HIPAA is a US federal law, not a certificate. Nobody can issue you one, which is exactly why buyers ask harder questions about it than they do about SOC 2.
The short answer
HIPAA is the Health Insurance Portability and Accountability Act, a United States law from 1996 that governs how protected health information is used, disclosed and safeguarded. It binds healthcare organisations and, critically, any vendor that handles health data on their behalf. Obligations are set out in three rules, and compliance is a continuing legal state rather than an award.
For a company outside the United States, the practical question is not whether HIPAA applies to your country. It is whether your customer is bound by it and has passed those obligations to you in a contract.
On this page
The three rules
| Rule | What it governs |
|---|---|
| Privacy Rule | Who may see health information, when authorisation is required, and the rights individuals hold over their own records |
| Security Rule | How electronic health information is protected, through administrative, physical and technical safeguards |
| Breach Notification Rule | Who must be told after an exposure, the four-factor test for whether it counts, and the deadlines that follow |
Engineering teams live almost entirely inside the Security Rule. The other two are legal and operational obligations that a platform cannot discharge for you, though it can supply the evidence they depend on.
Covered entity or business associate
This is the first question to answer, because it determines whether HIPAA reaches you directly or through a contract.
| You are | If |
|---|---|
| A covered entity | You deliver or pay for healthcare directly: a provider, a health plan, a clearing house |
| A business associate | You create, receive, store or transmit health information on behalf of a covered entity. Most health technology companies are here |
| A subcontractor | You handle that data on behalf of a business associate. The same obligations apply to you |
| Out of scope | You never touch protected health information, or you hold only properly de-identified data |
Indian and other non-US health technology companies are almost always business associates rather than covered entities. HIPAA reaches them through the business associate agreement their US customer requires before go-live, which is a contractual obligation enforceable regardless of where the company sits.
What counts as PHI
Protected health information is health data that can be tied to a specific person. The two halves both matter: strip the identifiers correctly and the data leaves scope entirely.
| Element | Detail |
|---|---|
| Health information | Physical or mental health condition, treatment provided, or payment for care |
| Identifiers | Eighteen categories including name, address, dates, contact details, account and device numbers, biometrics and full-face images |
| ePHI | The same information in electronic form. This is what the Security Rule governs and what your platform holds |
| De-identified data | Outside HIPAA once identifiers are removed by an approved method. Partial removal does not qualify |
| Limited data set | Some identifiers retained for research or operations, permitted only under a data use agreement |
The common scoping error is assuming that a test environment, an analytics replica or a support ticket export is somehow out of scope. It is the same data, and it carries the same obligations wherever it has been copied.
Why there is no HIPAA certificate
No authority certifies HIPAA compliance
The Department of Health and Human Services does not accredit anyone, and no auditor can issue a HIPAA certificate that carries legal weight. Any vendor selling one is selling their own opinion. Compliance is a continuous legal obligation, assessed after the fact by a regulator following a complaint or a breach. That is a genuinely different shape of obligation from an audited attestation.
| HIPAA | SOC 2 | ISO 27001 | |
|---|---|---|---|
| What it is | Law | Attestation report | Certification |
| Who assesses | A regulator, usually after an incident | A licensed CPA firm | An accredited certification body |
| Output | No document | A report you can share | A certificate |
| Expiry | Never. It is continuous | Covers a stated period | Three years with surveillance |
| Failure means | Civil or criminal penalty | A qualified opinion | A non-conformity |
Because there is nothing to hand over, buyers substitute their own evidence request: a signed agreement, a completed risk analysis, documented safeguards, training records, and frequently a SOC 2 report as corroboration. This is why health technology companies commonly end up doing both.
Where Osto fits
The Security Rule is the part a platform can genuinely carry, and it is where most of the technical work sits. Encryption, access management with multi-factor authentication and role-based access control, data loss prevention, endpoint controls and audit logging in one SIEM map directly to the technical safeguards. Security awareness training covers an administrative safeguard that is frequently the first thing a regulator asks to see.
Because the same controls also satisfy SOC 2, ISO 27001 and the DPDP Act, the evidence is collected once rather than assembled separately for each buyer. The parts that remain yours are the legal ones: signing agreements, appointing a privacy officer, writing notices of privacy practices and handling individual rights requests. No platform does those, and any that claims to is describing paperwork rather than compliance.
Platform walkthrough
Safeguards your US buyer will accept
Encryption, access control, audit logging and training deployed as real controls, with evidence that also answers SOC 2, ISO 27001 and DPDP. One owner, one dashboard.
Book a demoEvidence from live controls · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is HIPAA?
A United States federal law from 1996 governing how protected health information is used, disclosed and safeguarded. It applies to healthcare organisations and to any vendor handling health data on their behalf, through three rules covering privacy, security and breach notification.
Does HIPAA apply to companies outside the United States?
Not by geography, but by contract. If you handle health data for a US covered entity, you are a business associate and the obligations reach you through the business associate agreement you sign. Most non-US health technology companies encounter HIPAA this way.
Can you get HIPAA certified?
No. No government body or auditor issues a HIPAA certificate with legal standing. Vendors offering one are selling an opinion. Buyers therefore ask for a signed agreement, a risk analysis, documented safeguards, training records and often a SOC 2 report instead.
What is the difference between a covered entity and a business associate?
A covered entity delivers or pays for healthcare: a provider, health plan or clearing house. A business associate handles protected health information on behalf of one. Both are bound, and obligations pass further down to subcontractors through the same contractual chain.
What is PHI?
Protected health information: health data linked to an identifiable person through any of eighteen identifier categories. In electronic form it is ePHI, which is what the Security Rule governs. Correctly de-identified data falls outside HIPAA entirely.

