There is no government-issued "HIPAA certified" badge for IT companies or software. What exists is the Security Rule and its safeguards. Here is what those mean for a practice\u2019s technology, in plain language.
Published July 16, 2026 • Synergy Telecom & Medical Systems, Rome GA
Neither HHS nor its Office for Civil Rights certifies products, IT providers, or practices as HIPAA compliant. Vendors waving certificates are describing third-party attestations at best and marketing at worst.
What the law actually asks for is a set of safeguards under the Security Rule, applied to wherever electronic protected health information (ePHI) lives and moves in your practice. Compliance is a posture you maintain and document, not a plaque you buy. That framing changes how you evaluate every IT proposal you receive.
The administrative layer is where most enforcement attention lands, and it starts with a risk analysis: a documented look at where ePHI lives and what threatens it. It is required, and its absence is one of the most common findings in settlements.
Alongside it sit written policies, workforce training, access management (who can see what, and why), and business associate agreements with every vendor that touches ePHI. Our risk assessment guide covers what a proper analysis includes and costs.
The technical layer is where an IT provider earns their fee in a practice.
A note on encryption: the rule labels it "addressable," which some vendors misread aloud as optional. Addressable means you implement it or document a legitimate equivalent alternative. For a modern practice, the practical answer is simply to encrypt.
Server closets that lock, workstations angled away from waiting rooms, and a real procedure for wiping or destroying old drives and copiers before they leave the building.
Retired equipment is the classic miss. Hard drives in donated computers, leased copiers returned with images of scanned records, and drawers of old phones have all generated breach reports for practices that had the digital side handled.
The recurring gaps we see are rarely exotic:
Every one of these is fixable, and fixing them is cheaper than explaining them after an incident. The pattern behind all six is the same: the practice assumed somebody was handling it.
An IT provider that touches your systems touches ePHI, which makes them a business associate: they should offer to sign a BAA without being asked twice, and they should be able to explain these safeguards in your language.
That is the standard we build to on our HIPAA compliance and healthcare technology engagements across Northwest Georgia practices. If a proposal leads with a certificate instead of a safeguard conversation, keep interviewing.
Is there an official HIPAA certification for IT companies? No. HHS does not certify vendors, software, or practices. Third-party assessments can be useful evidence of good practices, but no certificate substitutes for the safeguards themselves or your own documented risk analysis.
Does HIPAA require encryption? Encryption is an addressable specification, which means you either implement it or document a legitimate equivalent alternative. In practice, encrypting devices and transmissions is the defensible answer for a modern practice, and it is built into most current tools.
Do small practices really face enforcement? Yes. Enforcement actions and settlements have included small and solo practices, and a missing risk analysis is one of the most frequently cited findings. Practice size changes the scale of the fine, not the applicability of the rule.
Does our IT company need to sign a BAA? If they can access systems holding ePHI, yes, they are a business associate and a BAA is required. A provider that hesitates on this question is telling you something important about their healthcare experience.
Want your current setup checked against these safeguards? Contact us for a plain-language review built for practices.
The Security Rule in one card. Documentation ties all three together.
Related reading: Risk assessment scope & cost • EHR support options