Compliance · US regulation
There's no such thing as a HIPAA certificate — there is a required risk analysis.
HIPAA governs how covered entities and business associates protect protected health information. It is a US law enforced by HHS OCR, not a certification scheme — and its Security Rule has one requirement organizations fail more than any other: an accurate, thorough risk analysis.
3
Core rules
Required
Risk analysis
BAA
Contract control
Three rules, and a set of safeguards that are deliberately technology-neutral.
The Privacy Rule governs use and disclosure of PHI, the Security Rule governs safeguards for electronic PHI, and the Breach Notification Rule governs what happens when it goes wrong.
Administrative (risk analysis, workforce training, sanctions), Physical (facility and device controls), and Technical (access control, audit controls, integrity, transmission security).
'Addressable' does not mean optional. It means implement it, or document why an alternative is reasonable. Treating addressable as ignorable is a common and expensive misreading.
Covered entities, and everyone handling PHI on their behalf.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We perform the accurate, thorough risk analysis the rule requires — the single most cited failure in OCR enforcement.
We close administrative, physical, and technical gaps, and document addressable decisions defensibly.
We find where ePHI actually lives — including the shadow copies in inboxes, laptops, and test environments.
We get business associate agreements in place and flowing down to subcontractors.
We build the detection, assessment, and notification process before you need it.
We handle training, sanctions policy, and the documentation OCR asks for first.
Find where protected health information lives and moves.
Run the required analysis and produce a risk management plan.
Implement safeguards and document addressable decisions.
Put BAAs in place across the chain.
Train, monitor, review, and keep evidence current.
No. HHS does not certify or endorse any HIPAA certification, and no vendor can make you officially certified. Third-party attestations of HIPAA alignment exist and have value in sales conversations, but compliance is demonstrated through your risk analysis, safeguards, and documentation — not a badge.
Failure to conduct an accurate and thorough risk analysis, over and over. It's the foundation the entire Security Rule builds on, and it's the first document requested in an investigation. If yours is stale or superficial, everything after it is exposed.
If you create, receive, maintain, or transmit PHI on behalf of a covered entity, yes — and that includes most SaaS and IT vendors serving healthcare, even if you never intentionally look at the data. Encryption doesn't exempt you, and neither does 'we just host it'.
HIPAA tells you what to achieve but not how; HITRUST CSF gives you a prescriptive, certifiable control set that maps to HIPAA. Many healthcare organizations require HITRUST from vendors precisely because HIPAA itself has no certification. If your customers are pressing for proof, HITRUST is usually the answer.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.