HIPAA frequently asked questions
Sixteen straight answers on certification (there isn't one), risk analyses, BAAs, costs, timelines, penalties, and HITRUST — updated September 2026.
Is there such a thing as HIPAA certification?
No. HHS OCR does not certify organizations, and no government-recognized 'HIPAA certified' credential exists. Vendors selling 'HIPAA certification' are selling their own badge. What exists: the Security Rule's required risk analysis, and third-party validations like HITRUST CSF certification. See our full explainer.
Who has to comply with HIPAA?
Covered entities — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically — and their business associates: any vendor that creates, receives, maintains, or transmits PHI on their behalf.
What is a HIPAA risk analysis?
The Security Rule requires an accurate and thorough assessment of potential risks to ePHI — covering threats, vulnerabilities, current controls, and the likelihood and impact of each risk. OCR's guidance lists nine required elements. It is the foundation of the entire security program, and its absence is the most cited failure in enforcement actions.
What is a Business Associate Agreement (BAA)?
A contract required between a covered entity and each business associate (and between business associates and their subcontractors) that handles PHI. It must specify permitted uses of PHI, safeguards, breach-notification duties, and subcontractor flow-down. No BAA, no PHI sharing — it's that simple.
Do business associates have to comply with HIPAA directly?
Yes. Since HITECH, business associates are directly liable for HIPAA Security Rule compliance and can be audited and penalized by OCR themselves — not just through the covered entity.
How much does a HIPAA risk assessment cost?
Planning estimates: roughly $10,000–$20,000 for a small practice, $20,000–$45,000 for a mid-size organization, $70,000–$150,000+ for a large health system. See the cost guide for the full breakdown.
How long does HIPAA compliance take?
A risk analysis takes 4–8 weeks of fieldwork; a first full program build takes 3–6 months for most mid-size organizations. See the timeline.
What is the difference between the Privacy Rule and the Security Rule?
The Privacy Rule governs who can use and disclose PHI and patients' rights over it. The Security Rule governs the administrative, physical, and technical safeguards protecting electronic PHI. The risk analysis is a Security Rule requirement; workforce training and policies span both.
What are the penalties for HIPAA violations?
Civil money penalties are tiered by culpability and inflation-adjusted annually — up to roughly $68,000 per violation with an annual cap over $2 million per identical violation category. Criminal penalties apply for knowing misuse. Public settlements include Anthem ($16M, 2018) and Premera ($6.85M, 2020).
Does OCR audit organizations proactively?
Yes — OCR runs a HIPAA audit program covering both covered entities and business associates, in addition to investigating complaints and breaches. Selection is not purely complaint-driven.
What is HITRUST, and do we need it?
HITRUST CSF is a private certifiable framework that harmonizes HIPAA, NIST, ISO, and other requirements; validated assessments are performed by HITRUST Authorized External Assessors. You need it when customers or partners require it — it's common in health-tech and payer contracting. See HIPAA vs HITRUST.
Can the same firm assess us and fix our gaps?
It can, but think carefully. The firm that implements your controls shouldn't be the only one validating them — especially if customers rely on the assessment. Many buyers hire a consultant to remediate and a separate firm to validate.
What should a risk analysis report contain?
Per OCR guidance: scope of the analysis, identified threats and vulnerabilities, assessment of current security measures, likelihood and impact determinations, and risk levels — documented, with a remediation plan. A two-page checklist is not a risk analysis.
How often must we do the risk analysis?
At minimum annually, and whenever there are significant operational or technological changes. OCR expects it to be current — stale analyses are a recurring enforcement finding.
What should I ask an assessor before signing?
Nine questions: healthcare focus and references, assessor bios (not sales), sample report structure, fixed vs. variable fee, scope boundaries, evidence process, scheduling, remediation independence, and two reference clients your size. Full checklist in how to choose an assessor.
We're a small practice — is there a cheaper path?
Keep the ePHI footprint small and documented, use a HIPAA-focused specialist rather than a Big-Firm generalist, and do the readiness basics (policies, training, BAAs) before paying for assessment. See the small-practice guide.
Still have questions? Get quotes
The fastest way to learn your number: scoped quotes from matched assessors. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match HIPAA assessors to your size, setting, and timeline → they send scoped quotes directly. Free, no obligation.