There is no HIPAA certification and no HIPAA registry. The Department of Health and Human Services does not certify vendors, and no badge on a trust centre changes that. What exists is a contract, the business associate agreement (BAA), whose required content the Privacy Rule sets out at 45 CFR 164.504(e). Send protected health information (PHI) to a vendor without one and the covered entity, not the vendor, is the party in breach. This checklist covers the clauses the rule requires, the places vendors narrow them, and the order in which to check.
- 35.8%
- of 2025 healthcare data breaches occurred at business associates
- HIPAA Journal, 2025 healthcare data breach report
- 21
- OCR enforcement actions resolved in 2025
- Second-highest annual count in HIPAA history
- 0
- HIPAA certifications that exist
- HHS does not certify vendors or products
Why the contract is the evidence
HIPAA regulates covered entities (providers, plans, clearinghouses) and their business associates (anyone that creates, receives, maintains or transmits PHI on their behalf). The Privacy Rule allows a covered entity to share PHI with a business associate only under a contract with specific content, and since the 2013 Omnibus Rule business associates are directly liable for Security Rule compliance and for their own subcontractors. The BAA is therefore both the permission and the allocation of liability. A vendor that says it is "HIPAA compliant" and will not sign a BAA is offering nothing a covered entity can use.
The contract must establish the permitted and required uses and disclosures of protected health information by the business associate.
The ten required elements
| Clause | What 164.504(e) requires | Where vendors narrow it |
|---|---|---|
| Permitted and required uses | Only what the contract allows and the law requires | Excludes support tickets, analytics, product improvement or AI training unless named |
| No further use or disclosure | None beyond the contract or as required by law | De-identification carve-outs; check the standard used |
| Safeguards | Appropriate safeguards; Security Rule compliance for ePHI | Points to the vendor’s own programme; ask for the SOC 2 or ISO evidence behind it |
| Reporting | Report any use or disclosure not provided for, any security incident, any breach of unsecured PHI | Reporting windows of 30 to 60 days; "unsuccessful" incidents reported in aggregate |
| Subcontractors | Flow the same restrictions down in writing | A named subprocessor list with a change notice period |
| Individual rights | Support access (164.524), amendment (164.526), accounting (164.528) | "Reasonable assistance" only; check response times |
| Covered entity obligations | Comply with the Privacy Rule where performing the covered entity’s duties | Rarely limited |
| Books and records | Make internal practices available to HHS | Rarely limited |
| Termination | Return or destroy PHI, or extend protections if infeasible | Destruction after a retention window; backups excluded for a period |
| Authorised termination | Covered entity may terminate for material breach | Cure periods of 30 days or more |
The first column follows 164.504(e)(2). The third column is what CertReports sees most often in published BAAs.
Where vendors limit the BAA
Most published BAAs are narrower than the marketing page. Three limits matter most. The covered products: often only an enterprise tier, and never beta features. The covered features: AI assistants, integrations, marketplace apps and support attachments are frequently excluded. The configuration you must apply: encryption settings, audit logging, retention and sharing controls that are your responsibility to switch on. A "HIPAA eligible" service is one you can configure to be covered, not one that is covered by default.
The covered services definition
Read the definition of "Covered Services" or "HIPAA Eligible Services" before anything else. Large cloud providers publish a list of eligible services and everything not on the list is out of scope. SaaS vendors tie coverage to a plan tier. If your plan or feature is not named, the BAA does not cover you, whatever the sales deck said.
Breach timing
Under 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Covered entities then owe individuals notice within 60 days of their own discovery under 164.404. A BAA that gives the vendor the full 60 days leaves you with little time; many covered entities negotiate ten business days or fewer.
The checklist
- 1
Confirm the vendor offers a BAA at all
Look on the trust centre or legal page. CertReports records a public BAA offer as a HIPAA row with a source link. No public offer means "no public evidence", not "no BAA"; ask. The HIPAA hub lists every vendor with a public offer. - 2
Match products and tiers to the order form
Read the covered services definition. If your plan is not listed, stop here and ask for a written confirmation or an upgrade.
- 3
Read the exclusions
AI features, beta features, support attachments, marketplace apps and integrations are the usual carve-outs. Decide whether your workflow touches any of them.
- 4
Check the configuration duties
Many BAAs require you to enable encryption, restrict sharing or disable features. Assign an owner to each duty before go-live and record it.
- 5
Check subprocessors and flow-down
The vendor must bind its subcontractors to the same terms. Ask for the subprocessor list and the notice period for changes.
- 6
Check reporting windows against your own duties
Compare the vendor’s incident and breach reporting timelines with 164.410 and your own 60-day clock under 164.404.
- 7
Ask for the security evidence behind it
A BAA says the vendor will safeguard PHI; a SOC 2 Type II or ISO 27001 certificate shows that someone checked. See healthcare vendors with public HIPAA evidence and their other frameworks.
What 2025 enforcement tells a buyer
Business associates are now the fastest-growing source of healthcare breaches. HIPAA Journal’s 2025 report puts 35.8 percent of reported breaches at business associates against 57.5 percent at providers, and the largest breach of the year, at Conduent Business Services, exposed the PHI of more than 62 million people through a business associate. OCR resolved 21 enforcement actions in 2025, and the finding that recurs across them is the absence of an accurate risk analysis before the incident. For a buyer, that is the question to put to a vendor: when was your last risk analysis, and does your SOC 2 or ISO scope cover the systems that will hold our PHI?
Business associates have become the single fastest-growing source of healthcare data breaches.
What CertReports says and does not say
A "vendor-stated" HIPAA row on CertReports means the vendor publicly offers a BAA and the index captured the page with a date and a snapshot. It never means the vendor is HIPAA compliant, because compliance is a property of how you use the service under the contract, not of the vendor alone. There is no registry to verify against, which is why HIPAA rows are never registry-verified.
If you are the vendor
Publish the BAA, the covered services list and the configuration duties on your trust centre. Reviewers will find them in minutes instead of asking sales, and the CertReports row will link straight to them.
People also ask
What must a HIPAA business associate agreement include?
The elements in 45 CFR 164.504(e)(2): permitted uses and disclosures, no further use, safeguards, reporting of incidents and breaches, subcontractor flow-down, support for individual rights, Privacy Rule compliance where applicable, HHS access to books and records, and return or destruction at termination.
Can a SaaS company be HIPAA certified?
No. HHS does not certify vendors or products. A vendor can sign a BAA and can hold SOC 2 or ISO 27001 evidence for its safeguards, but "HIPAA certified" describes nothing that exists.
What is the difference between HIPAA eligible and HIPAA compliant?
Eligible means the vendor will cover the service under a BAA if you configure it as required. Compliant is a property of the whole arrangement, including your configuration and your own policies, not a label a vendor can carry alone.
Who is liable if a business associate breaches PHI?
Since the 2013 Omnibus Rule, business associates are directly liable for Security Rule compliance and for their subcontractors. The covered entity remains responsible for having a compliant BAA in place and for its own notification duties.
How quickly must a business associate report a breach?
Without unreasonable delay and no later than 60 days after discovery, under 164.410. Many covered entities negotiate shorter windows in the BAA because their own 60-day clock to notify individuals starts at their discovery.
Do subcontractors of a business associate need a BAA?
Yes. The business associate must bind any subcontractor that handles PHI to the same restrictions in writing. Ask for the subprocessor list and confirm each entry is covered.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
A 30-minute vendor security review using public evidence
Solomon Amos · 30 Aug 2026 · 11 min read