Healthcare IT

What HIPAA-Compliant IT Actually Requires

There is no government-issued "HIPAA certified" badge for IT companies or software. What exists is the Security Rule and its safeguards. Here is what those mean for a practice\u2019s technology, in plain language.

Published July 16, 2026 • Synergy Telecom & Medical Systems, Rome GA

Start here: "HIPAA certified" is not a thing

Neither HHS nor its Office for Civil Rights certifies products, IT providers, or practices as HIPAA compliant. Vendors waving certificates are describing third-party attestations at best and marketing at worst.

What the law actually asks for is a set of safeguards under the Security Rule, applied to wherever electronic protected health information (ePHI) lives and moves in your practice. Compliance is a posture you maintain and document, not a plaque you buy. That framing changes how you evaluate every IT proposal you receive.

Administrative safeguards: the paperwork with teeth

The administrative layer is where most enforcement attention lands, and it starts with a risk analysis: a documented look at where ePHI lives and what threatens it. It is required, and its absence is one of the most common findings in settlements.

Alongside it sit written policies, workforce training, access management (who can see what, and why), and business associate agreements with every vendor that touches ePHI. Our risk assessment guide covers what a proper analysis includes and costs.

Technical safeguards: what your IT setup must do

The technical layer is where an IT provider earns their fee in a practice.

  • Unique logins for every user (no shared accounts)
  • Multi-factor authentication in practice, not just policy
  • Encryption for data at rest and in transit
  • Audit logging of who accessed what
  • Automatic logoff on unattended workstations
  • Backups that are tested, not assumed

A note on encryption: the rule labels it "addressable," which some vendors misread aloud as optional. Addressable means you implement it or document a legitimate equivalent alternative. For a modern practice, the practical answer is simply to encrypt.

Physical safeguards: the unglamorous layer

Server closets that lock, workstations angled away from waiting rooms, and a real procedure for wiping or destroying old drives and copiers before they leave the building.

Retired equipment is the classic miss. Hard drives in donated computers, leased copiers returned with images of scanned records, and drawers of old phones have all generated breach reports for practices that had the digital side handled.

Where practices actually fall short

The recurring gaps we see are rarely exotic:

  • Shared logins at the front desk
  • PHI in ordinary text messages
  • Vendors with no signed BAA on file
  • Consumer file-sharing tools holding patient documents
  • Backups that have never been restore-tested
  • No risk analysis anyone can produce

Every one of these is fixable, and fixing them is cheaper than explaining them after an incident. The pattern behind all six is the same: the practice assumed somebody was handling it.

What this means for choosing IT help

An IT provider that touches your systems touches ePHI, which makes them a business associate: they should offer to sign a BAA without being asked twice, and they should be able to explain these safeguards in your language.

That is the standard we build to on our HIPAA compliance and healthcare technology engagements across Northwest Georgia practices. If a proposal leads with a certificate instead of a safeguard conversation, keep interviewing.

HIPAA IT: FAQs

Is there an official HIPAA certification for IT companies? No. HHS does not certify vendors, software, or practices. Third-party assessments can be useful evidence of good practices, but no certificate substitutes for the safeguards themselves or your own documented risk analysis.

Does HIPAA require encryption? Encryption is an addressable specification, which means you either implement it or document a legitimate equivalent alternative. In practice, encrypting devices and transmissions is the defensible answer for a modern practice, and it is built into most current tools.

Do small practices really face enforcement? Yes. Enforcement actions and settlements have included small and solo practices, and a missing risk analysis is one of the most frequently cited findings. Practice size changes the scale of the fine, not the applicability of the rule.

Does our IT company need to sign a BAA? If they can access systems holding ePHI, yes, they are a business associate and a BAA is required. A provider that hesitates on this question is telling you something important about their healthcare experience.

Want your current setup checked against these safeguards? Contact us for a plain-language review built for practices.

The Three Safeguard Layers

The Security Rule in one card. Documentation ties all three together.

• Administrative: risk analysis, policies, training, BAAs
• Technical: access, MFA, encryption, logging, backups
• Physical: facility access, workstations, media disposal
Get a Practice IT Review

Related reading: Risk assessment scope & costEHR support options