HIPAA binds two kinds of organizations. Covered entities — providers, health plans, clearinghouses — and their business associates: vendors that handle protected health information on a covered entity’s behalf. Most digital-health startups enter as business associates. The moment a clinic, payer, or health system routes PHI through your product, you belong in scope, and the business associate agreement (BAA) you sign makes it contractual as well as regulatory. Signing a BAA is not a formality; it attaches direct obligations, including liability for breaches on your watch.
Founders misjudge the boundary in both directions. A consumer wellness app whose users type in their own data, sold direct to consumers, may sit entirely outside HIPAA. Meanwhile a scheduling tool that merely displays appointment details for a clinic sits inside it. The label “health tech” decides nothing — the data flow and the relationship decide everything, so map both before you assume. The HIPAA framework overview covers the rule structure; the operated HIPAA program covers how Agency runs it.
Plainly: the government certifies no one under HIPAA. No badge, no registry, no official seal. HIPAA is a regulatory obligation you comply with continuously and demonstrate on request — through your risk analysis, your safeguards, your training records, and, when buyers want third-party weight, an independent assessment or attestation over your program. Anyone selling you a “HIPAA certificate” is selling a training completion or an assessment wearing a costume.
This matters commercially, not just technically. Health-system security reviewers know there’s no certification, so a vendor claiming to be “HIPAA certified” flags itself as either confused or overselling — while a vendor that says “no certification exists; here is our risk analysis, our safeguards, and our third-party assessment” sounds like it has done this before. Precision is the trust signal in this market.
The artifacts a digital-health security review actually asks for.
Enterprise health buyers rarely stop at “are you HIPAA compliant?” — an unverifiable yes satisfies no reviewer. The standard pattern is HIPAA plus a SOC 2 report with HIPAA mapped into scope: the law is answered by your program, and the reviewer gets an audited artifact to read. On a mapped platform one control set feeds both, so the pairing is closer to one program with two outputs than two programs.
Then there’s HITRUST — the heavyweight certification large health systems and payers sometimes name as a procurement gate. It is a genuinely bigger lift, and the sensible posture for a startup is contract-driven: build HIPAA plus SOC 2 now, and treat HITRUST as a roadmap conversation the first time a signed-revenue opportunity puts it in writing. The control base you’ve already built carries much of the way there.
Popp shows the motion end to end: an AI copilot for recruiting that took on HIPAA alongside SOC 2 and ISO 27001 through Agency to meet enterprise requirements — and converted that stack into closed deals. For a digital-health startup, Agency builds the same machinery inside the startup program: risk analysis, policies, safeguards, training, the SOC 2 pairing, and the attestations that make it all demonstrable, for $2,500 to $12,500 all-in depending on stage and stack.
And when your buyers want a security leader in the room — a person who can field a hospital CISO’s questions live — that’s the healthcare vCISO engagement, which sits naturally on top of the compliance program rather than replacing it.
No — no government body certifies HIPAA compliance, full stop. What you can obtain is an independent third-party assessment or attestation over your program, which is exactly what sophisticated buyers ask for. Treat any vendor advertising an “official HIPAA certification” as a signal to read the fine print.
Properly de-identified data — via the safe-harbor method or expert determination — is not PHI, so HIPAA’s rules don’t attach to it. The scrutiny lands on the word “properly”: buyers and counsel will probe how de-identification happens, who can access data before it, and what prevents re-identification. Govern that pipeline as carefully as you would PHI itself.
It covers their layer, not yours. A cloud BAA is a precondition — it makes hosting PHI there permissible — but responsibility for application-level safeguards, access control, training, and incident response stays with you. Inheriting a provider’s BAA and calling yourself compliant is one of the most common early-stage mistakes in digital health.
Both, in practice. HIPAA because the law and the BAA demand it; SOC 2 because reviewers want an audited report they can actually read, and “we comply with HIPAA” alone gives them nothing to verify. Mapped onto one platform, the pair behaves like a single program producing two artifacts — which is how enterprises expect to see it.
When a large health system or payer names it in procurement — and generally not before. It’s a substantial certification effort, so let contracts justify it rather than pursuing it speculatively. A HIPAA-plus-SOC 2 program built on mapped controls gives you a running start if and when a deal puts HITRUST on the table.