If a healthcare AI vendor tells you it is "HIPAA certified," you have learned something useful — just not what they intended.
The short answer
There is no HIPAA certification. No government body issues one, and HHS says so directly:
"HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations." — HHS.gov, HIPAA FAQ on Security Rule certification
Elsewhere OCR is blunter still, warning about misleading marketing and stating that HHS and OCR "do not certify any persons or products as 'HIPAA compliant.'" (OCR guidance)
So when a vendor says "HIPAA compliant," they are making a self-assessment. That is not automatically dishonest — but it is a claim, and it should be checked like one.
What to ask for instead
One document does the work a hundred badges cannot: a signed business associate agreement.
A BAA is a contract, so it is enforceable, and under the HITECH Act business associates are directly liable for Security Rule violations — HHS notes they are "civilly and criminally liable for penalties for violations of these provisions."
HHS specifies what a BAA must do. A written contract between a covered entity and a business associate must, among other things:
- Establish the permitted and required uses and disclosures of PHI
- Provide that the vendor will not use or disclose it otherwise
- Require appropriate safeguards, including Security Rule requirements for ePHI
- Require the vendor to report breaches and security incidents to you
- Require them to make PHI available for individuals' access, amendment, and accounting requests
- Require them to make internal practices and records available to HHS
- Require return or destruction of PHI at termination, where feasible
- Bind subcontractors to the same restrictions
- Allow you to terminate if they violate a material term
(HHS, Business Associate Contracts)
Read that list against any vendor's standard BAA. If something is missing or watered down, that is a real finding — far more informative than whether their homepage has a shield icon.
The questions worth asking
Ask every AI vendor these, and get the answers in writing:
- Will you sign a BAA? If no, they cannot handle PHI. The conversation ends there.
- May we see your most recent security risk analysis? OCR has repeatedly identified deficient risk analysis as among the most common failings in its investigations. A vendor with no risk analysis has skipped the foundational requirement.
- Which subprocessors touch PHI? Model providers, cloud hosts, telephony vendors. Each is a link in the chain, and each needs its own BAA with your vendor.
- Is PHI used to train models — ours or anyone's? Older BAA templates predate this question, so it is frequently unaddressed. Get it answered explicitly.
- What is your breach notification timeline, in hours? HIPAA requires notice; the contract sets the clock.
- What happens to our PHI when we leave? Returned, destroyed, or retained — and on what schedule.
Why "HIPAA compliant" is a legal risk, not just weak marketing
This is the part most buyers miss. The label is not merely unhelpful — regulators have treated it as potentially deceptive.
The FTC has taken the position that representations implying a government determination that does not exist can be deceptive under Section 5 of the FTC Act. Attorneys writing for healthcare buyers now say it plainly: "HIPAA Compliant" Is Not a Certification, and a vendor displaying a HIPAA "seal" is making a self-assessment, nothing more.
And crucially: using a vendor that claims compliance does not transfer your obligation. A covered entity must obtain satisfactory assurances that its business associates safeguard PHI. If the vendor turns out to be careless, you did not outsource the responsibility — you outsourced the work.
What about SOC 2, ISO 27001, and HITRUST?
These are real, but they answer different questions than people assume.
| What it is | What it is not | |
|---|---|---|
| SOC 2 | An attestation by an accounting firm that controls were designed (Type I) or operated over a period (Type II) | A HIPAA determination, or a government certification |
| ISO 27001 | Certification of an information security management system by an accredited registrar | Healthcare-specific, or a substitute for a BAA |
| HITRUST | A private framework that maps to HIPAA, NIST, ISO and others, independently assessed | An OCR determination or proof of HIPAA compliance |
All three are genuine evidence that a vendor has controls and had someone examine them. None replaces the BAA, and none is a finding by HHS.
One practical note on SOC 2: ask which report and what period. "SOC 2 Type II" means an auditor observed controls over an observation window — so there is a report, a named auditor, and a date range. A vendor who cannot produce those three things is describing an intention, not an attestation.
Where we stand, stated plainly
Fair is fair. Applying our own test to ourselves, as of 7 August 2026:
| Agentman | |
|---|---|
| BAA | Available for customers handling PHI |
| SOC 2 | In progress. Controls implemented; audit not complete, no report issued |
| ISO 27001 | Audit underway |
| GDPR / CCPA | Controls in place |
| PHI used to train models | No |
| "HIPAA certified" | We do not claim this, because it does not exist |
We are publishing the in-progress rows rather than rounding them up, and we found some rounding-up of our own while researching this post — our site described SOC 2 as complete when the audit is not. We corrected it. That is embarrassing to write, and it is exactly the kind of thing this page is asking you to check for, so leaving it unsaid would have been worse.
If your reviewer needs the artifacts we do have, ask and we will send them.
Frequently Asked Questions
Is there such a thing as HIPAA certification?
No. There is no government-issued HIPAA certification, and no federal seal or registry exists. HHS states directly that it does not endorse or recognize private organizations' certifications regarding the Security Rule, and that such certifications do not absolve anyone of their legal obligations. Any vendor calling itself HIPAA certified is describing a private company's assessment or a training completion certificate, not a government determination.
What does it mean when an AI vendor says it is HIPAA compliant?
It means the vendor is making a self-assessment. The label carries no government endorsement because no agency pre-clears or certifies products. It may well be accurate — plenty of vendors take their obligations seriously — but it is a claim, not a credential, and it should be treated the same way you would treat any other unverified vendor statement.
What should I ask an AI vendor instead of asking if they are HIPAA compliant?
Ask whether they will sign a business associate agreement, and read it. Then ask for the artifacts behind it: their most recent security risk analysis, a list of subprocessors that will touch PHI, their breach notification timeline, and whether PHI is used to train models. A signed BAA plus documented controls tells you far more than any badge, because the BAA creates enforceable legal obligations and the badge creates none.
Does a business associate agreement make a vendor HIPAA compliant?
It does not make them compliant, but it makes them legally accountable, which is the more useful thing. Under the HITECH Act, business associates are directly liable for Security Rule violations and face civil and, in some cases, criminal penalties. A BAA documents required assurances, commits the vendor to the Security Rule, extends those obligations to their subcontractors, and obligates them to report breaches to you.
Is SOC 2 the same as HIPAA compliance?
No. SOC 2 is a voluntary attestation about a service organization's controls, issued by an accounting firm against criteria the organization itself helps scope. HIPAA is federal law enforced by the HHS Office for Civil Rights. A SOC 2 report is meaningful evidence that a vendor has controls and had them examined, but it is not a HIPAA determination and it does not replace a BAA.
Can an AI vendor use PHI to train its models?
Only if your business associate agreement permits it, and most should not. A business associate may use or disclose protected health information only as permitted by its contract or as required by law. If model training is not addressed explicitly in the BAA, ask for it in writing before any PHI moves. This is one of the few AI-specific questions that older BAA templates often fail to cover.
Who is liable if an AI vendor mishandles PHI?
Both parties, in different ways. The business associate is directly liable under HIPAA for its own violations. But the covered entity remains responsible for obtaining satisfactory assurances that its business associates safeguard PHI appropriately, so using a vendor that turns out to be careless does not transfer your obligation away. That is why the diligence happens before deployment rather than after a breach.
What to do next
Stop asking vendors whether they are HIPAA compliant. The answer is always yes and it means nothing.
Ask for the BAA, read it against the nine requirements above, and ask for the risk analysis behind it. Ten minutes with those two documents tells you more than a page of badges — including about us.
Our security posture states each framework's real status, and the same verify-the-claim discipline we apply to automation percentages applies here too.



