HIPAA
HIPAA: Health Insurance Portability and Accountability Act
HIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment.
Last verified Jul 17, 2026
Q&A
What is HIPAA?
HIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment.
Who needs HIPAA?
Any organization that creates, receives, maintains, or transmits protected health information for the US healthcare system: providers and health plans, and the SaaS and cloud vendors that serve them as business associates.
How long does HIPAA take?
HIPAA compliance is continuous. An initial risk analysis and remediation typically take a few weeks to a few months; an independent assessment can then be performed and refreshed periodically, commonly annually.
How much does a HIPAA audit cost?
Independent HIPAA assessment fees vary with scope and the state of your program. Pairing HIPAA with SOC 2 or pursuing HITRUST changes the cost profile; budget for remediation on top of assessment.
What does a HIPAA audit cover?
An independent assessor reviews your safeguards against the HIPAA Security Rule and related requirements, producing an attestation or gap report. It is an assessment against a regulation, not a government-issued certification.
What it is
HIPAA is US federal law that sets requirements for protecting individuals' health information. Its Security Rule, Privacy Rule, and Breach Notification Rule apply to covered entities such as healthcare providers and health plans, and to business associates, including SaaS vendors, that handle protected health information (PHI) on their behalf.
There is no official HIPAA certificate issued by the government; HHS does not certify compliance. Instead, organizations demonstrate compliance through an independent assessment against the HIPAA Security Rule, often documented as an attestation or gap assessment. Many vendors satisfy customer requirements by combining a HIPAA assessment with SOC 2, or by pursuing HITRUST, which maps to HIPAA.
Because enforcement is complaint- and breach-driven, the practical goal is a defensible, well-documented compliance program: risk analysis, safeguards, workforce training, and business associate agreements.
Any organization that creates, receives, maintains, or transmits protected health information for the US healthcare system: providers and health plans, and the SaaS and cloud vendors that serve them as business associates.
An independent assessor reviews your safeguards against the HIPAA Security Rule and related requirements, producing an attestation or gap report. It is an assessment against a regulation, not a government-issued certification.
HIPAA compliance is continuous. An initial risk analysis and remediation typically take a few weeks to a few months; an independent assessment can then be performed and refreshed periodically, commonly annually.
Independent HIPAA assessment fees vary with scope and the state of your program. Pairing HIPAA with SOC 2 or pursuing HITRUST changes the cost profile; budget for remediation on top of assessment.
No government credential exists for HIPAA. Choose assessors with demonstrable HIPAA Security Rule expertise and, ideally, HITRUST or SOC 2 experience for PHI environments. Be wary of anyone marketing an official "HIPAA certification". HHS does not issue one.
Service pathways
Not every service under this framework is fully available today. Hover a pathway for context.
- AvailableHIPAA risk assessment
- AvailableSecurity Rule / Privacy Rule gap audit
Find HIPAA auditors by region
Browse independent HIPAA auditors serving each region.