HIPAA compliance certification for organizations
Can an organization or product be HIPAA certified? What the rule requires instead, what third-party assessments prove, and how to read a vendor's "HIPAA certified" badge.
HIPAA compliance certification for organizations at a glance
No organization can be officially "HIPAA certified": HHS does not certify covered entities, business associates or products. HIPAA instead requires each organization to periodically evaluate its own security compliance (45 CFR 164.308(a)(8)), which it may do internally or with an outside assessor. Seals, badges and third-party attestations such as HITRUST or SOC 2 reports can be useful evidence, but none is a government certification of HIPAA compliance.
| Official certification | None — HHS does not certify organizations or products |
|---|---|
| What the rule requires | Periodic technical and non-technical evaluation, 45 CFR 164.308(a)(8) |
| Who can evaluate | The organization itself or an external assessor |
| Useful evidence | Risk analysis, policies, training records, BAAs, third-party audit reports |
| Vendor claims | Ask for the BAA and what it covers, not a badge |
What HIPAA requires instead of certification
The Security Rule’s evaluation standard (45 CFR 164.308(a)(8)) requires covered entities and business associates to perform a periodic technical and non-technical evaluation of how well their security policies and procedures meet the rule — initially, and again when their environment or operations change. They can do it themselves or hire an outside assessor. Nothing in the rule turns that evaluation into a certification.
Even large cloud providers say so plainly: Microsoft’s HIPAA documentation notes that there is no certification standard approved by HHS for demonstrating HIPAA compliance by a business associate.
What third-party assessments can and can’t show
| Evidence | What it shows | What it doesn’t |
|---|---|---|
| Your own risk analysis and evaluation | That you assessed and addressed risks | Independent assurance |
| External HIPAA assessment | An outside view of gaps at a point in time | Ongoing compliance or legal approval |
| HITRUST certification | A mature, audited security program mapped to HIPAA | An HHS certification |
| SOC 2 report | Controls tested by an auditor against trust criteria | HIPAA-specific obligations like BAAs or patient rights |
| “HIPAA compliant” seal or badge | That someone sold a badge | Anything on its own |
Reading a vendor’s “HIPAA certified” claim
A badge doesn’t protect you. What does:
- A signed BAA — and knowing which plans and services it covers.
- Knowing what you still have to configure for the service to be used safely.
- Independent audit reports where the risk justifies asking for them.
Our HIPAA email services comparison shows how this looks for real products.
Next steps
- HIPAA email services →Tool
- Security risk analysis →Requirement
- Business associate agreements (BAAs) →Requirement
- HIPAA training requirements →Requirement
Frequently asked questions
Can a company be HIPAA certified?
Not officially. HIPAA has no certification program. A company can show evidence of compliance — a risk analysis, policies, training records, BAAs and independent audit reports — but no one can grant it HIPAA certification.
Is HITRUST a HIPAA certification?
No. HITRUST is a private security framework and certification that maps to HIPAA among other requirements. It can be strong evidence of a security program, but it is not issued or recognized by HHS as HIPAA certification.
What should I ask a vendor that says it is HIPAA certified?
Ask whether it will sign a BAA, which plans and services the BAA covers, what you still need to configure, and whether it can share independent audit reports. Our tool pages answer these questions for specific products.