Privacy

·

There is no such thing as a HIPAA certificate

No government agency issues one. Here is what HIPAA asks for instead, and what to ask a vendor.

You have probably seen the badge. A shield, a tick, and the words “HIPAA compliant”. It turns up on software websites, in sales decks, in the footer of an email. It looks like a certificate. It is not one, because there is no such thing.

Nobody issues it

The Department of Health and Human Services enforces HIPAA through its Office for Civil Rights. It does not certify products or companies. In its own guidance it says it does not endorse or otherwise recognize private organizations’ “certifications” under the Security Rule, and that such a certificate does not release anyone from their legal obligations.

Security audits are real. SOC 2 reports and ISO 27001 certificates exist, and they say useful things about how a company runs its systems. They are not HIPAA certificates. Nothing is.

What HIPAA asks for instead

HIPAA is not a badge. It is a set of duties that sit on your practice, and on anyone who handles patient information for you. The Security Rule asks a practice to evaluate its own safeguards regularly. That work is never finished, so it cannot be certified once and framed.

When a vendor creates, receives, keeps or sends patient information for you, the law calls them a business associate. You need a written contract with them, a business associate agreement. It says what they may do with the information and what they must do to protect it.

The contract does not stop at the vendor. If they pass patient information to another company, such as a host or a transcription service, that company is a business associate too, and the same kind of contract has to exist between them. A promise from the company you pay is only as good as the contracts behind it.

Ask these instead

“Are you HIPAA compliant?” invites a yes. These questions invite an answer.

  1. Will you sign a business associate agreement with my practice, and can I read it first?

  2. Which other companies touch my patients’ information, and does each one have a signed agreement with you?

  3. Where does the audio go, and is it kept after the note is written? For how long?

  4. If something goes wrong, how will you tell me, and how fast?

A vendor that answers these plainly, in writing, has told you more than any badge can.

Start free

Free forever on Mac. iPhone and iPad coming soon.

Get early access