There’s a scene in Tommy Boy where Tommy Callahan tries to explain the value of a guarantee, and finally admits the quiet part: a guarantee is just the promise on the box. It doesn’t mean what’s in the box is any good. It just means somebody’s willing to say it is, in writing, until someone calls them on it.

That’s HIPAA compliance. Not the safeguards behind it (those are real, and they matter), but the label. The seal on the footer of a website, the line in a sales deck that says “HIPAA Compliant,” as if a regulator stamped it. Nobody did. There’s no HIPAA certificate to earn, because there’s no HIPAA certification to give out.

A bronze "HIPAA Seal of Compliance" medallion this isn’t real

There’s no such thing as a HIPAA certification

HHS’s Office for Civil Rights, which enforces HIPAA, has said this directly: there is no official government certification of HIPAA compliance, and no third party is authorized to issue one on the government’s behalf. A vendor advertising “HIPAA Certified” software or a consultant selling a “HIPAA Certification” course is selling something that doesn’t formally exist: a marketing claim built to look like a regulatory one.

That’s not a technicality. It matters because a seal implies someone checked. Nobody checked. What actually happened is that an organization decided, on its own, that it meets the Security Rule and Privacy Rule’s requirements, and then said so.

What compliance actually is: a self-attested state

HIPAA compliance is something you claim, not something you’re awarded. In practice, that means:

  • You run the risk analysis identifying where electronic PHI lives and what threatens it.
  • You decide which administrative, physical, and technical safeguards are “reasonable and appropriate” for your environment and implement them.
  • You write the policies, train the workforce, and sign the business associate agreements.
  • You document all of it, because the documentation is the only evidence that any of it happened.

Nobody pre-approves this. There’s no exam, no inspector, no pass/fail gate before you’re allowed to say you’re compliant. The only time anyone independent looks at your work is after something goes wrong: a patient complaint, a breach report, a random OCR audit. At that point, your self-attestation gets tested against your actual controls, and the gap between the two becomes the finding in a resolution agreement or civil penalty.

In other words: HIPAA compliance isn’t verified going in. It’s graded going out, if it’s graded at all.

HITRUST is the real analog, and it’s optional

If you want an actual certification (a third party that reviews evidence, tests controls, and issues something you can point to), that exists. It’s called HITRUST CSF, and it’s a legitimate, independently assessed framework that maps to HIPAA’s requirements (along with NIST, ISO 27001, and others). A HITRUST r2 certification means an accredited assessor actually looked at your environment.

But HITRUST isn’t HIPAA, and it isn’t required by law. Nothing in the HIPAA statute or regulations requires an organization to obtain HITRUST, or SOC 2, for that matter, which follows a similar pattern of a real, independent audit that nobody is legally obligated to pursue. Both are things covered entities and business associates choose to pursue, usually because a customer, partner, or insurer asks for the assurance a self-attestation can’t provide. They’re valuable. They’re just not the floor. The floor is the self-attested Security Rule and Privacy Rule, and that floor applies whether or not you ever sit for an audit.

Don’t wait on the next rule to fix the self-attestation problem

We recently covered the proposed HIPAA Security Rule update now delayed to roughly mid-2027. It’s tempting to treat that delay as a reason to wait, as if the real requirements are still years out. They aren’t. The proposed rule tightens what “reasonable and appropriate” means and closes the “addressable equals optional” loophole, but it doesn’t create a certifying body. It’s still a framework you implement and attest to yourself, just with less room to argue your way out of specific safeguards. Whatever gap exists between your actual controls and what you’re claiming today is the gap that gets you in trouble today, not in 2027.

Self-attestation isn’t just made to the government

OCR isn’t the only audience for a HIPAA compliance claim, and it isn’t the sharpest one either.

Customer and partner contracts increasingly bolt security addenda onto the BAA itself: specific attestations about encryption, access controls, and breach notification timelines written in as contract terms, often surfaced through a vendor security questionnaire before a deal even closes. If what you attested to in that questionnaire doesn’t match what you actually run, that’s a breach-of-contract problem, independent of anything HIPAA-specific.

Cyber insurance applications ask the same kind of pointed questions before a carrier will bind a policy: Is MFA enforced everywhere? Is EDR deployed? Are backups tested? Those answers become representations the policy is priced on. If a breach happens and the controls you attested to weren’t actually in place, carriers can rescind coverage or deny the claim for misrepresentation, often faster and with more immediate financial consequence than an OCR investigation ever moves.

The throughline across all three audiences (regulator, customer, insurer) is the same: nobody independently checks the claim before you make it. It’s attestation all the way down. Which is exactly why the controls behind the attestation are the only thing that actually protects you; the attestation itself protects no one. If you’re making these claims to customers or carriers, it’s worth having someone actually verify your vendor and partner attestations rather than taking a security questionnaire at face value. That’s the gap our vendor risk assessments and policy review work are built to close: turning attestations into documented, implemented controls instead of paperwork.

What to check instead of a seal

Next time a vendor’s site shows a “HIPAA Certified” badge, or a partner tells you they’re “fully compliant,” skip the badge and ask for the paper trail instead:

  • A recent, documented risk analysis: not a template, an actual assessment of their environment.
  • A signed BAA, if they touch PHI at all.
  • Any independent audit report they’re willing to share: a HITRUST r2 or SOC 2 Type II report is real evidence; a logo is not.

If they can’t produce any of that, the badge is just the box. Somebody’s willing to say it’s good. Nobody’s checked.

Get the promise checked

The self-attestation isn’t going away, and neither is the gap between what organizations claim and what they’ve actually implemented. Our HIPAA and NIST gap assessment exists to close that gap before OCR, a customer questionnaire, or a claims adjuster finds it first: a practical review of your actual environment, not a checklist exercise, with a prioritized list of what to fix. If you want to talk through where your organization actually stands, contact us or call (608) 448-6075.