By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Who Certifies HIPAA Compliance?
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Technology > Medical Devices > Who Certifies HIPAA Compliance?
eHealthMedical DevicesMedical InnovationsMedical RecordsMobile HealthPolicy & LawTechnology

Who Certifies HIPAA Compliance?

tswann
tswann
Share
3 Min Read
HIPAA certification
SHARE

Who certifies HIPAA compliance?

The short answer is no one.

HIPAA certificationUnlike PCI, there is no one that can “certify” that an organization is HIPAA compliant. The Office for Civil Rights (OCR) from the Department of Health and Human Services (HHS) is the federal governing body here. And, HHS does not endorse or recognize the “certifications” made by private organizations.

Who certifies HIPAA compliance?

More Read

Image
3 Best Health Care Tips – mHealth to Social Media Networking
Florida House Passes Medicaid Privatization Plan
What Do Patients Really Want? Part I
Searching Online for Health Information
Degenerative Disc Disease: Comparing Lumbar Artificial Disc Replacement to Spinal Fusion

The short answer is no one.

HIPAA certificationUnlike PCI, there is no one that can “certify” that an organization is HIPAA compliant. The Office for Civil Rights (OCR) from the Department of Health and Human Services (HHS) is the federal governing body here. And, HHS does not endorse or recognize the “certifications” made by private organizations.

There is an evaluation standard in the Security Rule § 164.308(a)(8), and it requires you to perform a periodic technical and non-technical evaluation to make sure that your security policies and procedures meet the security requirements. But, HHS doesn’t care if the evaluation is performed internally or by an external organization.

Having said all that, being evaluated by an independent, third party auditor is still a really good idea. Even though it is not official you should still do it. There are a number of great companies that can help. For example, Coalfire Systems (http://www.coalfire.com) and ComplySmart (http://www.complysmart.com) offer HIPAA Assessments.

Important. Even if you get a “certification” from an external organization HHS can still come in and find a security violation. Third party audits and “certifications” do not absolve you from your legal obligations under the Security Rule.

It is interesting to note that Texas was the first state in the nation to create a formal Covered Entity Privacy and Security Certification Program. The program was developed as part of Texas’ House Bill (HB) 300. The Texas Health Services Authority (THSA) and the Health Information Trust Alliance (HITRUST) have partnered to implement the Certification Program. They will tell you that the Texas state law protecting patients’ health information is more stringent than HIPAA. So in theory, if you are certified by the THSA, then you are ipso facto HIPAA compliant. Don’t hold me to that because HHS does not endorse or otherwise recognize this claim. But, considering the absence of a federal seal of approval this is a fantastic program and a step in the right direction.

(HIPAA / shutterstock)

TAGGED:HIPAA
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

file a police report after a car accident
Can Filing a Police Report Help with Medical Bills?
Policy & Law
November 2, 2025
Slips and falls can happen in the blink of an eye, often in spaces we believe to be safe. A brief moment of misstep
When a Simple Fall Becomes a Serious Health Concern
Health
November 1, 2025
How Setting Boundaries Helps Trauma Survivors Heal
Health
October 30, 2025
how to improve REM sleep
Unlock Better Sleep: How to Improve REM Sleep Naturally
Wellness
October 30, 2025

You Might also Like

Engage Your Patients and Members Where They Are – Not Where You Wish They Were

November 23, 2013
eHealthMedical Records

The AMA Will Release 335 CPT Code Updates Next Year

September 22, 2018

Startup Founder Reacquires His Patient Portal Business

August 27, 2013
lyme disease vaccine
Public Health

Lyme Disease Vaccine: Cautionary Tale or Opportunity for Renewed Activism?

October 4, 2013
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?