, and used. That clarity strengthens informed consent, improves confidence in digital tools, and gives care teams language for explaining privacy practices in ways families can understand. It also honors the trust families place in doulas and maternal health workers when they share details that may be difficult, private, or deeply personal.
In health organizations, security is not separate from compassionate care, it is one of the quiet ways care teams protect the people they serve. HIPAA helps define the responsibility to safeguard health information, NIST offers a practical path for building reliable protections, and SOC 2 can help demonstrate that those protections are being maintained over time. For doula organizations and community-based birth workers, these frameworks do not replace the human relationship at the center of care. Instead, they can support that relationship by helping teams handle sensitive information with consistency, transparency, and respect. When privacy practices are aligned with state requirements and thoughtful daily operations, digital care can protect both information and dignity. The heart of cybersecurity is creating systems that allow families to share vulnerable information with confidence, knowing their stories are being cared for as carefully as their health.
Follow me on Instagram for more info!
Motise Miles, Holistic Coach and HIPAA Compliance Analyst
Motise Miles is a mental wellness advocate, holistic coach, and doula who walks with the human race through healing, reminding individuals that balance, clarity, and Spiritual Alignment are birthrights. Rooted in nurturing gardening principles, she teaches others the power of grounding themselves like a flower while cultivating resilience. As a co-author of Mastering Mental Health Vol. 1, she shares insight on embracing sacred rarity through affirmations and reflective questions that support emotional processing and inner renewal. Known for her witty voice and grounded confidence, Motise encourages others to water the mind and bloom with intention.
References:
American Institute of Certified Public Accountants. (2022). SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy. AICPA & CIMA.
Joint Task Force Transformation Initiative. (2020). Assessing Security and Privacy Controls in Information Systems and Organizations (NIST Special Publication 800-53A, Revision 5). National Institute of Standards and Technology.
Michigan Department of Health and Human Services. (n.d.). MDHHS Doula Initiative. State of Michigan.
Michigan Department of Health and Human Services. (n.d.). Become a Medicaid Enrolled Doula. State of Michigan.
Michigan Department of Health and Human Services. (n.d.). Medicaid Information and Resources. MDHHS Doula Initiative Continuing Education. State of Michigan.
Michigan Department of Health and Human Services. (2024). Update to Medicaid Coverage of Doula Services (Policy Bulletin MMP 24-40). State of Michigan.
Michigan Department of Health and Human Services. (2022). Medicaid Coverage of Doula Services (Policy Bulletin MMP 22-47). State of Michigan.
Michigan Legislature. (2026). Michigan Compiled Laws § 330.1748: Confidentiality. State of Michigan.
National Institute of Standards and Technology. (2024). NIST Cybersecurity Framework 2.0: Resource & Overview Guide (NIST Special Publication 1299). U.S. Department of Commerce.
U.S. Department of Health & Human Services. (2013). Breach Notification Rule. Office for Civil Rights.
U.S. Department of Health & Human Services. (2025). Summary of the HIPAA Privacy Rule. Office for Civil Rights.
U.S. Department of Health & Human Services. (2026). Business Associates. Office for Civil Rights.










