HIPAA is a US federal law that establishes national standards for the protection of protected health information (PHI). Covered entities and their business associates must comply with the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule.
Unlike SOC 2 or ISO 27001, HIPAA compliance is not certified by a third party — it is self-attested and enforced by the Office for Civil Rights (OCR). Vendors handling PHI on behalf of a covered entity must sign a Business Associate Agreement (BAA). TrustVendor tracks BAA availability, HIPAA attestation status, and any disclosed OCR enforcement actions.
Which vendors hold HIPAA?
Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.
Common questions about HIPAA
Which vendors hold HIPAA certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current HIPAA certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does HIPAA certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's HIPAA report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.