The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law governing how protected health information (PHI) is used, disclosed and safeguarded. It applies to covered entities — healthcare providers, health plans and clearinghouses — and to the business associates that handle PHI on their behalf.
There is no such thing as HIPAA certification. The US Department of Health and Human Services does not recognize, endorse or accredit any HIPAA certification, and no certificate provides a safe harbor in an OCR investigation. What the Security Rule does require is a documented risk analysis and a periodic technical evaluation — and that is what we deliver.



HIPAA applies to covered entities — such as healthcare providers, health plans and clearinghouses — and their business associates.
Digital health and telehealth platforms, EHR and practice management vendors, medical billing and revenue cycle companies, health plans, and any business associate whose covered-entity customers are asking for evidence before renewing a BAA.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.