By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Who Certifies HIPAA Compliance?
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Technology > Medical Devices > Who Certifies HIPAA Compliance?
eHealthMedical DevicesMedical InnovationsMedical RecordsMobile HealthPolicy & LawTechnology

Who Certifies HIPAA Compliance?

tswann
tswann
Share
3 Min Read
HIPAA certification
SHARE

Who certifies HIPAA compliance?

The short answer is no one.

HIPAA certificationUnlike PCI, there is no one that can “certify” that an organization is HIPAA compliant. The Office for Civil Rights (OCR) from the Department of Health and Human Services (HHS) is the federal governing body here. And, HHS does not endorse or recognize the “certifications” made by private organizations.

Who certifies HIPAA compliance?

More Read

Telehealth Project from my UW SON Clinical Informatics class. Circa 2011
BIG-BIG-BIG: Company, Heart and Checkbook
Don’t Miss to Consider These 4 Digital Health App Trends
American Recall Center New Resource for Consumers [VIDEO]
Opiate Overdose Symptoms Families of Addicts Must Know
The Cost of Treating Uninsured Care – The Whistleblower Weighs In

The short answer is no one.

HIPAA certificationUnlike PCI, there is no one that can “certify” that an organization is HIPAA compliant. The Office for Civil Rights (OCR) from the Department of Health and Human Services (HHS) is the federal governing body here. And, HHS does not endorse or recognize the “certifications” made by private organizations.

There is an evaluation standard in the Security Rule § 164.308(a)(8), and it requires you to perform a periodic technical and non-technical evaluation to make sure that your security policies and procedures meet the security requirements. But, HHS doesn’t care if the evaluation is performed internally or by an external organization.

Having said all that, being evaluated by an independent, third party auditor is still a really good idea. Even though it is not official you should still do it. There are a number of great companies that can help. For example, Coalfire Systems (http://www.coalfire.com) and ComplySmart (http://www.complysmart.com) offer HIPAA Assessments.

Important. Even if you get a “certification” from an external organization HHS can still come in and find a security violation. Third party audits and “certifications” do not absolve you from your legal obligations under the Security Rule.

It is interesting to note that Texas was the first state in the nation to create a formal Covered Entity Privacy and Security Certification Program. The program was developed as part of Texas’ House Bill (HB) 300. The Texas Health Services Authority (THSA) and the Health Information Trust Alliance (HITRUST) have partnered to implement the Certification Program. They will tell you that the Texas state law protecting patients’ health information is more stringent than HIPAA. So in theory, if you are certified by the THSA, then you are ipso facto HIPAA compliant. Don’t hold me to that because HHS does not endorse or otherwise recognize this claim. But, considering the absence of a federal seal of approval this is a fantastic program and a step in the right direction.

(HIPAA / shutterstock)

TAGGED:HIPAA
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

new talent in nursing
The Fast-Track Paths Bringing New Talent Into the Nursing Workforce
Career Nursing
November 30, 2025
AI agents in healthcare
AI Agents in Healthcare: How Sully.ai’s Virtual Team is Transforming Hospital Operations
Hospital Administration Technology
November 26, 2025
hospitality jobs health benefits
The Health Benefits of J-1 Hospitality Careers
Career
November 23, 2025
healing care
Why Healing Spaces Depend On Healthy Building Systems
Infographics News
November 19, 2025

You Might also Like

The Cost of a Credentialing Mistake

October 29, 2015

Social Media Policies and “Spying” by Physicians

December 13, 2013

Yale Spinoff Licenses HER3 Cancer Drug from MedImmune

August 1, 2013
Mobile Health

EHR and Changing Healthcare Dimensions

September 28, 2012
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?