HIPAA Compliance
HIPAA is United States federal law enforced by the Department of Health and Human Services. No government body certifies anyone as HIPAA compliant, so this page sets out what the rules actually require and what defensible evidence looks like.
What HIPAA Is and Who Enforces It
The Health Insurance Portability and Accountability Act of 1996 is United States federal legislation. Its administrative simplification provisions gave the Department of Health and Human Services authority to issue the rules that people mean when they say HIPAA. The Health Information Technology for Economic and Clinical Health Act of 2009 extended direct liability to business associates and introduced federal breach notification, and the 2013 omnibus rule folded those changes into the regulations.
- The Privacy Rule governs the use and disclosure of protected health information and gives individuals rights over their records.
- The Security Rule applies to electronic protected health information and requires administrative, physical and technical safeguards.
- The Breach Notification Rule sets out who must be told after a breach of unsecured protected health information, and how quickly.
- The Enforcement Rule covers investigations, hearings and civil money penalties.
The Office for Civil Rights within the Department of Health and Human Services investigates complaints, conducts compliance reviews and imposes civil money penalties. Criminal matters are referred to the Department of Justice. State attorneys general may also bring civil actions on behalf of residents.
There Is No HIPAA Certification
Stated plainly, because it matters commercially: the Department of Health and Human Services does not certify, endorse or accredit any organisation, product or service as HIPAA compliant. There is no accreditation body, no accredited certification body, no two stage audit and no surveillance cycle. Any badge that reads HIPAA certified was issued by a private company against criteria it wrote itself.
What organisations do instead, and what buyers generally accept:
- An independent Security Rule risk analysis and risk management plan, refreshed on a defined cycle. This is the single piece of evidence the Office for Civil Rights asks for most often in investigations.
- A HITRUST assessment, which can incorporate HIPAA requirements as a regulatory factor and produces a certification under the HITRUST scheme rather than a government one.
- A SOC 2 examination performed by a licensed CPA firm, with HIPAA criteria mapped into the description of the system.
- ISO/IEC 27001 certification of the information security management system, used as the underlying control framework and supplemented with HIPAA specific policies.
Who Is Covered and What the Rules Require
Covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction. Business associates are organisations that create, receive, maintain or transmit protected health information on behalf of a covered entity, and they are directly liable under the Security Rule and parts of the Privacy Rule. Subcontractors of business associates are business associates in their own right.
The obligations that generate most of the work:
- Risk analysis. An accurate and thorough assessment of risks to the confidentiality, integrity and availability of electronic protected health information, across every system that holds it.
- Safeguards. Administrative measures such as workforce training, sanctions and contingency planning, physical measures such as facility access and device controls, and technical measures such as access control, audit controls, integrity and transmission security.
- Business associate agreements. Written agreements with every vendor that touches protected health information, flowed down to subcontractors.
- Minimum necessary. Uses and disclosures limited to the minimum necessary to accomplish the purpose, other than for treatment and a short list of exceptions.
- Individual rights. Access to records, amendment, an accounting of disclosures, restriction requests and confidential communications.
- Breach notification. Notice to affected individuals without unreasonable delay and no later than 60 days from discovery, notice to the Secretary of Health and Human Services, and notice to prominent media where a breach affects 500 or more residents of a state or jurisdiction.
How Univate Runs a HIPAA Engagement
- Scoping. Establish whether you are a covered entity, a business associate or both, and map every flow of protected health information including the ones that run through spreadsheets and email.
- Risk analysis. A documented assessment against the Security Rule safeguards, with likelihood and impact reasoning recorded so it stands up to scrutiny years later.
- Remediation. Policies, access control, encryption decisions and the documentation that supports them, audit logging, contingency planning and workforce training.
- Vendor management. Business associate agreement coverage, diligence on subcontractors and a register that is reviewed rather than filed.
- Assurance. Where a customer demands third party evidence, we prepare you for HITRUST, SOC 2 or ISO/IEC 27001 and are explicit about what each one does and does not say about HIPAA.
Points Worth Being Careful About
- A vendor questionnaire answered yes does not constitute a risk analysis. The Office for Civil Rights has repeatedly found the absence of a genuine, organisation wide risk analysis to be the root failure in enforcement actions.
- Encryption is an addressable specification, not an optional one. If you do not encrypt, you must document why and what you did instead.
- Business associate agreements do not transfer liability. You remain accountable for your own compliance regardless of what the contract says.
- The Office for Civil Rights published a notice of proposed rulemaking to strengthen the Security Rule on 6 January 2025. It has not been finalised, so current obligations remain those of the existing rule. Treat any product marketed as compliant with the new rule with caution.
- HIPAA is not a global privacy law. It does not cover most consumer health apps, employer held records or data held outside the covered entity and business associate relationship.
HIPAA Questions We Are Asked Most Often
Can an organisation become HIPAA certified?
No. The United States Department of Health and Human Services does not certify, endorse or accredit any organisation, product or service as HIPAA compliant, and no accreditation body oversees such a scheme. Certificates sold as HIPAA certification are private attestations issued against criteria the seller wrote.
What evidence do customers accept instead?
Most commonly an independent HIPAA Security Rule risk analysis and remediation plan, a HITRUST assessment that includes HIPAA as a regulatory factor, a SOC 2 report from a licensed CPA firm, or ISO/IEC 27001 certification used as the underlying control framework.
Are business associates directly liable under HIPAA?
Yes. Since the HITECH Act and the 2013 omnibus rule, business associates are directly liable for compliance with the Security Rule and with certain Privacy Rule provisions, and their subcontractors are business associates in turn.
How quickly must a breach be reported?
Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery. The Secretary of Health and Human Services must also be notified, immediately for breaches affecting 500 or more individuals and annually for smaller ones. Breaches affecting 500 or more residents of a state or jurisdiction also require notice to prominent media.
Does ISO 27001 satisfy HIPAA?
Not by itself. ISO/IEC 27001 provides a strong security management system and covers much of the Security Rule, but HIPAA also imposes Privacy Rule, breach notification and business associate obligations that fall outside the standard.
Tell us whether you are a covered entity or a business associate, what protected health information you touch and which customer is asking. We will scope a Security Rule risk analysis and a remediation plan you can evidence.
Related Services & Resources
Univate supports certification, assessment and compliance programmes for organisations operating across international markets. Talk to our team about scope, effort and the route that genuinely applies to your organisation.








