What is HIPAA compliance?
What the HIPAA rules actually require, why HIPAA certification is not an official designation, and what documentation a regulator expects to see when they ask.
HIPAA compliance meaning: HIPAA compliance is a covered entity's or business associate's ongoing adherence to the US Health Insurance Portability and Accountability Act — principally the Privacy Rule, the Security Rule and the Breach Notification Rule, enforced by the HHS Office for Civil Rights. It is demonstrated through documented safeguards, policies, a security risk analysis, workforce training records and business associate agreements. There is no government-issued HIPAA certificate; compliance is a state you maintain and evidence, not a badge you obtain once.
Is there such a thing as HIPAA certification?
Not as an official designation. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and it does not recognise any third party to do so on its behalf. Vendors do sell HIPAA certification, training certificates and attestations, and those can be genuinely useful as evidence that you assessed yourself against the rules — but none of them is a legal status, and none of them is a defence in an Office for Civil Rights investigation. What matters in an enforcement action is whether you can produce the underlying artifacts: the risk analysis, the policies, the training records, the signed business associate agreements, and the record of what you did about the gaps you found.
The HIPAA Privacy Rule
The HIPAA Privacy Rule governs how protected health information may be used and disclosed, and it is where individual rights live. It sets the minimum necessary standard — you use or disclose only the least PHI needed for the purpose — requires a Notice of Privacy Practices, and gives individuals the right to access and request amendment of their records and to receive an accounting of certain disclosures. The access right carries a response deadline measured in days, not months, and failure to meet it has been one of the most commonly enforced provisions. Take the exact periods and exceptions from the rule text or your counsel rather than from a summary, including this one.
Minimum necessary standard
Use or disclose only the least PHI needed for the purpose at hand, and limit internal access the same way. In practice this is a role-based question: which job functions need which categories of record, written down, and reflected in what the systems actually permit. It does not apply to disclosures to the individual, to treatment, or where an authorisation or a legal requirement sets the scope.
Notice of Privacy Practices
A plain-language notice of how PHI is used and disclosed, the individual's rights, and how to complain, provided to individuals and posted where the organisation has a service site or a web presence. Providers with a direct treatment relationship also have to make a good-faith effort to obtain written acknowledgement that it was received — the acknowledgement, or the reason it could not be obtained, is the artifact a reviewer asks for.
Individual right of access
Individuals can inspect and obtain a copy of their records in a designated record set, in the form and format they request where it is readily producible, and can direct a copy to a third party. Only a reasonable, cost-based fee may be charged. This is the provision enforcement actions have concentrated on, and the failure is almost always operational rather than legal: no owner, no clock, no log of what was sent and when.
Permitted uses and disclosures
PHI may be used or disclosed without authorisation for treatment, payment and health care operations, to the individual, and for a defined set of public-interest activities such as public health reporting and certain law-enforcement and judicial purposes. Anything outside those categories — marketing and most sales of PHI in particular — needs a valid authorisation. The compliance work is knowing which bucket a given request falls into before answering it, and recording that judgment.
The three rules, and what each one asks of you
| Rule | Covers | What you have to be able to show |
|---|---|---|
| Privacy Rule | Use and disclosure of PHI in any form | Policies and procedures, Notice of Privacy Practices, minimum-necessary controls, records of how access and amendment requests were handled |
| Security Rule | Electronic PHI specifically | A security risk analysis, plus administrative, physical and technical safeguards, with documented decisions where a safeguard is addressable rather than required |
| Breach Notification Rule | Unsecured PHI that has been compromised | A breach risk assessment, notice to affected individuals and to HHS within the prescribed windows, and media notice above the large-breach threshold |
What are the HIPAA rules, and what is HIPAA law?
HIPAA is a 1996 federal statute; the rules are regulations issued under it. Title I of the act deals with keeping health coverage when people change or lose a job. Title II, Administrative Simplification, is the part everyone means when they say HIPAA, and it is where the rules come from. “The three HIPAA rules” is shorthand for Privacy, Security and Breach Notification — the right shorthand, because those three generate the day-to-day obligations — but they are not the whole set.
Transactions and Code Sets Rule
Standard formats and code sets for electronic health care transactions such as claims, eligibility checks and remittance advice. It is the reason “covered transaction” appears in the definition of a covered entity: a provider who never transmits health information electronically in one of these transactions is not a covered entity at all.
Unique Identifiers Rule
Standard identifiers for the parties to those transactions — the National Provider Identifier for providers and the employer identification number for employers. Administrative rather than protective, but it is part of the rule set and it does bind covered entities.
Enforcement Rule
How the Office for Civil Rights investigates, holds hearings and imposes civil money penalties, including the tiered penalty structure based on culpability. It is not a duty you implement; it is the procedure that applies to you when something goes wrong, which is why the documentation set matters more than any certificate.
Omnibus Rule (2013)
The rule that implemented the HITECH Act changes: business associates became directly liable, the obligations were extended down the subcontractor chain, and the breach standard changed so that a compromise is presumed unless a risk assessment demonstrates a low probability that PHI was compromised. Anything written about HIPAA before 2013 should be read with that in mind.
Who each rule binds is the dimension most summaries drop. The Privacy Rule binds covered entities directly and business associates through their agreements, with certain provisions applying to them directly. The Security Rule and most of the Breach Notification Rule bind business associates directly, whatever a particular contract says — a vendor cannot negotiate its way out of the Security Rule. The Transactions, Identifiers and Enforcement rules sit with covered entities. Work out which of those descriptions is you before deciding which obligations are yours, and take the exact scope from the rule text or your counsel rather than from a summary.
Who has to comply
Covered entities
Health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions. The obligation attaches to the role, not the size of the organisation.
Business associates
Vendors that create, receive, maintain or transmit PHI on a covered entity's behalf — hosting, billing, analytics, transcription. They are directly liable under HIPAA, and the relationship has to be papered with a business associate agreement.
Subcontractors
A business associate's own vendors that touch PHI inherit the same obligations, which is why BAAs chain downward. Mapping that chain is usually the part that is missing when someone asks for it.
Who is outside it
HIPAA does not reach every organisation holding health data. Most consumer wellness apps, and employers acting in their capacity as employers, fall outside it — other privacy law may still apply. GDPR compliance
What HIPAA compliance looks like as documentation
Strip away the framework language and the deliverable is a document set: privacy and security policies, a completed security risk analysis with a remediation plan, workforce training and sanction records, a business associate agreement inventory, an incident and breach response procedure, and a retention rule covering how long each of those is kept. HIPAA requires documentation to be retained for a defined period, so retention is part of the obligation rather than a separate housekeeping question. Data retention policy · Compliance checklist drafting · Risk register
Where Gixo Lex fits — and where it does not
Gixo Lex is a drafting and review workspace for the documentation layer: policy drafts, compliance checklists, evidence matrices and working papers, prepared as reviewable first drafts that surface missing facts as open items rather than filling them in silently. It is not a compliance management platform, a risk scoring tool or a certification body — Compliancy Group, HIPAA One, Drata and Vanta own that layer, and Gixo owns the draft and review layer underneath it. Gixo helps prepare regulated work. It does not provide legal advice, certify compliance, or replace professional review, and every draft goes to a qualified reviewer before it is adopted. AI compliance for healthcare · Compliance documentation software
Frequently Asked Questions
Related compliance guidance
Updated