SOC 2 Auditors

HIPAA

US law · $10K–$60K · varies

Controls
HIPAA Security, Privacy, and Breach Notification Rules
Recertification
No certificate; ongoing legal obligation
Oversight
US Dept. of Health & Human Services (OCR)
Common gaps
Risk analysis, BAAs, access controls, encryption
Related
HITRUST CSF, SOC 2 Type 2
Public registry
HHS.gov

What is HIPAA?

HIPAA is a US law governing how protected health information (PHI) is handled. It is a legal obligation, not a certification, so there is no official HIPAA certificate.

Is HIPAA a certification or an attestation?

Neither — HIPAA compliance is a legal requirement. Vendors typically demonstrate it via a third-party HIPAA assessment, often bundled with SOC 2.

Who needs HIPAA?

Any company that creates, receives, stores, or transmits PHI — health-tech vendors and their sub-processors (business associates).

What does it cost and how long does it take?

A third-party HIPAA assessment is often scoped alongside SOC 2; cost depends on overlap and the size of the PHI environment.

Sources

Get 3 quotes that fit.

Tell us your stage, framework, and timeline once. We match you with three firms that fit — one short call, not five sales pitches.

Free for buyers · No spam · Independent of every firm listed