A contracting coordinator at a regional health system sends your office manager a portal link with eleven required uploads. Field seven reads: HIPAA certification certificate (PDF, required). Ten business days to complete, or the referral agreement stalls. Your practice has never had anything called a HIPAA certification, because the federal government does not issue one — and yet you still have to put something in that field by January 8.

This article is for the person who has to answer that request: the practice owner, privacy officer, or compliance lead. It covers what "HIPAA certification" means when a buyer, insurer, or auditor asks for it, what documentation actually satisfies them, what the Office for Civil Rights looks for instead, and how to assemble the package in under two weeks.

Is HIPAA Certification Required by Law? (Short Answer)

No. HIPAA contains no certification requirement, and HHS does not certify, accredit, or endorse any organization, training course, or software product as HIPAA compliant. There is no federal registry of certified practices. Any certificate you hold was issued by a private company — a training vendor, an auditing firm, or a consultant — and it attests only to what that private company reviewed on the date it looked.

What the law does require is documentation: a current security risk analysis, written policies and procedures, workforce training records, signed business associate agreements, and a documented breach response process. Those obligations live in the Privacy, Security, and Breach Notification Rules, and they are what OCR asks for when it opens an investigation. A certificate is not a substitute for any of them.

What HIPAA Certification Actually Means in Practice

The phrase gets used for three different things. Knowing which one your requester means saves you a week of email.

Individual training completion certificates

Most often, "HIPAA certification" means a per-person training certificate. Your medical assistant finishes a two-hour course, downloads a PDF with her name and a completion date, and that PDF goes in her personnel file. This is legitimate and useful — the Security Rule requires a security awareness and training program for all workforce members under 45 CFR 164.308(a)(5), and the Privacy Rule requires training on policies and procedures under 164.530(b).

What makes the certificate defensible is not the word "certified" on it. It is the surrounding record: who took it, on what date, which modules, how long, who assigned it, and what you did about the person who never completed it. Keep a training roster spreadsheet with those columns and reconcile it against your active employee list every quarter.

Organizational attestations and third-party assessments

Larger buyers usually mean something else: an independent assessment of your organization. In practice that means a SOC 2 Type II report, a HITRUST CSF validated assessment, or a written gap assessment letter from a security firm. These cost real money and take months. A four-provider orthopedic practice does not need one to accept referrals; a billing company processing claims for 300 practices probably does.

Certified health IT — a genuinely different thing

ONC-certified health IT is a formal program, run through the ONC Health IT Certification Program and searchable in the Certified Health IT Product List. That certification covers functionality and interoperability criteria for EHR modules. It is not a HIPAA certification, and it does not mean your configuration of that product is compliant. Your access controls, audit log review, and user provisioning are still yours to document.

The Seven Documents Enterprise Buyers Ask For Instead

When you push back on the certificate field and ask what the requester actually needs, you will get some subset of this list. Build all seven and you can answer nearly any questionnaire in an afternoon.

  1. Security risk analysis — a current, written, organization-wide assessment of risks to ePHI, with identified vulnerabilities, likelihood and impact ratings, and assigned remediation owners. HHS has published final guidance on risk analysis that describes the required elements.
  2. Risk management plan — what you are doing about the findings, with target dates and evidence of closure.
  3. Written policies and procedures — Privacy, Security, and Breach Notification, dated and version-controlled, with an approval signature.
  4. Training records — the roster described above, plus your sanction policy for noncompliance.
  5. Business associate agreement — the executed BAA between you and the requesting entity, plus your vendor list showing BAAs are in place downstream.
  6. Incident response and breach notification procedure — including who declares an incident, the 60-day notification clock, and your log of incidents that did not rise to breaches.
  7. Contingency plan — data backup, disaster recovery, and emergency mode operations, with a documented restore test.

Notice what is absent: a certificate. Notice also that six of the seven are documents you were already obligated to maintain. The questionnaire is not asking you to do new work. It is asking whether you did the existing work.

Worked Example: Ten Business Days to Answer the Questionnaire

Take the scenario from the top. Here is a realistic split of the work for a practice with one privacy officer, an office manager, and an outside IT provider.

Days 1–2 (privacy officer). Email the contracting coordinator: "HIPAA does not include a federal certification program. I can provide our current security risk analysis summary, policy index, workforce training log, and executed BAA. Confirm this satisfies field seven." In most cases it does. Get that confirmation in writing and save it in the vendor file.

Days 2–4 (privacy officer plus IT). Pull the last risk analysis. Check the date. If it predates your last EHR migration, new location, or move to remote scheduling staff, it is stale — the analysis has to reflect your current environment, not the one you had in 2022. Update the asset inventory first: every system, device, and third party that touches ePHI.

Days 4–6 (office manager). Reconcile the training roster. Two people hired in August have no completion record. Assign the course, set a five-day deadline, document the assignment. Incomplete training discovered and fixed is a far better record than incomplete training nobody noticed.

Days 6–8 (privacy officer). Audit the BAA list. Walk your vendor spend for the year and flag anyone who creates, receives, maintains, or transmits PHI on your behalf: transcription, answering service, shredding, cloud backup, IT support, billing, patient reminder platform, secure messaging. Find the missing agreements.

Days 8–10. Assemble a single indexed PDF. Cover page with your practice name, the compliance contact, and the date. Upload. Calendar the next review for twelve months out.

When a Vendor Tells You They're "HIPAA Certified"

This is where most practices get hurt. A scheduling platform's website says "HIPAA certified" in the footer, your office manager reads that as "we can skip the paperwork," and eighteen months later there is no signed BAA for a system holding 40,000 appointment records with patient names and reasons for visit.

A vendor's self-declared certification is a marketing claim, not a contract. Under 45 CFR 164.502(e) and 164.308(b), you need a written business associate agreement with satisfactory assurances before that vendor touches PHI. When a subcontractor is involved, the BAA has to flow down. If the vendor won't sign one, the vendor cannot have your PHI — regardless of what its footer says.

Three questions to ask any vendor claiming certification: Who issued it, what was the scope, and what date does it cover? A 2023 assessment of a product you're buying in 2025 tells you little. A training certificate for the CEO tells you nothing about the engineer with production database access.

If you are the one being asked to produce an agreement — or you have found four vendors on your list with no BAA on file — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same day. One-time purchase, no subscription, which matters when you need three agreements this week and none next month.

Recognized Security Practices: The Evidence That Actually Moves OCR

The 2021 HITECH amendment (Public Law 116-321) directs HHS to consider whether a regulated entity had recognized security practices in place for the prior twelve months when it determines fines, calculates penalties, or sets the terms of a resolution agreement. This is the closest thing in law to a benefit for voluntary security work — and it is explicitly not a certification. It is a twelve-month evidentiary record.

Recognized security practices include the NIST Cybersecurity Framework and practices developed under Section 405(d) of the Cybersecurity Act of 2015. To claim them, you need dated artifacts spanning that year: policy approval dates, training completion timestamps, vulnerability scan reports, patch logs, access review sign-offs. A certificate purchased last Tuesday does nothing for you here. Twelve months of quarterly access reviews does.

NIST's SP 800-66 Revision 2 maps HIPAA Security Rule requirements to the Cybersecurity Framework and is the most practical free crosswalk available. Use it to structure your risk analysis so the same document serves both purposes.

What HHS proposed in January 2025

HHS published a proposed Security Rule update in January 2025 that would, among other changes, require regulated entities to conduct compliance audits at least annually and to obtain written verification from business associates that technical safeguards are deployed. As of today, December 24, 2025, that rule is not final. Do not restructure your program around a proposal — but do note the direction: more documented verification, on a fixed cadence, from named parties.

Retention: Six Years, and Why the Certificate Date Matters

Under 45 CFR 164.316(b)(2)(i), required Security Rule documentation must be retained for six years from the date of creation or the date it last was in effect, whichever is later. Same six-year clock applies to Privacy Rule documentation under 164.530(j).

Apply that to training certificates. An employee who left in 2021 still has records you keep until 2027. A policy retired in 2024 stays in the archive until 2030. Build a folder structure by year and never delete on instinct — when OCR requests documentation covering a 2022 incident, "we replaced that policy" is not an answer.

Also worth reviewing: your breach log. Breaches affecting fewer than 500 individuals for calendar year 2025 must be reported to HHS no later than 60 days after the end of the year — that is March 1, 2026. Submissions go through the HHS breach reporting portal. If you have small incidents logged from February and July, put that filing on the January calendar now.

Build the Binder Before Someone Asks

The practices that handle certification requests calmly are the ones that already have the seven documents current, indexed, and dated. The ones that panic are the ones assembling a risk analysis from scratch while a referral agreement sits unsigned.

Pick a quarter — Q1 2026 is right there — and assign each of the seven items an owner and a completion date. Then treat the questionnaire as what it is: a request for a copy of work you finished months ago.

If your risk analysis, policy set, and compliance documentation need to be built rather than dusted off, automated HIPAA risk analysis and policy generation will get you a defensible baseline faster than a consultant's calendar allows. And when the next vendor asks you to paper an arrangement, draft the business associate agreement and get it executed the same week — not the same quarter.