Skip to content

INSIGHTS / Jun 9, 2026 · 2 MIN READ

HIPAA-aware is a posture, not a certificate

There is no such thing as HIPAA-certified software. What exists is a set of habits — and you can tell within one meeting whether a vendor has them.

Haven Technologies

HealthtechCompliance

A vendor who tells you their software is "HIPAA certified" has told you something important — just not what they intended. There is no HIPAA certification. No government body issues one; no auditor can sell you one. HHS itself says so.

What exists instead is a posture: a set of habits that make a product defensible when someone — a patient, an auditor, a breach investigator — asks hard questions. That's why we say HIPAA-aware, and mean something specific by it.

What the posture looks like in software

  • Access control that maps to roles, not convenience. The front desk sees schedules; billing sees claims; nobody sees everything because it was easier to build that way.
  • Audit logs from the first commit. Who viewed what, who changed what, and when. Retrofitting an audit log is one of the most expensive line items in healthtech — building it early is one of the cheapest.
  • Encryption at rest and in transit, boringly. This one is table stakes, which is exactly why its absence is so telling.
  • A map of where PHI goes. Every vendor in the chain — hosting, email, analytics, AI providers — either signs a BAA or never sees protected data. If a vendor can't produce this map, the map doesn't exist.
  • Documentation your compliance counsel can read. Not a badge on a landing page: an architecture memo, in plain language, that invites challenge.

What the posture is not

It is not a substitute for the covered entity's own obligations. HIPAA compliance belongs to organizations, not code — policies, training, risk analysis, breach procedures. Software can make those obligations easier or harder to meet. It cannot meet them for you, and a vendor who implies otherwise is selling comfort, not compliance.

The one-meeting test

Ask a prospective vendor two questions. First: "Are you HIPAA certified?" The right answer explains why that's not a thing. Second: "Where does PHI flow in your architecture?" The right answer is a diagram, or an offer to produce one.

Vendors with the posture answer both without flinching. Vendors without it reach for the badge.

Agree with how we think? See how we build.

Ten minutes with the Brain, a structured brief, and a fixed-scope plan within 48 hours.

Start a project