Regulatory & Compliance

HIPAA has no certifying body, and enforcement is moving toward vendors

HHS states plainly that it recognises no private HIPAA certification. Business associates reported 139 of the 804 large breaches logged in 2025, and OCR's third round of audits is now examining them directly.

Key Notes
  • HHS recognises no private HIPAA certification, and a certificate does not reduce an entity's legal obligations
  • A brand that contracts clinicians through a professional corporation is usually a business associate rather than an outsider to HIPAA
  • Business associates have been directly liable since the 2013 Omnibus Rule, and subcontractors inherit the same status
  • The cybersecurity update to the Security Rule, published in January 2025, has not been finalised
  • Business associates reported 139 of the 804 large breaches logged in 2025, and OCR's Phase 3 audits are examining them directly

The question of who certifies HIPAA compliance has a public answer, and it has been sitting on the HHS website since 2003. Asked whether an organisation must certify its compliance with the Security Rule, the agency's guidance replies: "No, there is no standard or implementation specification that requires a covered entity to 'certify' compliance."

Then it goes further. "HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule."

That is narrower than it first sounds, and worth reading carefully. A third-party assessment is not worthless. It is evidence that somebody looked, it answers a procurement questionnaire, and a vendor who has been through one has usually fixed a few things on the way. What it does not do is transfer. The obligation stays where it was, and the Office for Civil Rights can open an action the week after a certificate is issued. So when "HIPAA compliant" appears on a vendor's site with the grammar of a credential, what sits behind it is that vendor's account of its own practices, and what the account covers varies by business model.

Where a brand that employs no clinicians sits

The badge is the less interesting question. What sets a brand's exposure is where it sits in the structure, and the answer tends to surprise people who assume that employing no clinicians puts them outside HIPAA altogether.

In a direct-to-consumer arrangement, the professional corporation that employs the clinicians and delivers the care is the covered entity. The patient-facing company contracting with it is a business associate, on the analysis law firms have published since the model became common. HHS defines a business associate as a person or organisation that creates, receives, maintains or transmits protected health information on behalf of a covered entity.

Business associate is not a junior version of covered entity. Since the 2013 Omnibus Final Rule, still the most recent finalised change to the HIPAA rules, business associates have been directly liable for the Security Rule, for breach notification, and for parts of the Privacy Rule. The liability attaches to the role rather than arriving through the contract, and it follows however the structure is arranged across states.

It also runs deeper than most brands map it. A subcontractor handling protected health information on behalf of a business associate is itself a business associate, so the agreement is needed at every link rather than only at the top. Count the links on an ordinary setup: telehealth partner, platform, pharmacy, analytics vendor. That is four.

What is moving in 2026

The cybersecurity update to the Security Rule is still a proposal. HHS published the notice of proposed rulemaking on 6 January 2025 and comments closed that March. It has not been finalised, and trade coverage now puts the final rule in 2027. A number of widely shared articles describe its requirements as though they already apply, so it is worth checking the date on anything a vendor cites.

Two things have moved the other way. The 2024 rule strengthening protection for reproductive health information was vacated nationwide by a Texas court in June 2025, and its attestation requirement went with it. The part of OCR's online tracking guidance that treated an IP address plus a visit to a health-related public page as protected information was vacated in June 2024, with OCR withdrawing its appeal that August. The rest of that guidance survived, which is the distinction most summaries lose.

Enforcement has kept moving while the rulemaking has not. OCR's third round of compliance audits has been running since March 2025 across 50 covered entities and business associates, focused on risk analysis and risk management. The backdrop is 804 large breaches in 2025 affecting around 138.5 million people, with business associates reporting 139 of them, up from 16 per cent of the total a year earlier. The true share is higher, because a vendor's breach is often reported by the covered entity it hit.

What this means for operators

Put those together and the shape is uncomfortable for a particular kind of company. A brand employing no clinicians does carry fewer obligations than a provider: less of the Privacy Rule, no treatment records of its own. The subset it does carry happens to be the subset regulators are currently working through.

How much weight to put on that is arguable. Fifty entities is a small audit sample, none of it has reported yet, and the rising business associate share of breaches partly reflects better attribution rather than worse security. The sceptical reading is a fair one. What makes the point worth acting on anyway is the asymmetry: the two things an audit asks for first are cheap to hold and expensive to assemble under pressure.

Those two are a signed business associate agreement at every link in the chain, including the links a brand never signed itself, and a risk analysis carrying a current date. Risk analysis is the failure named most often in settlements, which this year have run from the low tens of thousands into the high hundreds. Penalties are adjusted annually, and the cap for uncorrected wilful neglect now sits above two million dollars.

Neither is a certificate, and neither can be bought. They are also the two documents a brand built around a professional corporation is most likely to assume somebody else is holding.

No certificate shortens the list of things an operator is accountable for. The defensible position is the one that can be produced on request: a signed agreement at every link, and a risk analysis dated this year.

Back to the Newsroom

Launching a telehealth program without a compliance team?

FUSE supplies the infrastructure operators launch on, and partners with a telehealth company that contracts the provider network. Every clinical decision sits with an independent licensed provider.

Launch now!