Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

HIPAA Security Rule Certification (NIST 800-66 R2)

Demonstrate conformity with the HIPAA Security Rule through an SCR 3PAO assessment. Providing independent, third-party validation that goes beyond self-attestation to deliver stakeholder trust.

Key Takeaways - HIPAA Security Rule Certification
  • The SCF partnered with The Cyber AB to create a legitimate HIPAA Security Rule certification path.
  • Assessment uses NIST SP 800-66 Rev 2 as the reference for HIPAA Security Rule conformity.
  • An SCR 3PAO certifies your organization as SCR Certified, HIPAA Security Rule through a conformity assessment.
  • Ideal for Covered Entities, Business Associates and their service providers needing to prove HIPAA compliance.
  • ComplianceForge provides gap assessment services and documentation to prepare for certification.
  • StrikePath serves as recommended 3PAO partner with expertise in ComplianceForge documentation.
Beyond Self-Attestation

Why Get HIPAA Certified?

While the US Department of Health and Human Services (HHS) does not offer a formal certification program for the Health Insurance Portability and Accountability Act (HIPAA), there is a legitimate way to obtain a HIPAA Security Rule certification for Covered Entities (CE) and Business Associates (BA).

The Secure Controls Framework (SCF) partnered with The Cyber AB to be the Accreditation Body (AB) for the Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP). This enables organizations to offer a certification path for the HIPAA Security Rule where an SCR Third-Party Assessment Organization (3PAO) can certify an entity as SCR Certified - HIPAA Security Rule through a conformity assessment useing SCF controls.

Note

The SCR CAP is focused on using the SCF as the control set to provide a company-level certification. While the SCR CAP shares some similarities with other existing, single-focused certifications (e.g., ISO 27001, CMMC, FedRAMP, etc.), the SCR CAP is unique in its metaframework approach to covering cybersecurity and data protection requirements that span multiple laws, regulations and frameworks.

The Path

Your Path To Demonstrating Conformity With HIPAA

If you want to get SCR Certified for the HIPAA Security Rule, you can download the HIPAA Security Rule (NIST SP 800-66) Assessment Guide from the SCF's website.

For organizations that have a current Cybersecurity Maturity Model Certification (CMMC) Level 2 certification and want to leverage reciprocity towards HIPAA Security Rule certification. (Note - this is only applicable if the organization holds a current CMMC L2 certification)

What Is The SCR CAP?

Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) - HIPAA Certification

The SCR CAP is designed for cybersecurity & privacy practitioners by cybersecurity & data privacy practitioners. This concept is based on the need within the industry for a tailored conformity assessment solution that is capable of addressing several key considerations:

  • View compliance as a natural by-product of secure practices;
  • Scale to address multifaceted operational requirements (e.g., laws, regulations and frameworks);
  • Acknowledge the stated risk tolerance of the OSC since not all organizations have the same risk tolerance;
  • Minimize the risk of “gaming” the certification process that provides no useful insights into the security posture of the OSA;
  • Utilize technology to make the assessment process more efficient to drive down labor-related assessment costs; and
  • Leverage existing industry recognized practices, where possible.
Enables Certification

HIPAA Security Rule Structure Enables Certification

The lack of controls within HIPAA makes it difficult for organizations to demonstrate conformity with the framework. The solution is to leverage a controls framework that provides coverage for the HIPAA Security Rule and the SCF is that solution!

A HIPAA Security Rule-specific Assessment Guide (AG) is published for Organizations Seeking Assessment (OSA) to understand the assessment process. In addition to the SCR CAP’s assessment standards, the SCR CAP’s HIPAA Security Rule AG contains:

Controls;
Assessment Objectives (AOs); and
Evidence Request List (ERL).

Additionally, the SCF has comprehensive controls coverage for NIST CSF 2.0. In adherence to NIST IR 8477, the SCF utilizes Set Theory Relationship Mapping (STRM) to provide crosswalk mapping between HIPAA Security Rule requirements to SCF controls.  The result is a defendable set of controls and Assessment Objectives (AOs) that can be assessed against to demonstrate conformity with the HIPAA Security Rule.

Set Theory Relationship Mapping (STRM) example
What Is THe Certification Process?

SCR Certification Process For The HIPAA Security Rule / NIST SP 800-66 Rev 2

The SCR CAP is designed to look at a holistic approach to cybersecurity and data protection. SCR assessors will evaluate your HIPAA Security Rule-specific approach to:

  • Categorizing controls
  • Selecting controls
  • Implementing controls
  • Assessing controls
  • Authorizing controls
  • Monitoring Controls
NIST CSF certification process diagram - ComplianceForge
Where To Start?

HIPAA Security Rule Certification Starts With ComplianceForge!

To obtain HIPAA Securty Rule certification, these are the recommended steps:

  • Contact ComplianceForge so that we can help you on your journey to demonstrate conformity with the HIPAA Security Rule;
  • Download the HIPAA Security Rule assessment guide and familiarize yourself with the SCR CAP process;
  • Implement the necessary controls to demonstrate conformity;
  • Perform an internal assessment to validate assumptions and necessary evidence; and
  • Engage an SCR 3PAO to conduct a third-party conformity assessment.

ComplianceForge can help you step-by-step through this process from start to finish. We want you to be success to obtain a HIPAA Security Rule certification!

Where To Get An Assessment?

HIPAA Security Rule Assessments

ComplianceForge can provide gap assessment services to provide independent assurance of your cybersecurity program to determine how it conforms with the HIPAA Security Rule (NIST SP 800-66 Rev 2).

The SCR CAP is an authoritative structure to conduct Third Party Assessment, Attestation and Certification Services (3PAAC Services). The SCR CAP is a scalable, cost-effective solution for organizations to obtain an independent, third-party assessment of its cybersecurity & data protection practices.

The SCR CAP is specifically designed to be:

  • An affordable solution for businesses to obtain certification of its cybersecurity and data protection capabilities.
  • Scalable to address the modern reality facing businesses for multiple compliance obligations.
  • Sustainable by businesses to minimize the reliance upon expensive consultants.

The SCF-based certification for the HIPAA Security Rule is designed to deliver significant value through an efficient third-party assessment process. The SCR CAP employs a rigorous third-party assessment process governed by The Cyber AB. This governance ensures SCR Third-Party Assessment Organizations (SCR 3PAOs) implement the highest level of assurance in certification results, reinforcing trust and credibility with stakeholders. The assessment process is prescriptive and the results are unbiased.

Successfully demonstrating conformity with the HIPAA Security Rule will lead to an SCR Certified - HIPAA Security Rule certification!

StrikePath – Your NIST CSF Audit Partner
ComplianceForge has a strong working relationship with StrikePath to serve as your 3PAO for a HIPAA Security Rule assessment. StrikePath has expertise with ComplianceForge documentation and that can lead to a more efficient and cost-effective assessment process. Contact StrikePath to get on their calendar for your assessment!
SCR CAP assessor strikepath - Secure Controls Framework certification path
What Solutions Does ComplianceForge Provide?

NIST CSF 2.0 Policies, Standards & Procedures

ComplianceForge has editable policies, standards and procedures for HIPAA / HITECH to assist your organization earning a HIPAA Security Rule certification as part of the SCR CAP:

$ 10,400.00 USD
Policies & Standards - Security, Compliance & Resilience Program (SCRP)
This version of the SCRP is a hybrid, "best in class" approach to cybersecurity documentation that covers dozens of statutory, regulatory and contractual frameworks to create a comprehensive set of cybersecurity policies & standards. The SCRP has a 1-1 mapping relationship with the Secure Controls Framework (SCF) so it maps to over 200 leading practices!
Contains:
Word
Excel
PowerPoint
PDF
Examples:
Word Example
Excel Example
$ 6,400.00 USD
Procedures - Security, Compliance & Resilience Program (SCRP)
This version of the SCRP is a hybrid, "best in class" approach to cybersecurity documentation that covers dozens of statutory, regulatory and contractual frameworks to create a comprehensive set of cybersecurity procedures. The SCRP has a 1-1 mapping relationship with the Secure Controls Framework (SCF) so it maps to over 200 leading practices!
Contains:
Word
Excel
PowerPoint
PDF
Examples:
Word Example
Excel Example
Common Questions

Frequently-Asked Questions

Here are answers to common questions about HIPAA certification through the SCF:

Is there an official HIPAA certification?
No, HHS does not offer an official HIPAA certification, and the Security Rule does not require covered entities to certify compliance. Instead, 45 CFR 164.308(a)(8) requires a periodic technical and non-technical evaluation, which can be done internally or by an outside organization. HHS also states that it does not endorse or recognize private organizations' certifications. Third-party programs such as the SCR CAP can still provide independent evidence of conformity for customers and partners.
Does a HIPAA certification protect you from HHS penalties?
No, HHS states that private HIPAA Security Rule certifications do not absolve covered entities of their legal obligations, and a certification by an outside organization does not prevent HHS from later finding a violation. A certification is useful as evidence of due diligence for business partners, but compliance depends on how safeguards actually operate. Covered entities must keep implementing their policies and procedures and retain that documentation for six years.
How do you get a HIPAA Security Rule certification?
You can get a HIPAA Security Rule certification through the SCR CAP, where an accredited SCR 3PAO assesses your organization against Secure Controls Framework (SCF) controls mapped to the HIPAA Security Rule. The assessment uses NIST SP 800-66 Rev 2 as its reference, and a successful result earns the SCR Certified HIPAA Security Rule designation. It is intended for covered entities, business associates and their service providers. The SCF publishes a HIPAA Security Rule assessment guide with the controls, Assessment Objectives and Evidence Request List used.
How long does a HIPAA Security Rule certification last?
HHS sets no expiration because it does not issue HIPAA certifications, so the term depends on the program that issues one. The SCR Certified HIPAA Security Rule designation has a three-year lifecycle. In years two and three, the organization must perform an internal assessment and submit a self-attestation that it still conforms. After three years, the certification expires and a new third-party assessment is needed to keep the designation.
What is NIST SP 800-66 Rev 2?
NIST SP 800-66 Rev 2 is a NIST cybersecurity resource guide for implementing the HIPAA Security Rule, published in February 2024. It gives regulated entities of all sizes practical guidance for safeguarding electronic protected health information (ePHI) and for understanding the security concepts in the Security Rule. It is guidance, not a regulation. The SCR CAP uses it as the reference for assessing conformity with the HIPAA Security Rule.