✨ Standpoint covers HIPAA readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / HIPAA
Privacy · Regulation (binding)

HIPAA

HIPAA — the Health Insurance Portability and Accountability Act — is the U.S. law that protects people's health information. If a customer, a hospital, or a health-plan partner is asking whether you're "HIPAA compliant," here's the plain-language version: what HIPAA is, who has to follow it, the three main rules (Privacy, Security, and Breach Notification), why there is no official HIPAA certificate, and a practical path to get your Security Rule safeguards in order. HIPAA is U.S. public law, so we can describe its requirements directly — this is our own plain-language summary, not the statutory text.

What
HIPAA (the Health Insurance Portability and Accountability Act of 1996) sets national rules for protecting individuals' health information,…
Who
"Covered Entities" (health plans, most health-care providers, and clearinghouses) and their "Business Associates" (vendors that handle protected health information (PHI) on their behalf).
PHI
Protected Health Information — individually identifiable health data; when it's electronic it's called ePHI (electronic PHI).
The three rules
the Privacy Rule (how PHI may be used and disclosed), the Security Rule (safeguards for ePHI — Administrative, Physical, and Technical),…
// What Standpoint gives you

HIPAA Security Rule checklist

A safeguard-by-safeguard readiness checklist.

Free readiness assessment

See your HIPAA gaps in minutes.

Map to other frameworks

How HIPAA lines up with NIST 800-53, ISO 27001 & SOC 2.

// What the framework covers
Privacy RuleGAP
Security RulePARTIAL
Breach Notification RuleDONE

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is HIPAA?

HIPAA is a federal law, not a certification or a product. Passed in 1996 and expanded over the years (notably by the HITECH Act in 2009), it establishes national standards for keeping health information private and secure. The rules that most organizations work through today were issued by HHS and are administered by its Office for Civil Rights. Because HIPAA is public law, its requirements are freely available — but "being HIPAA compliant" is something you build and evidence, not a badge you buy.

Who must comply?

HIPAA reaches two groups: - Covered Entities — health plans, health-care clearinghouses, and most health-care providers that transmit health information electronically (for example, a clinic, a hospital, or an insurer). - Business Associates — vendors and contractors that create, receive, maintain, or transmit PHI on a Covered Entity's behalf (for example, a billing service, an IT provider, or a SaaS platform that processes patient data). Subcontractors of Business Associates are also on the hook. The link between them is the Business Associate Agreement (BAA) — the contract that permits a vendor to handle PHI and spells out how it must be protected. If you handle PHI for someone else and there's no signed BAA in place, that's a gap to close before anything else.

The three main HIPAA rules

Most technical readiness work centers on the Security Rule, because that's where the concrete safeguards for your systems live. The Security Rule is deliberately scalable — what's reasonable and appropriate depends on your size, complexity, and risk — and it's built around a formal risk analysis that drives everything else.

Is there a HIPAA certification?

No. There is no official government HIPAA certificate, and OCR does not endorse or accredit any "HIPAA certified" seal. What you can do is attest to compliance and demonstrate it — a documented risk analysis, written policies and procedures, implemented safeguards, signed BAAs, training records, and an incident/breach process. Third-party assessments or readiness reviews can help, but they don't produce a legally binding certification. When someone asks if you're "HIPAA certified," the honest, defensible answer is: here is our documented compliance program and the evidence behind it.

A practical path to readiness

- Map your PHI. Know where ePHI is created, received, stored, and transmitted — and which vendors touch it. - Run a risk analysis. The Security Rule's cornerstone: identify risks to ePHI and rate them. - Close the safeguard gaps. Work Administrative, Physical, and Technical safeguards in turn. - Get your BAAs in order. A signed Business Associate Agreement with every vendor that touches PHI. - Prepare for breaches. Have an incident and breach-notification process ready before you need it. The fastest start is a gap assessment. Our free HIPAA readiness assessment shows where you stand, and the …

Frequently asked questions

Q: Is there a HIPAA certification? A: No. There is no official government HIPAA certificate, and no seal that legally certifies compliance. You demonstrate compliance through a documented risk analysis, policies, implemented safeguards, signed BAAs, training, and a breach process. Third-party readiness reviews can help but don't produce a binding certification. Q: Who needs to comply with HIPAA? A: Covered Entities — health plans, clearinghouses, and most health-care providers — and their Business Associates, meaning vendors that handle protected health information (PHI) on their behalf. Subcontractors of Business Associates are covered too. The Security Rule groups safeguards for electronic PHI into three families: Administrative (risk analysis, workforce training, access management, contingency planning), Physical (facility, workstation, and device controls), and Technical (access control, audit controls, integrity, and transmission security such as encryption). A BAA is the contract between a Covered Entity and a vendor (Business Associate) that permits the vendor to handle PHI and sets out how it must protect that data and report incidents. If a vendor touches PHI without a signed BAA, that's a compliance gap. If a SaaS vendor creates, receives, stores, or transmits PHI for a Covered Entity, it is a Business Associate and must comply — including signing a BAA and meeting the Security Rule. A SaaS product that never handles PHI (like Standpoint, which prohibits PHI and only tracks your controls and evidence) is not acting as a Business Associate. This article is general information, not legal advice, and is Standpoint's own plain-language summary of a public U.S. law. Consult the official HIPAA rules and a qualified privacy or legal advisor for authoritative requirements. Standpoint is a self-assessment aid — not a certification, attestation, or legal advice — and does not store PHI.

HIPAA work counts elsewhere too

The crosswalk maps your HIPAA evidence onto the frameworks it overlaps — so you move forward on several at once.

ISO 27001SOC 2NIST 800-53

Get your HIPAA readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →