HIPAA · COMPLIANCE PROOF
There is no HIPAA certificate to earn. What you hand a partner, auditor, or customer instead is evidence. The most common piece is a SOC 2 Type II report scoped to HIPAA. That report proves less than most buyers assume.
TL;DR
HHS does not certify anyone as HIPAA compliant, and never has. The closest thing to proof most companies use is a SOC 2 Type II report. It gets scoped to add HIPAA rules. That combined report tests your Security Rule safeguards. It covers 45 CFR 164.308 through 164.316. It says nothing about the Privacy Rule or the Breach Notification Rule. If you are a covered entity, you need a second set of evidence for that half. The same goes for a business associate whose customers ask about patient rights.
Sources: HHS Office for Civil Rights · AICPA, additional subject matter guidance · Federal Register, 28 January 2026
Why “HIPAA certified” is not a real credential #
Search for a HIPAA badge and you will find plenty for sale. None of them come from HHS. The department has already answered this question. Asked if a covered entity must certify its own compliance, HHS said no.
“No, there is no standard or implementation specification that requires a covered entity to ‘certify’ compliance.”
“HHS does not endorse or otherwise recognize private organizations’ ‘certifications’ regarding the Security Rule.”
U.S. Department of Health and Human ServicesFAQ on certifying compliance with the Security Rule
A vendor’s certificate can still work as an in-house checklist. It does not meet a legal duty, because no such duty exists. A partner, an investor, or a hospital procurement team wants evidence they can evaluate themselves. That is where a SOC 2 report comes in.
The most common way to prove it: a SOC 2 Type II scoped to HIPAA #
A SOC 2 Type II audit already tests your security controls over a period of months. Three to twelve months is the common range. The AICPA lets a CPA firm extend that same audit. It can cover “additional subject matter and criteria” beyond the standard Trust Services Criteria. HIPAA is the most requested addition in healthcare. The result gets called a SOC 2 + HIPAA report. Some firms call it a SOC 2 Plus report instead.
Nothing about the engagement changes. The same auditor runs it. The same evidence requests and sampling rules apply. The extra HIPAA rules get tested with the same rigor as the core Trust Services Criteria. They get reported alongside them, in the same document. You get one report instead of two.
A SOC 2 Type II, not a Type I, is the version that matters here. A Type I attests to your control design on a single day. A Type II attests to whether those controls operated for the whole review period. That is the question a HIPAA-conscious buyer is asking. A HIPAA-scoped Type I proves almost nothing about ongoing operation.
What that combined report does not prove #
The rules a SOC 2 + HIPAA report tests come from 45 CFR 164.308 through 164.316. That range is the Security Rule. It covers administrative, physical, and technical safeguards, plus the paperwork rules that sit around them. It stops there. The Breach Notification Rule and the Privacy Rule live in different parts of the same regulation. A SOC 2 audit was never built to test either one.
| HIPAA requirement | Tested by SOC 2 + HIPAA? | What it requires |
|---|---|---|
| Security Rule safeguards (45 CFR 164.308, 164.310, 164.312) | Yes | Risk analysis, access controls, encryption, audit controls, workforce security |
| Security Rule organization and documentation (45 CFR 164.314, 164.316) | Yes | Business associate contract terms, written policies, six-year retention |
| Notice of Privacy Practices (45 CFR 164.520) | No | A published notice, plus tracked patient acknowledgment |
| Patient right of access (45 CFR 164.524) | No | Fulfilling a records request within the required turnaround |
| Minimum necessary standard (45 CFR 164.502(b), 164.514(d)) | No | Limiting use and disclosure to what a task needs |
| Breach notification to individuals, HHS, and media (45 CFR 164.400-414) | No | Notifying affected individuals within 60 days, HHS, and media for large breaches |
One CPA firm that performs these engagements puts the gap plainly. Its own comparison warns that it “does not address HIPAA’s Breach Notification Rule and Privacy Rule requirements.”
That warning applies to the underlying report, not just to the firm’s article. A SOC 2 + HIPAA report answers one question well: “prove your security controls.”
It does not answer a second one. That question is “prove you handle patient rights requests correctly.”
Closing the Privacy Rule gap #
If you are a covered entity, the Privacy Rule applies to you. The gap needs closing. If you are a business associate, check your contracts instead. Many business associate agreements now delegate specific Privacy Rule duties down to the vendor. Minimum necessary handling and breach notification timing are common examples.
The evidence here does not come from an audit firm. It comes from your own day-to-day records.
- A current Notice of Privacy Practices, with tracked patient acknowledgments.
- A log of access requests, and how fast each one closed.
- A minimum necessary policy your workforce learned in training.
- A current inventory of your business associate agreements.
Our covered-entity guide walks through building each piece. A SOC 2 report will never contain any of it. None of it is a security control.
Other paths people try, and their limits #
Two other approaches come up often enough to name here.
HITRUST CSF certification. HITRUST’s own certifying guidance is explicit here. A certificate does not count as proof of compliance with any required rule. Like a SOC 2 + HIPAA report, HITRUST covers the security angle well. It was not built to prove Privacy Rule compliance either. It also says nothing about non-HIPAA duties, like Medicare conditions of participation.
Recognized security practices. A 2021 amendment to HITECH requires OCR to consider whether you had recognized security practices in place. The window is the 12 months before an incident. The NIST Cybersecurity Framework is one accepted example. Demonstrating this can soften an enforcement outcome. But it is only a mitigating factor in a penalty calculation. It is not proof of compliance, and it only ever touches the security side.
Neither one replaces the work in the table above. Both sit on the same side of that line as a SOC 2 + HIPAA report.
| Culpability tier | Minimum per violation | Maximum per violation | Annual cap |
|---|---|---|---|
| Did not know, and reasonable diligence would not have found it | $145 | $73,011 | $2,190,294 |
| Reasonable cause, not willful neglect | $1,461 | $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
What to hand someone who asks for proof #
A partner, a customer’s security team, or an investor may ask for proof. Hand them a package, not a single document.
- Your SOC 2 Type II report, scoped to HIPAA. This is the piece most buyers expect first. It covers your security controls, with third-party testing behind it.
- A signed business associate agreement. If you are the vendor, your customer’s legal team will ask for this first.
- Your current Notice of Privacy Practices. Covered entities need this published. A business associate seldom needs one of its own, but should know its customer’s.
- A summary of your latest risk analysis. Not the full document, which stays in-house, but confirmation of when it ran and what it covered. Our risk analysis guide covers what that document should contain.
- Workforce training records. Dates and completion rates for both security and privacy training. Keep the two separate, since they cover different rules.
- An incident response and breach notification plan. Reviewers want to see the clock is already built. They do not want a promise you would build one after the fact.
The audit is one piece, not the whole program
A SOC 2 + HIPAA report tests what you built. It does not build it for you. Our business associate guide and our covered-entity guide cover the program each audience needs to run.
Frequently asked questions #
Is there an official HIPAA certification?
No. HHS has stated plainly that no standard requires a covered entity to certify compliance. HHS also does not endorse or accept any private organization’s HIPAA certification. Anything sold as a “HIPAA certificate” is a vendor product, not a government credential.
What’s the fastest way to prove HIPAA compliance to a partner or customer?
A SOC 2 Type II report scoped to add HIPAA rules. It is the most requested piece of evidence. It comes from an independent CPA firm, and it covers the security controls most buyers check first.
Does a SOC 2 + HIPAA report cover the Privacy Rule?
No. The extra rules map to 45 CFR 164.308 through 164.316, which is the Security Rule. The Privacy Rule and the Breach Notification Rule sit in different parts of the law. Both fall outside what the audit tests.
What closes the Privacy Rule gap?
Your own day-to-day records, not an audit report. That means a Notice of Privacy Practices and an access-request log. It also means a minimum necessary policy and a business associate agreement list. No audit firm issues a report for any of it. You build and keep the evidence yourself.
Does HITRUST certification prove HIPAA compliance?
No. HITRUST’s own guidance says a certificate does not count as proof of compliance. It covers the security side well, similar to a SOC 2 + HIPAA report. It leaves the Privacy Rule and non-HIPAA duties untested.
What should we hand someone who asks for proof, if we only have one document ready?
Lead with the SOC 2 Type II report scoped to HIPAA, since that is what most buyers expect first. But be ready to follow with a signed business associate agreement and your Notice of Privacy Practices. A single document seldom satisfies a thorough buyer, because no single document covers both rules.
Key takeaways #
- No government body certifies HIPAA compliance. HHS has said so plainly, and it does not recognize private certifications either.
- A SOC 2 Type II report scoped to HIPAA is the most common piece of evidence. It should be a Type II, not a Type I.
- That report tests 45 CFR 164.308 through 164.316, the Security Rule. It does not test the Privacy Rule or the Breach Notification Rule.
- Covered entities need their own Privacy Rule evidence, not a security audit. So does a business associate with delegated privacy duties.
- HITRUST certification and demonstrated recognized security practices share the same limit. Both cover security, and neither is legal proof of full compliance.
- The strongest answer to a compliance question is a package of documents, not one report alone.
Get proof that answers the whole question #
Nank.ai helps companies across Canada and the United States run the SOC 2 and HIPAA programs a real buyer checks. That means security, and it means privacy too. A compliance manager tracks the evidence. You get a real answer ready before someone asks.