The Health Insurance Portability and Accountability Act (HIPAA) is a restrictive data security law regulating US healthcare organizations’ use of protected health information (PHI). Covered entities and business associates handling US patients’ PHI are subject to HIPAA.
The Department of Health and Human Services (HHS) doesn’t formally recognize the certification, it can be issued by private companies that specialize in HIPAA certification. HIPAA certification is not an obligatory training program; it is granted after a successful audit. The HIPAA certification audit proves that healthcare organizations met the standards of HIPAA and didn’t violate HIPAA guidelines at the time of the audit. It must be noted that HIPAA certification doesn’t mean the organization is HIPAA compliant. Third-party auditors give the certification, while the official HIPAA compliance process must be completed internally to properly secure patients’ data and avoid penalties and fines.
The course is not official but may better prepare a facility and its workers for achieving and maintaining compliance. It also may serve as a confirmation to patients and business associates that the organization is patient-first and approaches PHI with privacy and care.
Learn more about HIPAA:
HIPAA certification
-

First-party analytics without consent: Your Digital Omnibus compliance guide
The Digital Omnibus is the European Commission’s simplification initiative to modernize the EU’s digital rulebook and reduce consent fatigue. The framework would enable first-party analytics without consent when specific criteria are met, ending years of uncertainty about the use of legitimate interest for web statistics.
-

University website personalization: First-party data strategies for student recruitment and retention
University websites receive millions of visits annually from diverse audiences – prospective students, admitted students weighing their options, current undergraduates, graduate students, parents, alumni, and faculty. Yet most institutions serve identical content to all these visitors, missing critical opportunities to engage each audience with relevant information.
Other definitions
Recent posts from Piwik PRO blog
- First-party analytics without consent: Your Digital Omnibus compliance guide
- University website personalization: First-party data strategies for student recruitment and retention
- Digital marketing in the energy sector: Key challenges and fixes
- From Customer Data Platform to Data Activation: Why we’re evolving our approach
- Life after GA4: Why EU organizations are going local
- Telehealth analytics: Optimizing virtual care experiences in a HIPAA-compliant way
- The combined benefits of using Piwik PRO and Cookie Information Consent Management Platform
- Global data centers: secure, GDPR-compliant analytics hosting with Piwik PRO