HIPAA Certified Website: Why There Is No Such Thing
No federal agency certifies websites, software, or hosting as HIPAA compliant. HHS said so on the record in 2003. Here is what a "HIPAA certified" badge actually is, and what to ask instead.
A vendor tells you their platform is HIPAA certified. It says so on the pricing page, sometimes with a badge.
There is no such certification. Not for websites, not for hosting, not for form tools, not for anything. No federal agency issues one, and none ever has.
This is worth knowing before you choose a vendor, because the badge is doing work it has not earned.
What HHS actually said
When the Security Rule was written, people asked for exactly this. They wanted a federal list of approved products so a practice could buy from it and be safe.
HHS declined, in writing, in the 2003 rulemaking record. Asked to certify software and off-the-shelf products, the department responded that it would not assume that task. Asked to publish certification criteria instead, it said it did not intend to create them.
That position has never been reversed. There is no registry, no seal, no pre-clearance, and no office at HHS that reviews your website. Even the government's own Security Risk Assessment Tool carries a disclaimer saying that using it is neither required by nor a guarantee of compliance.
So what is the badge?
A self-assessment. Sometimes a careful one, sometimes an audit the vendor commissioned and paid for, sometimes a designer's afternoon.
Some are backed by real work. A vendor that has had a third party review its controls, and will tell you who did it and what was in scope, has done something worth respecting. That is a different claim from "certified," and the honest ones say so.
The ones that matter are the ones where the badge is doing the arguing.
The agency that does police this
Here is the part most people find surprising. The federal agency that has actually brought cases over "HIPAA compliant" marketing claims is not HHS. It is the Federal Trade Commission, under its general authority over deceptive advertising.
The FTC has charged companies for claiming compliance they could not support, and the list includes a dental practice management software vendor. The theory is not that they violated HIPAA. It is that they told customers something untrue.
Which means a compliance badge is a marketing claim, and marketing claims have a regulator. That regulator is simply not the one anybody expects.
What to ask instead
You cannot ask for a certificate, because none exists. You can ask four questions that a vendor either answers plainly or does not.
Will you sign a Business Associate Agreement for my account, on my plan? Not "do you offer BAAs." Many vendors sign only on an enterprise tier, and the answer changes with what you are paying. Get it in writing against your actual plan.
Which of your features does the BAA cover? This catches more problems than anything else on the list. A BAA that covers the core product and silently excludes a newer feature is common, and a signed agreement that does not cover the thing you use is not protection.
Who else touches the data? Your form tool has a host. Your host has a CDN. Each company in that chain that handles patient information needs its own signed agreement with the one above it. Ask them to describe the chain. A vendor that can do this quickly has thought about it.
What happens when something goes wrong? Breach notification is a contractual obligation with a clock on it. Ask how fast they will tell you, and in what form.
None of those questions requires you to know HIPAA. They require the vendor to know their own product.
The deeper problem with the idea of certification
Suppose HHS had said yes in 2003 and a real federal certification existed. It still would not do what people want it to do, because it would certify a moment.
We scanned 4,601 independent practice websites in July 2026. 88.0% produced at least one finding. 10.7% came back with nothing to report. Almost none of those sites launched broken. They launched fine and then a year happened: an agency added a conversion tag to the appointment page, a form vendor shipped a feature that is not named in the agreement, a host changed its subcontractors, somebody built a new location page and copied the old contact form onto it.
Every one of those is ordinary competent work by somebody doing their job. None of them would invalidate a certificate, because a certificate describes a day. And each one quietly moves a practice from the 10.7% into the 88%.
This is the part the badge conceals even when the badge is honest. Compliance is not a property a product has. It is a property a configuration has, on a particular date, and configurations move.
The uncomfortable implication
If no certification exists, nobody can hand you compliance. Not us either.
What somebody can do is accept continuing responsibility for a defined part of the chain, put it in a contract you can hold them to, and keep checking. That is the whole mechanism. Everything else is a badge, and a badge has no opinion about what happened to your site in November.
That distinction is what our Managed Plan is built around. We hold the site, the hosting, the form path and the agreements, so there is one accountable party rather than four, and the site is rescanned rather than remembered. Not because a regulator approved it, and not because we have a seal. Because you can read the chain, and because somebody is still looking at it after launch week.
If you want to know what your current site is doing before you have that conversation with anyone, start with the scan. It reports which of your form and hosting vendors will sign for what they receive, and what it could not determine from outside.