What is HIPAA compliance?
What the HIPAA rules actually require, why HIPAA certification is not an official designation, and what documentation a regulator expects to see when they ask.
HIPAA compliance meaning: HIPAA compliance is a covered entity's or business associate's ongoing adherence to the US Health Insurance Portability and Accountability Act — principally the Privacy Rule, the Security Rule and the Breach Notification Rule, enforced by the HHS Office for Civil Rights. It is demonstrated through documented safeguards, policies, a security risk analysis, workforce training records and business associate agreements. There is no government-issued HIPAA certificate; compliance is a state you maintain and evidence, not a badge you obtain once.
Is there such a thing as HIPAA certification?
Not as an official designation. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and it does not recognise any third party to do so on its behalf. Vendors do sell HIPAA certification, training certificates and attestations, and those can be genuinely useful as evidence that you assessed yourself against the rules — but none of them is a legal status, and none of them is a defence in an Office for Civil Rights investigation. What matters in an enforcement action is whether you can produce the underlying artifacts: the risk analysis, the policies, the training records, the signed business associate agreements, and the record of what you did about the gaps you found.
The HIPAA Privacy Rule
The HIPAA Privacy Rule governs how protected health information may be used and disclosed, and it is where individual rights live. It sets the minimum necessary standard — you use or disclose only the least PHI needed for the purpose — requires a Notice of Privacy Practices, and gives individuals the right to access and request amendment of their records and to receive an accounting of certain disclosures. The access right carries a response deadline measured in days, not months, and failure to meet it has been one of the most commonly enforced provisions. Take the exact periods and exceptions from the rule text or your counsel rather than from a summary, including this one.
The three rules, and what each one asks of you
| Rule | Covers | What you have to be able to show |
|---|---|---|
| Privacy Rule | Use and disclosure of PHI in any form | Policies and procedures, Notice of Privacy Practices, minimum-necessary controls, records of how access and amendment requests were handled |
| Security Rule | Electronic PHI specifically | A security risk analysis, plus administrative, physical and technical safeguards, with documented decisions where a safeguard is addressable rather than required |
| Breach Notification Rule | Unsecured PHI that has been compromised | A breach risk assessment, notice to affected individuals and to HHS within the prescribed windows, and media notice above the large-breach threshold |
Who has to comply
Covered entities
Health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions. The obligation attaches to the role, not the size of the organisation.
Business associates
Vendors that create, receive, maintain or transmit PHI on a covered entity's behalf — hosting, billing, analytics, transcription. They are directly liable under HIPAA, and the relationship has to be papered with a business associate agreement.
Subcontractors
A business associate's own vendors that touch PHI inherit the same obligations, which is why BAAs chain downward. Mapping that chain is usually the part that is missing when someone asks for it.
Who is outside it
HIPAA does not reach every organisation holding health data. Most consumer wellness apps, and employers acting in their capacity as employers, fall outside it — other privacy law may still apply. GDPR compliance
What HIPAA compliance looks like as documentation
Strip away the framework language and the deliverable is a document set: privacy and security policies, a completed security risk analysis with a remediation plan, workforce training and sanction records, a business associate agreement inventory, an incident and breach response procedure, and a retention rule covering how long each of those is kept. HIPAA requires documentation to be retained for a defined period, so retention is part of the obligation rather than a separate housekeeping question. Data retention policy · Compliance checklist drafting · Risk register
Where Gixo Lex fits — and where it does not
Gixo Lex is a drafting and review workspace for the documentation layer: policy drafts, compliance checklists, evidence matrices and working papers, prepared as reviewable first drafts that surface missing facts as open items rather than filling them in silently. It is not a compliance management platform, a risk scoring tool or a certification body — Compliancy Group, HIPAA One, Drata and Vanta own that layer, and Gixo owns the draft and review layer underneath it. Gixo helps prepare regulated work. It does not provide legal advice, certify compliance, or replace professional review, and every draft goes to a qualified reviewer before it is adopted. AI compliance for healthcare · Compliance documentation software