legal
HIPAA evidence across 15 vendors
There is no HIPAA certification. HHS declined to create certification criteria in the Security Rule preamble (68 FR 8334, 20 February 2003). The artefact that matters is a business associate agreement, so CertReports records whether a vendor offers a BAA, where it says so, and when that was captured.
- Verified rows
- 0
- Vendor-stated
- 15
- Expired
- 0
- Last verified
- 17 Sep 2026
Datadog
DevOps and observability
Snowflake
Data platforms
Drata
Compliance and GRC
Cyera
Security
Wiz
Security
Okta
Identity and access
Twilio
Communications and CPaaS
Fortinet
Security
Diligent
Compliance and GRC
Axon
Government and public sector
Intercom
Customer support
Vercel
Cloud and hosting
Bird
Communications and CPaaS
The world’s largest omnichannel communications platform
Otter.ai
Communications and CPaaS
Axiom
Analytics
What "HIPAA compliant" means on a marketing page
It is a vendor claim. The verifiable facts are a BAA (public, on request or not offered), a HIPAA-mapped SOC 2 or HITRUST assessment, and the products the BAA covers.
Which products the BAA covers
Many vendors sign a BAA only for specific plans or products. Confirm the covered products with the vendor before sending protected health information.