HIPAA is a US federal law governing the privacy and security of protected health information (PHI), enforced by the HHS Office for Civil Rights (OCR). There is no official HIPAA certification. HHS has stated this directly and repeatedly. Compliance is an ongoing legal obligation, evidenced by your actual safeguards and documentation — not a one-time credential.
Why We're Leading With What HIPAA Certification Isn't
Search "HIPAA certification" and you'll find dozens of vendors selling seals, badges, and certificates. HHS has been explicit that it does not endorse or recognize any of these private programmes, and that holding one "does not absolve covered entities of their legal obligations." A 2021 amendment to the HITECH Act does require HHS to consider "recognized security practices" when determining fines — but this is not the same as certification.
A framed certificate means nothing if OCR investigators ask for your Security Risk Assessment and find none. What actually protects you is the underlying compliance work: documented risk analysis, implemented safeguards, workforce training records, business associate agreements, and breach notification procedures.
What We Actually Help You Build
- Security Risk Assessment (SRA): the single most commonly cited deficiency in OCR enforcement actions
- Administrative, physical, and technical safeguards: documented policies and controls
- Privacy Rule policies: minimum necessary standard procedures, patient rights processes
- Breach Notification procedures: documented processes for identifying, assessing, and reporting breaches
- Business Associate Agreements: properly structured agreements with vendors and partners
- Workforce training records: documented, substantive training
Current Enforcement Reality
OCR enforcement is active and increasing: more than 20 enforcement actions resulted in settlements or civil monetary penalties in 2024 alone. OCR's Risk Analysis Initiative continues to specifically target organisations lacking a genuine, documented Security Risk Assessment. Phase 3 of OCR's compliance audit programme is currently underway.
Build Real Compliance Evidence
Free consultation. We assess your current gaps honestly and provide a fixed quote within 24 hours.
Get Free Consultation →Health-Tech Company?
SOC 2 and ISO 27001 are genuine, accredited certifications many health-tech buyers also expect.
Explore ISO 27001 →Real value of honest HIPAA readiness work
Based on outcomes reported by healthcare organisations we've advised.
Evidence That Actually Holds Up
Documented Security Risk Assessments and safeguards are what OCR investigates — not a certificate.
OCR-Relevant EvidenceAddresses the Most Common Deficiency
A missing or outdated Security Risk Assessment is the most frequently cited gap in OCR enforcement actions.
Root-Cause FixHonest, No False Assurance
We will never sell you a certificate implying government recognition that doesn't exist.
No OversellingFavourable Treatment Under HITECH
Demonstrating genuine, ongoing "recognized security practices" can lead to more favourable treatment in HHS penalty determinations.
HITECH-AlignedPairs Naturally with ISO 27001
For health-tech companies wanting a genuine, accredited security credential alongside HIPAA readiness.
Accredited PairingReady for OCR's Active Audit Program
With Phase 3 of OCR's compliance audit programme underway, genuine documented readiness matters more than ever.
Audit-ReadyWhat organisations say about London Cert's HIPAA advisory
Feedback from healthcare organisations and business associates we've worked with.
We'd bought a "HIPAA certificate" from another vendor years ago and never had a real Security Risk Assessment. London Cert was honest that the certificate meant nothing and helped us build the actual documentation we needed.
As a health-tech business associate, we needed genuine evidence for our enterprise clients' vendor risk assessments. London Cert's work gave us that, plus honest guidance on pairing with ISO 27001.
We appreciated that London Cert didn't try to sell us a meaningless seal. The Security Risk Assessment and policy work they did was genuinely thorough and gave our board real confidence.
