---
title: Who Certifies HIPAA Compliance?
description: Who Certifies HIPAA Compliance?
---

<https://safe.truevault.com/>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-pii)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/)
- Login
  
  [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com) [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

- [Resources](https://safe.truevault.com/learn/)
- Login

- Login
- [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com)
- [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

[Blog](https://safe.truevault.com/blog)

- [Home](https://www.truevault.com/index.html)
- [Blog](https://safe.truevault.com/blog)

# Who Certifies HIPAA Compliance?

By Jason Wang/ Published on January 4, 2014

The short answer is no one.

Unlike PCI, there is no one that can “certify” that an organization is HIPAA compliant. The Office for Civil Rights (OCR) from the Department of Health and Human Services (HHS) is the federal governing body here. And, HHS does not endorse or recognize the “certifications” made by private organizations.

There is an evaluation standard in the Security Rule § 164.308(a)(8), and it requires you to perform a periodic technical and non-technical evaluation to make sure that your security policies and procedures meet the security requirements. But, HHS doesn’t care if the evaluation is performed internally or by an external organization.

Having said all that, being evaluated by an independent, third party auditor is still a really good idea. Even though it is not official you should still do it. There are a number of great companies that can help. For example, Coalfire Systems ([http://www.coalfire.com](http://www.coalfire.com)) and ComplySmart ([http://www.complysmart.com](http://www.complysmart.com)) offer HIPAA Assessments.

Important. Even if you get a “certification” from an external organization HHS can still come in and find a security [violation](https://safe.truevault.com/what-is-the-penalty-for-a-hipaa-violation.html). Third party audits and “certifications” do not absolve you from your legal obligations under the Security Rule.

[![Get The HIPAA Compliant Checklist](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4693513/e7f4b6db-52ca-46a0-bd1e-cb24ace89926.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4693513/e7f4b6db-52ca-46a0-bd1e-cb24ace89926)

It is interesting to note that Texas was the first state in the nation to create a formal Covered Entity Privacy and Security Certification Program. The program was developed as part of Texas' House Bill (HB) 300. The Texas Health Services Authority (THSA) and the Health Information Trust Alliance (HITRUST) have partnered to implement the Certification Program. They will tell you that the Texas state law protecting patients' health information is more stringent than HIPAA. So in theory, if you are certified by the THSA, then you are ipso facto HIPAA compliant. Don’t hold me to that because HHS does not endorse or otherwise recognize this claim. But, considering the absence of a federal seal of approval this is a fantastic program and a step in the right direction.

If you have any questions about HIPAA compliance certification please talk to us today!

[![Talk To Our Team](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4693513/73a33362-e1a8-4c20-b594-5ea457730cf2.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4693513/73a33362-e1a8-4c20-b594-5ea457730cf2)

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control)

 Phillip Walters  / November 7, 2022

## [A Cookie Banner Isn't Enough for CCPA Compliance](https://safe.truevault.com/blog/a-cookie-banner-isnt-enough)

 Phillip Walters  / October 27, 2022

## [Why CCPA Compliance Matters to HR](https://safe.truevault.com/blog/why-ccpa-matters-to-hr)

 Phillip Walters  / October 21, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2024 © All Rights Reserved.  [Privacy Policy](https://privacy.truevault.com/privacy-policy)  |  [Terms of Use](https://www.truevault.com/legal/truevault-terms-of-use)  |  [Supplemental Terms](https://www.truevault.com/legal/truevault-supplemental-terms-of-use)<https://www.truevault.com/legal/truevault-terms-of-use> | [California Privacy Notice](https://privacy.truevault.com/privacy-policy#california-privacy-notice)