HIPAA · COMPLIANCE PROCESS
HIPAA has no certificate and no pass mark. It has a process you run, write down, and produce for a federal regulator six years later. Here is that process, and the one step OCR keeps finding missing.
TL;DR
HIPAA compliance is a documented process, not a certificate. You map where patient data lives. You run a written risk analysis and fix what it finds. You sign business associate agreements up and down your supply chain. Then you keep the records for six years. If you handle that data for a healthcare customer, you answer to the Office for Civil Rights yourself. Your customer does not have to audit you first.
Sources: HHS Office for Civil Rights · Federal Register, 28 January 2026 · Unified Agenda, 2026
What HIPAA compliance means when you are the vendor #
Two kinds of company carry HIPAA duties. A covered entity is a provider, a health plan, or a healthcare clearinghouse. A business associate is anyone who handles protected health information on a covered entity’s behalf.
If you sell software, hosting, analytics, billing, transcription, or support to a clinic or an insurer, you are the second kind. Most technology companies reading this are business associates and do not think of themselves that way.
The distinction used to decide who got fined. Before 2009, OCR could act only against the covered entity, so your customer carried your risk. The HITECH Act made business associates directly liable that year, and the 2013 Omnibus Rule put the details into regulation. OCR now enforces against business associates as a matter of routine, and the list of what you answer for is public.
The ten duties you answer for yourself #
HHS publishes the exact list. A business associate carries direct liability for each of these, with or without a contract in place.
- Impermissible uses and disclosures. Any use of PHI the Rules or your agreement do not allow. 45 CFR 164.502(a)(3)
- The Security Rule in full. Administrative, physical, and technical safeguards, plus the documents behind them. 45 CFR 164.306 through 164.316
- Breach notification. Telling the covered entity, and telling other business associates in the chain. 45 CFR 164.410
- Minimum necessary. Limiting PHI to what the task in front of you needs. 45 CFR 164.502(b)
- Subcontractor agreements. A signed BAA with every subcontractor that touches PHI. 45 CFR 164.502(e)(1)(ii)
- Subcontractor oversight. Acting when a subcontractor breaks its agreement. 45 CFR 164.504(e)(1)(iii)
- Electronic copies of PHI. Handing ePHI to the covered entity or the individual when the Rule calls for it. 45 CFR 164.502(a)(4)(ii)
- Accounting of disclosures. Producing the log when someone asks for it. HITECH Act section 13405(c)(3)
- Cooperation with OCR. Records, compliance reports, and access during an investigation. 45 CFR 160.310
- No retaliation. Against anyone who files a complaint or helps an investigation. 45 CFR 160.316
Read item two again. The whole Security Rule sits on you, at the same standard as the hospital you serve.
A signed BAA is a contract, not a control #
Teams treat the business associate agreement as the finish line. It is the starting gun. The BAA is your promise to run the safeguards. OCR turns up to check whether you ran them, and the contract you signed becomes the measure of the gap.
The same logic runs downhill. Your hosting provider, your log aggregator, your offshore support desk, your AI transcription vendor. Each one that touches PHI needs its own BAA with you, signed before the data moves. The chain does not stop at your edge.
The process, in six steps #
Nothing in HIPAA lays out a numbered method. The Security Rule states outcomes and leaves you to reach them. This is the sequence that survives an OCR investigation, drawn from what the Rule requires and what the enforcement record shows.
Map where PHI lives #
Goal: name every system, service, and person that touches protected health information.
You cannot protect data you cannot locate. Write down each application, database, backup, log store, laptop, and third party in the path. Record how PHI enters, where it rests, and where it leaves.
What goes wrong: shadow copies. A support engineer’s CSV export, a test database seeded from production, an object storage bucket nobody owns. These surface during breach investigations, never during planning.
Run a written risk analysis #
Goal: a document naming each threat, each vulnerability, and the risk level you assigned to it.
45 CFR 164.308(a)(1)(ii)(A) requires this, and it is the foundation every other safeguard rests on. HHS offers a free Security Risk Assessment Tool. NIST SP 800-66 Revision 2 maps every Security Rule standard to concrete controls. It landed on 14 February 2024.
What goes wrong: teams submit a vendor questionnaire, a controls checklist, or a vulnerability scan report and call it done. None of those is a risk analysis. OCR has now said so in twelve separate enforcement actions.
Manage the risks you found #
Goal: bring each risk to a reasonable level, and record why you stopped where you stopped.
The Security Rule splits its implementation specifications into required and addressable. Addressable has never meant optional. It means one of three things. You put the control in place. You put an equal control in place and write down why. Or you record why neither one fits your size and setup.
What goes wrong: engineers read addressable as skip, and the decision leaves no trace. A control you chose not to implement, with no written rationale, reads to an investigator as a control you forgot.
Write the policies, train the people, sign the agreements #
Goal: the safeguards exist on paper and in the workforce, not only in the platform.
Name a security official who owns this. Train every person who touches PHI, and keep the attendance record. Write a sanction policy and use it. Sign subcontractor BAAs before data moves, not at renewal.
What goes wrong: a policy set bought from a template vendor that describes a hospital ward. An investigator reads your access control policy, then reads your access logs, and the two describe different companies.
Build the breach response you will need at 2am #
Goal: detect, assess, and notify inside the clock, starting from the day you discover the problem.
HIPAA treats any impermissible use or disclosure as a breach unless you show a low probability of compromise. You show that through four factors. What kind of PHI went out. Who received it. Whether anyone acquired or viewed it. And how far you cut the risk. Then the clock runs. A business associate tells the covered entity without unreasonable delay. The outer limit is 60 calendar days from discovery.
What goes wrong: waiting for certainty. The presumption runs against you, so the investigation and the notification happen in parallel, not in sequence.
Review, update, and keep everything for six years #
Goal: documents that still describe your company on the day OCR asks for them.
45 CFR 164.316(b)(2)(i) sets the retention period at six years from the date a document was created or last in effect, whichever falls later. The Rule also tells you to review and update documents in response to operational or environmental changes.
What goes wrong: a risk analysis from 2021 describing a stack you retired in 2023. It fails on accuracy, and it hands OCR the evidence that you knew the process existed and let it lapse.
The step everyone skips is the step OCR audits #
In late 2024 OCR started a focused enforcement push it calls the Risk Analysis Initiative. Twelve enforcement actions have followed. Every one turns on the same finding. The company failed to conduct an accurate and thorough assessment of the risks to its ePHI.
Not a weak password policy. Not a missing firewall rule. The paperwork step in front of all of it.
What the MMG Fusion case shows a vendor #
MMG Fusion, a Maryland software company, held PHI for dental and medical practices. In December 2020 an intruder reached its systems. The haul covered about 15 million people: names, phone numbers, addresses, dates of birth, and appointment details. The data then surfaced on the dark web. OCR opened its investigation in March 2023.
OCR found three failures. MMG never ran an accurate and thorough risk analysis. It never safeguarded the PHI it held. And it never told the covered entities whose patients it had exposed.
“When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery.”
Paula M. StannardDirector, HHS Office for Civil Rights
The settlement came to $10,000, because OCR weighed the company’s financial condition. Do not read that as a price list. Read the rest of the agreement. MMG accepted three years of federal monitoring under a corrective action plan. That means three years of handing policies, risk analyses, and training records to a regulator on demand. That is the real cost, and no insurance policy covers it.
The third failure is the one worth sitting with. Notifying the covered entity is the duty a business associate cannot push onto anyone else. Your customer cannot warn their patients until you warn your customer.
| Culpability tier | Minimum per violation | Maximum per violation | Annual cap |
|---|---|---|---|
| Did not know, and reasonable diligence would not have found it | $145 | $73,011 | $2,190,294 |
| Reasonable cause, not willful neglect | $1,461 | $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
What a failure costs #
HHS adjusts these figures for inflation every January. The amounts above took effect on 28 January 2026 and apply to penalties OCR assesses on or after that date. All figures are USD.
Two details in that table decide your exposure. The first is the phrase per violation. One missing safeguard across ten thousand records can count as many violations, subject to the annual cap for that provision. The second is the tier structure. Your penalty band turns on what you knew, and willful neglect covers what you should have known through reasonable diligence.
How a company lands in the top tier
An out-of-date risk analysis is the usual route. You ran one, so you knew the obligation. You let it go stale, so you stopped exercising diligence. That combination reads as willful neglect, and the floor for an uncorrected finding starts at $73,011 per violation.
The 2027 rule everyone is planning around #
OCR issued a proposed overhaul of the Security Rule on 27 December 2024, and it would be the first substantial rewrite since 2013. Coverage treated it as imminent. It is not.
The federal Unified Agenda now projects July 2027 for the final rule. Until then the current Security Rule stays in force, word for word, and HHS says so on its own NPRM page. Any plan built around a 2025 or 2026 compliance deadline for the new requirements rests on nothing.
That does not make the proposal useless. It makes it a roadmap instead of a deadline. Most of what OCR proposes reflects what healthcare buyers already demand in procurement, so the work pays for itself before the rule lands.
| Proposed requirement | Status under today’s rule | Worth doing now |
|---|---|---|
| Written asset inventory and network map, reviewed each year | Implied by the risk analysis, not named | Yes |
| Multi-factor authentication, with limited exceptions | Addressable under access control | Yes |
| Encryption of ePHI at rest and in transit | Addressable | Yes |
| Vulnerability scans every six months, penetration test each year | Not required | Yes |
| Restore critical systems and data within 72 hours | Contingency plan, no stated time | Yes |
| End of the required and addressable split | Split still applies | No change if you documented your decisions |
| Written certification every 12 months by a subject matter expert | Draft only | Wait for the final text |
The scanning and testing line deserves a note. A twice-yearly vulnerability scan and a yearly penetration test already appear in most healthcare vendor questionnaires. You will do this work for your sales cycle long before OCR asks for it.
There is no HIPAA certificate, so what do you send the customer? #
This is where the honest answer costs a vendor money, so most guides skip it. HHS has answered the question for over twenty years, in plain words.
“No, there is no standard or implementation specification that requires a covered entity to ‘certify’ compliance.”
U.S. Department of Health and Human ServicesHIPAA Security Rule FAQ
HHS goes further in the same answer. It does not endorse or recognize private certifications. Holding one does not release you from your legal duties. And a certificate from an outside firm does not stop HHS from finding a violation later.
So a badge reading HIPAA Certified carries no regulatory weight. Healthcare buyers worked this out years ago, which is why their security reviews ask for something else.
SOC 2 Type 2 with HIPAA mapping
A SOC 2 report tests the same administrative and technical safeguards the Security Rule demands, over an observation window, by a CPA firm. Map your criteria to the Security Rule standards and one audit serves both audiences. The difference between Type 1 and Type 2 matters here, because healthcare buyers ask for the window.
ISO 27001 plus a HIPAA gap assessment
Better fit when you sell across borders. ISO 27001 gives you a certified management system that European and Canadian buyers recognize, and its risk assessment satisfies the discipline HIPAA asks for. Add a gap assessment against the Security Rule to cover the parts ISO does not name.
A HIPAA attestation or readiness letter
An assessor reviews your safeguards against the Rule and writes what they found. Cheaper and faster than an audit, and honest as long as you call it what it is. It carries less weight in enterprise procurement, and a buyer who knows the difference will ask for one of the first two.
A note for Canadian vendors #
HIPAA reaches your company through your customer, not through your address. Take a Toronto firm running scheduling software for a clinic in Ohio. Under United States law that firm is a business associate, and OCR can enforce against it. PIPEDA and PHIPA govern your Canadian work. They sit alongside HIPAA rather than replacing it. Plan for both sets of duties, because your American customer will ask about the American one.
Frequently asked questions #
Is HIPAA certification a real thing?
No. HHS states that no standard requires a company to certify compliance, and it does not endorse or recognize private certifications. A certificate from an outside firm does not release you from the Security Rule and does not stop HHS from finding a violation afterwards. Buyers accept three things instead. A SOC 2 Type 2 report. An ISO 27001 certificate with a HIPAA gap assessment. Or a written attestation from an assessor.
Does signing a BAA make my company HIPAA compliant?
No. The business associate agreement records what you promise to do. Compliance is whether you do it. OCR enforces the Security Rule against business associates directly, so the contract sets the standard you will answer against rather than satisfying it.
How often do I need to redo the HIPAA risk analysis?
The Security Rule sets no fixed interval. It tells you to review and update documents in response to operational or environmental changes. In practice that means a full refresh each year. Update it sooner if you add a system that touches PHI, change hosting, or buy a company. The proposed 2027 rule would make the yearly cycle explicit.
What is my deadline to report a breach as a business associate?
You notify the affected covered entity without unreasonable delay and no later than 60 calendar days from discovery. The covered entity then carries the duties to notify individuals, HHS, and in larger breaches the media. Discovery starts the clock, so a long internal investigation does not extend it.
Do I need SOC 2 or ISO 27001 to sell to healthcare?
Neither one is a legal requirement. Both solve a commercial problem, because HIPAA gives you nothing to hand a buyer. Most North American healthcare procurement teams accept a SOC 2 Type 2 report. ISO 27001 travels better outside the United States. Companies selling in both markets often hold both.
When do the new HIPAA Security Rule requirements take effect?
Not yet, and not soon. OCR issued the proposed rule on 27 December 2024, and the federal Unified Agenda now projects July 2027 for the final version. Compliance dates would follow publication. The current Security Rule applies in the meantime, so treat the proposal as a roadmap and not a deadline.
Does HIPAA apply to a Canadian company?
Yes, when you handle protected health information for a United States covered entity. The obligation follows the data and the customer relationship, not your head office. Canadian privacy law applies to your Canadian work at the same time, so you carry both sets of duties.
Key takeaways #
- HIPAA has no certificate. It has a process you document and defend for six years.
- As a business associate you hold ten duties in your own right, and the entire Security Rule is one of them.
- The written risk analysis is the step OCR audits, and the failure it has cited in all twelve Risk Analysis Initiative actions.
- Addressable never meant optional. It meant write down your reasoning.
- You have 60 calendar days from discovery to tell the covered entity about a breach. No one else can do it for you.
- Penalties for uncorrected willful neglect start at $73,011 per violation in 2026, and the corrective action plan outlasts the fine.
- The new Security Rule is projected for July 2027. Build toward it, but comply with the rule in force today.
Get the risk analysis OCR asks for #
Nank.ai runs the HIPAA process for software and service companies that hold patient data for healthcare customers. A compliance manager builds the documents. The platform keeps them current. A security review then takes hours instead of quarters.