Questions? Talk to a Real Person via our Live Chat
What Does “HIPAA Certified” Mean? The Truth About HIPAA Certification
By Gil Vidals, , HIPAA Blog, HIPAA Compliance, Resources

What Does “HIPAA Certified” Mean? The Truth About HIPAA Certification

The short answer: There is no official government-issued “HIPAA certification.” The U.S. Department of Health and Human Services (HHS) does not offer, endorse, or recognize any HIPAA certification program. When a vendor, software provider, or service claims to be “HIPAA certified,” that certification comes from a private third-party organization — not from HHS or any... Continue reading
What Does HIPAA Stand For?
By Brenda Medel, , HIPAA Blog, HIPAA Compliance, Resources

What Does HIPAA Stand For?

HIPAA stands for the Health Insurance Portability and Accountability Act. It is a federal law signed by President Bill Clinton on August 21, 1996. HIPAA establishes national standards for protecting sensitive patient health information — known as protected health information (PHI) — from being disclosed without a patient’s knowledge or consent. The law is administered... Continue reading
Who Needs to Be HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Compliance, Resources

Who Needs to Be HIPAA Compliant?

Healthcare organizations often ask the same critical question: who needs to be HIPAA compliant? The answer is broader than many companies realize. HIPAA compliance applies to more than hospitals and doctor’s offices. Health insurance companies, healthcare software vendors, cloud hosting providers, medical billing companies, and even email providers may all fall under HIPAA regulations depending... Continue reading
Is Google Analytics HIPAA Compliant?
By Alicia Kelley, , HIPAA Blog, HIPAA Compliance, Resources

Is Google Analytics HIPAA Compliant?

No — Google Analytics is not inherently HIPAA compliant. Healthcare organizations can use Google Analytics only in limited circumstances, and only if no Protected Health Information (PHI) is transmitted. If PHI is disclosed to Google without proper safeguards and agreements, it may constitute a HIPAA violation. Because many healthcare websites collect appointment requests, include condition-specific... Continue reading
2026 HIPAA Changes: Why HIPAA Security Is No Longer “Addressable”
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

2026 HIPAA Changes: Why HIPAA Security Is No Longer “Addressable”

The 2026 HIPAA changes mark a fundamental shift in how healthcare organizations must approach compliance. For the first time, HIPAA security is no longer about documenting intent — it’s about proving technical enforcement. As discussed on the HIPAA Insider Show with Adam Zeinnedine and HIPAA Vault CTO Gil Vidals, the proposed overhaul of the HIPAA... Continue reading