Skip to content
Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.

What is HIPAA compliance?

What the HIPAA rules actually require, why HIPAA certification is not an official designation, and what documentation a regulator expects to see when they ask.

Start 14-day Lex trial View Lex pricing

HIPAA compliance meaning: HIPAA compliance is a covered entity's or business associate's ongoing adherence to the US Health Insurance Portability and Accountability Act — principally the Privacy Rule, the Security Rule and the Breach Notification Rule, enforced by the HHS Office for Civil Rights. It is demonstrated through documented safeguards, policies, a security risk analysis, workforce training records and business associate agreements. There is no government-issued HIPAA certificate; compliance is a state you maintain and evidence, not a badge you obtain once.

PrivacyUse and disclosure of PHI
SecuritySafeguards for electronic PHI
BreachNotification duties and deadlines
EvidencePolicies, training, BAAs

Is there such a thing as HIPAA certification?

Not as an official designation. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and it does not recognise any third party to do so on its behalf. Vendors do sell HIPAA certification, training certificates and attestations, and those can be genuinely useful as evidence that you assessed yourself against the rules — but none of them is a legal status, and none of them is a defence in an Office for Civil Rights investigation. What matters in an enforcement action is whether you can produce the underlying artifacts: the risk analysis, the policies, the training records, the signed business associate agreements, and the record of what you did about the gaps you found.

Why the distinction matters commercially. Buyers in healthcare frequently ask for a HIPAA certificate in security questionnaires. The correct answer is not to buy one — it is to hand over the documentation set, which is what a knowledgeable reviewer is really asking for. Vendors often pair it with a SOC 2 report, which is an audited attestation, to give the buyer something independently examined. SOC 2 checklist drafting

The HIPAA Privacy Rule

The HIPAA Privacy Rule governs how protected health information may be used and disclosed, and it is where individual rights live. It sets the minimum necessary standard — you use or disclose only the least PHI needed for the purpose — requires a Notice of Privacy Practices, and gives individuals the right to access and request amendment of their records and to receive an accounting of certain disclosures. The access right carries a response deadline measured in days, not months, and failure to meet it has been one of the most commonly enforced provisions. Take the exact periods and exceptions from the rule text or your counsel rather than from a summary, including this one.

Minimum necessary standard

Use or disclose only the least PHI needed for the purpose at hand, and limit internal access the same way. In practice this is a role-based question: which job functions need which categories of record, written down, and reflected in what the systems actually permit. It does not apply to disclosures to the individual, to treatment, or where an authorisation or a legal requirement sets the scope.

Notice of Privacy Practices

A plain-language notice of how PHI is used and disclosed, the individual's rights, and how to complain, provided to individuals and posted where the organisation has a service site or a web presence. Providers with a direct treatment relationship also have to make a good-faith effort to obtain written acknowledgement that it was received — the acknowledgement, or the reason it could not be obtained, is the artifact a reviewer asks for.

Individual right of access

Individuals can inspect and obtain a copy of their records in a designated record set, in the form and format they request where it is readily producible, and can direct a copy to a third party. Only a reasonable, cost-based fee may be charged. This is the provision enforcement actions have concentrated on, and the failure is almost always operational rather than legal: no owner, no clock, no log of what was sent and when.

Permitted uses and disclosures

PHI may be used or disclosed without authorisation for treatment, payment and health care operations, to the individual, and for a defined set of public-interest activities such as public health reporting and certain law-enforcement and judicial purposes. Anything outside those categories — marketing and most sales of PHI in particular — needs a valid authorisation. The compliance work is knowing which bucket a given request falls into before answering it, and recording that judgment.

The three rules, and what each one asks of you

The three HIPAA rules and the evidence each one expects
RuleCoversWhat you have to be able to show
Privacy RuleUse and disclosure of PHI in any formPolicies and procedures, Notice of Privacy Practices, minimum-necessary controls, records of how access and amendment requests were handled
Security RuleElectronic PHI specificallyA security risk analysis, plus administrative, physical and technical safeguards, with documented decisions where a safeguard is addressable rather than required
Breach Notification RuleUnsecured PHI that has been compromisedA breach risk assessment, notice to affected individuals and to HHS within the prescribed windows, and media notice above the large-breach threshold

What are the HIPAA rules, and what is HIPAA law?

HIPAA is a 1996 federal statute; the rules are regulations issued under it. Title I of the act deals with keeping health coverage when people change or lose a job. Title II, Administrative Simplification, is the part everyone means when they say HIPAA, and it is where the rules come from. “The three HIPAA rules” is shorthand for Privacy, Security and Breach Notification — the right shorthand, because those three generate the day-to-day obligations — but they are not the whole set.

Transactions and Code Sets Rule

Standard formats and code sets for electronic health care transactions such as claims, eligibility checks and remittance advice. It is the reason “covered transaction” appears in the definition of a covered entity: a provider who never transmits health information electronically in one of these transactions is not a covered entity at all.

Unique Identifiers Rule

Standard identifiers for the parties to those transactions — the National Provider Identifier for providers and the employer identification number for employers. Administrative rather than protective, but it is part of the rule set and it does bind covered entities.

Enforcement Rule

How the Office for Civil Rights investigates, holds hearings and imposes civil money penalties, including the tiered penalty structure based on culpability. It is not a duty you implement; it is the procedure that applies to you when something goes wrong, which is why the documentation set matters more than any certificate.

Omnibus Rule (2013)

The rule that implemented the HITECH Act changes: business associates became directly liable, the obligations were extended down the subcontractor chain, and the breach standard changed so that a compromise is presumed unless a risk assessment demonstrates a low probability that PHI was compromised. Anything written about HIPAA before 2013 should be read with that in mind.

Who each rule binds is the dimension most summaries drop. The Privacy Rule binds covered entities directly and business associates through their agreements, with certain provisions applying to them directly. The Security Rule and most of the Breach Notification Rule bind business associates directly, whatever a particular contract says — a vendor cannot negotiate its way out of the Security Rule. The Transactions, Identifiers and Enforcement rules sit with covered entities. Work out which of those descriptions is you before deciding which obligations are yours, and take the exact scope from the rule text or your counsel rather than from a summary.

Who has to comply

Covered entities

Health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions. The obligation attaches to the role, not the size of the organisation.

Business associates

Vendors that create, receive, maintain or transmit PHI on a covered entity's behalf — hosting, billing, analytics, transcription. They are directly liable under HIPAA, and the relationship has to be papered with a business associate agreement.

Subcontractors

A business associate's own vendors that touch PHI inherit the same obligations, which is why BAAs chain downward. Mapping that chain is usually the part that is missing when someone asks for it.

Who is outside it

HIPAA does not reach every organisation holding health data. Most consumer wellness apps, and employers acting in their capacity as employers, fall outside it — other privacy law may still apply. GDPR compliance

What HIPAA compliance looks like as documentation

Strip away the framework language and the deliverable is a document set: privacy and security policies, a completed security risk analysis with a remediation plan, workforce training and sanction records, a business associate agreement inventory, an incident and breach response procedure, and a retention rule covering how long each of those is kept. HIPAA requires documentation to be retained for a defined period, so retention is part of the obligation rather than a separate housekeeping question. Data retention policy · Compliance checklist drafting · Risk register

Where Gixo Lex fits — and where it does not

Gixo Lex is a drafting and review workspace for the documentation layer: policy drafts, compliance checklists, evidence matrices and working papers, prepared as reviewable first drafts that surface missing facts as open items rather than filling them in silently. It is not a compliance management platform, a risk scoring tool or a certification body — Compliancy Group, HIPAA One, Drata and Vanta own that layer, and Gixo owns the draft and review layer underneath it. Gixo helps prepare regulated work. It does not provide legal advice, certify compliance, or replace professional review, and every draft goes to a qualified reviewer before it is adopted. AI compliance for healthcare · Compliance documentation software

Frequently Asked Questions

What is HIPAA compliance?
HIPAA compliance is a covered entity's or business associate's ongoing adherence to the US Health Insurance Portability and Accountability Act — principally the Privacy Rule, the Security Rule and the Breach Notification Rule, enforced by the HHS Office for Civil Rights. In practice it is demonstrated through documented safeguards, policies, a security risk analysis, workforce training records and business associate agreements.
Is HIPAA certification a real thing?
Not as an official designation. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and does not recognise a third party to do so on its behalf. Commercial HIPAA certifications and training certificates exist and can be useful evidence that you assessed yourself against the rules, but none of them confers a legal status or acts as a defence in an Office for Civil Rights investigation.
How do you get HIPAA certified?
You cannot, in the sense most people mean. What you can do is complete a security risk analysis, put the required policies and safeguards in place, train your workforce, sign business associate agreements with every vendor that touches PHI, and keep the records that prove all of it. Some organisations also obtain a third-party attestation such as SOC 2, which is independently audited, to give buyers something examined rather than self-declared.
What does the HIPAA Privacy Rule require?
The HIPAA Privacy Rule governs how protected health information may be used and disclosed. It sets the minimum necessary standard, requires a Notice of Privacy Practices, and gives individuals rights of access to their records, the right to request amendment, and the right to an accounting of certain disclosures. Access requests carry a response deadline, and missing it has been among the most commonly enforced provisions.
What are the three HIPAA rules?
The Privacy Rule, which governs how protected health information may be used and disclosed in any form; the Security Rule, which requires administrative, physical and technical safeguards for electronic PHI and is anchored by a security risk analysis; and the Breach Notification Rule, which sets what has to be assessed, reported and disclosed when unsecured PHI is compromised. Those three carry the day-to-day obligations, but they are not the whole of HIPAA — the Transactions and Code Sets, Unique Identifiers, Enforcement and 2013 Omnibus rules complete the Administrative Simplification set.
What is HIPAA law?
HIPAA is the Health Insurance Portability and Accountability Act of 1996, a US federal statute. Title I protects health coverage when people change or lose a job. Title II, Administrative Simplification, is the part that produced the privacy and security regulations everyone means by "HIPAA" — the rules themselves are regulations issued under the act and amended since, most significantly by the HITECH Act and the 2013 Omnibus Rule. It is enforced by the HHS Office for Civil Rights, and state attorneys general can also bring actions.
What is the difference between the HIPAA Privacy Rule and the Security Rule?
The Privacy Rule covers protected health information in any form — spoken, paper or electronic — and governs who may use or disclose it and on what terms. The Security Rule applies specifically to electronic PHI and requires administrative, physical and technical safeguards, with a security risk analysis as its anchor. The Privacy Rule sets the permissions; the Security Rule sets how electronic copies are protected.
Who has to comply with HIPAA?
Covered entities — health plans, health care clearinghouses, and providers transmitting health information electronically in covered transactions — and their business associates, meaning vendors that create, receive, maintain or transmit PHI on their behalf. Business associates are directly liable, and their own subcontractors inherit the obligations, which is why business associate agreements chain downward. Most consumer wellness apps and employers acting as employers fall outside HIPAA, though other privacy law may still apply.
What documentation does HIPAA compliance require?
Privacy and security policies, a completed security risk analysis with a remediation plan, workforce training and sanction records, a business associate agreement inventory, an incident and breach response procedure, and a rule covering how long each of those is retained. HIPAA requires documentation to be kept for a defined period, so retention is part of the obligation rather than a separate matter.
Can Gixo Lex help with HIPAA compliance?
With the documentation layer, as reviewable first drafts — policy drafts, compliance checklists, evidence matrices and working papers, with missing facts surfaced as open items rather than filled in silently. Gixo is not a compliance management platform, a risk scoring tool or a certification body. It helps prepare regulated work; it does not provide legal advice, certify compliance, or replace professional review, and drafts go to a qualified reviewer before adoption.

Updated