hipaa.systems
Guide

HIPAA compliance certification for organizations

Can an organization or product be HIPAA certified? What the rule requires instead, what third-party assessments prove, and how to read a vendor's "HIPAA certified" badge.

HIPAA compliance certification for organizations at a glance

No organization can be officially "HIPAA certified": HHS does not certify covered entities, business associates or products. HIPAA instead requires each organization to periodically evaluate its own security compliance (45 CFR 164.308(a)(8)), which it may do internally or with an outside assessor. Seals, badges and third-party attestations such as HITRUST or SOC 2 reports can be useful evidence, but none is a government certification of HIPAA compliance.

Official certificationNone — HHS does not certify organizations or products
What the rule requiresPeriodic technical and non-technical evaluation, 45 CFR 164.308(a)(8)
Who can evaluateThe organization itself or an external assessor
Useful evidenceRisk analysis, policies, training records, BAAs, third-party audit reports
Vendor claimsAsk for the BAA and what it covers, not a badge

What HIPAA requires instead of certification

The Security Rule’s evaluation standard (45 CFR 164.308(a)(8)) requires covered entities and business associates to perform a periodic technical and non-technical evaluation of how well their security policies and procedures meet the rule — initially, and again when their environment or operations change. They can do it themselves or hire an outside assessor. Nothing in the rule turns that evaluation into a certification.

Even large cloud providers say so plainly: Microsoft’s HIPAA documentation notes that there is no certification standard approved by HHS for demonstrating HIPAA compliance by a business associate.

What third-party assessments can and can’t show

Evidence What it shows What it doesn’t
Your own risk analysis and evaluation That you assessed and addressed risks Independent assurance
External HIPAA assessment An outside view of gaps at a point in time Ongoing compliance or legal approval
HITRUST certification A mature, audited security program mapped to HIPAA An HHS certification
SOC 2 report Controls tested by an auditor against trust criteria HIPAA-specific obligations like BAAs or patient rights
“HIPAA compliant” seal or badge That someone sold a badge Anything on its own

Reading a vendor’s “HIPAA certified” claim

A badge doesn’t protect you. What does:

  1. A signed BAA — and knowing which plans and services it covers.
  2. Knowing what you still have to configure for the service to be used safely.
  3. Independent audit reports where the risk justifies asking for them.

Our HIPAA email services comparison shows how this looks for real products.

Next steps

Frequently asked questions

Can a company be HIPAA certified?

Not officially. HIPAA has no certification program. A company can show evidence of compliance — a risk analysis, policies, training records, BAAs and independent audit reports — but no one can grant it HIPAA certification.

Is HITRUST a HIPAA certification?

No. HITRUST is a private security framework and certification that maps to HIPAA among other requirements. It can be strong evidence of a security program, but it is not issued or recognized by HHS as HIPAA certification.

What should I ask a vendor that says it is HIPAA certified?

Ask whether it will sign a BAA, which plans and services the BAA covers, what you still need to configure, and whether it can share independent audit reports. Our tool pages answer these questions for specific products.