Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.

What is HIPAA compliance?

What the HIPAA rules actually require, why HIPAA certification is not an official designation, and what documentation a regulator expects to see when they ask.

Start 14-day Lex trial View Lex pricing

HIPAA compliance meaning: HIPAA compliance is a covered entity's or business associate's ongoing adherence to the US Health Insurance Portability and Accountability Act — principally the Privacy Rule, the Security Rule and the Breach Notification Rule, enforced by the HHS Office for Civil Rights. It is demonstrated through documented safeguards, policies, a security risk analysis, workforce training records and business associate agreements. There is no government-issued HIPAA certificate; compliance is a state you maintain and evidence, not a badge you obtain once.

PrivacyUse and disclosure of PHI
SecuritySafeguards for electronic PHI
BreachNotification duties and deadlines
EvidencePolicies, training, BAAs

Is there such a thing as HIPAA certification?

Not as an official designation. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and it does not recognise any third party to do so on its behalf. Vendors do sell HIPAA certification, training certificates and attestations, and those can be genuinely useful as evidence that you assessed yourself against the rules — but none of them is a legal status, and none of them is a defence in an Office for Civil Rights investigation. What matters in an enforcement action is whether you can produce the underlying artifacts: the risk analysis, the policies, the training records, the signed business associate agreements, and the record of what you did about the gaps you found.

Why the distinction matters commercially. Buyers in healthcare frequently ask for a HIPAA certificate in security questionnaires. The correct answer is not to buy one — it is to hand over the documentation set, which is what a knowledgeable reviewer is really asking for. Vendors often pair it with a SOC 2 report, which is an audited attestation, to give the buyer something independently examined. SOC 2 checklist drafting

The HIPAA Privacy Rule

The HIPAA Privacy Rule governs how protected health information may be used and disclosed, and it is where individual rights live. It sets the minimum necessary standard — you use or disclose only the least PHI needed for the purpose — requires a Notice of Privacy Practices, and gives individuals the right to access and request amendment of their records and to receive an accounting of certain disclosures. The access right carries a response deadline measured in days, not months, and failure to meet it has been one of the most commonly enforced provisions. Take the exact periods and exceptions from the rule text or your counsel rather than from a summary, including this one.

The three rules, and what each one asks of you

The three HIPAA rules and the evidence each one expects
RuleCoversWhat you have to be able to show
Privacy RuleUse and disclosure of PHI in any formPolicies and procedures, Notice of Privacy Practices, minimum-necessary controls, records of how access and amendment requests were handled
Security RuleElectronic PHI specificallyA security risk analysis, plus administrative, physical and technical safeguards, with documented decisions where a safeguard is addressable rather than required
Breach Notification RuleUnsecured PHI that has been compromisedA breach risk assessment, notice to affected individuals and to HHS within the prescribed windows, and media notice above the large-breach threshold

Who has to comply

Covered entities

Health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions. The obligation attaches to the role, not the size of the organisation.

Business associates

Vendors that create, receive, maintain or transmit PHI on a covered entity's behalf — hosting, billing, analytics, transcription. They are directly liable under HIPAA, and the relationship has to be papered with a business associate agreement.

Subcontractors

A business associate's own vendors that touch PHI inherit the same obligations, which is why BAAs chain downward. Mapping that chain is usually the part that is missing when someone asks for it.

Who is outside it

HIPAA does not reach every organisation holding health data. Most consumer wellness apps, and employers acting in their capacity as employers, fall outside it — other privacy law may still apply. GDPR compliance

What HIPAA compliance looks like as documentation

Strip away the framework language and the deliverable is a document set: privacy and security policies, a completed security risk analysis with a remediation plan, workforce training and sanction records, a business associate agreement inventory, an incident and breach response procedure, and a retention rule covering how long each of those is kept. HIPAA requires documentation to be retained for a defined period, so retention is part of the obligation rather than a separate housekeeping question. Data retention policy · Compliance checklist drafting · Risk register

Where Gixo Lex fits — and where it does not

Gixo Lex is a drafting and review workspace for the documentation layer: policy drafts, compliance checklists, evidence matrices and working papers, prepared as reviewable first drafts that surface missing facts as open items rather than filling them in silently. It is not a compliance management platform, a risk scoring tool or a certification body — Compliancy Group, HIPAA One, Drata and Vanta own that layer, and Gixo owns the draft and review layer underneath it. Gixo helps prepare regulated work. It does not provide legal advice, certify compliance, or replace professional review, and every draft goes to a qualified reviewer before it is adopted. AI compliance for healthcare · Compliance documentation software

Frequently Asked Questions

What is HIPAA compliance?
HIPAA compliance is a covered entity's or business associate's ongoing adherence to the US Health Insurance Portability and Accountability Act — principally the Privacy Rule, the Security Rule and the Breach Notification Rule, enforced by the HHS Office for Civil Rights. In practice it is demonstrated through documented safeguards, policies, a security risk analysis, workforce training records and business associate agreements.
Is HIPAA certification a real thing?
Not as an official designation. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and does not recognise a third party to do so on its behalf. Commercial HIPAA certifications and training certificates exist and can be useful evidence that you assessed yourself against the rules, but none of them confers a legal status or acts as a defence in an Office for Civil Rights investigation.
How do you get HIPAA certified?
You cannot, in the sense most people mean. What you can do is complete a security risk analysis, put the required policies and safeguards in place, train your workforce, sign business associate agreements with every vendor that touches PHI, and keep the records that prove all of it. Some organisations also obtain a third-party attestation such as SOC 2, which is independently audited, to give buyers something examined rather than self-declared.
What does the HIPAA Privacy Rule require?
The HIPAA Privacy Rule governs how protected health information may be used and disclosed. It sets the minimum necessary standard, requires a Notice of Privacy Practices, and gives individuals rights of access to their records, the right to request amendment, and the right to an accounting of certain disclosures. Access requests carry a response deadline, and missing it has been among the most commonly enforced provisions.
What is the difference between the HIPAA Privacy Rule and the Security Rule?
The Privacy Rule covers protected health information in any form — spoken, paper or electronic — and governs who may use or disclose it and on what terms. The Security Rule applies specifically to electronic PHI and requires administrative, physical and technical safeguards, with a security risk analysis as its anchor. The Privacy Rule sets the permissions; the Security Rule sets how electronic copies are protected.
Who has to comply with HIPAA?
Covered entities — health plans, health care clearinghouses, and providers transmitting health information electronically in covered transactions — and their business associates, meaning vendors that create, receive, maintain or transmit PHI on their behalf. Business associates are directly liable, and their own subcontractors inherit the obligations, which is why business associate agreements chain downward. Most consumer wellness apps and employers acting as employers fall outside HIPAA, though other privacy law may still apply.
What documentation does HIPAA compliance require?
Privacy and security policies, a completed security risk analysis with a remediation plan, workforce training and sanction records, a business associate agreement inventory, an incident and breach response procedure, and a rule covering how long each of those is retained. HIPAA requires documentation to be kept for a defined period, so retention is part of the obligation rather than a separate matter.
Can Gixo Lex help with HIPAA compliance?
With the documentation layer, as reviewable first drafts — policy drafts, compliance checklists, evidence matrices and working papers, with missing facts surfaced as open items rather than filled in silently. Gixo is not a compliance management platform, a risk scoring tool or a certification body. It helps prepare regulated work; it does not provide legal advice, certify compliance, or replace professional review, and drafts go to a qualified reviewer before adoption.