Is there an official HIPAA certification?
No — and this surprises many boards, because an entire industry sounds as though there were. There is no government-issued HIPAA certification or federal registry of compliant organizations. In its official Security Rule certification guidance, HHS says it does not endorse or recognize private certifications. The seals and badges that vendors offer are private attestations of varying rigor; some reflect genuine assessment work, but none of them is a credential the government stands behind, and none of them changes what a regulator will examine.
This matters because “HIPAA compliant” on a public website reads, to a visitor, like a certification — a status someone conferred. Legally, it is something else entirely: a factual representation your organization is making about itself, on the record, to everyone who visits.
What do state regulators actually look at?
The observable pattern in the public record is worth stating precisely, because it is calmer than the vendor marketing around it. Regulators have not, so far, been pursuing pregnancy help organizations over firewall configurations. The activity has centered on whether organizations’ public statements about privacy match their actual practices.
Between 2024 and 2025, advocacy organizations filed complaints with attorneys general in ten states — Idaho, Minnesota, Washington, Pennsylvania, New Jersey, Louisiana, Arkansas, Missouri, Texas, and Florida — arguing that “HIPAA compliant” language on center websites misled clients into believing their information carried federal protections it did not have. These complaints invoke state unfair-and-deceptive-practices statutes: consumer-protection laws with investigative authority that may apply to nonprofits depending on the state and the facts.
Notice what the theory of those complaints requires. It does not require a breach. It does not require harm to any client. It requires only a gap between what the website says and what is true. That is why the standard exhibits in this kind of matter are ordinary documents: the website’s privacy statements, the client intake form, and whatever records exist of actual practice. Inconsistency between the website and the intake form — one promising more than the other — is exactly the kind of gap an investigator is trained to notice.
What if your organization is not a covered entity at all?
For many pregnancy help organizations, this is where the ground actually sits. A center that does not conduct the standard electronic transactions identified by HHS is generally not a HIPAA covered entity — the analysis we walk through in does HIPAA apply to your pregnancy help organization? For a non-covered organization, an unqualified “we are HIPAA compliant” claim may mislead visitors about the legal protections that apply. That is the kind of gap between statement and regulatory status alleged in the state complaints.
The practice underneath the phrase is usually admirable. Centers that voluntarily meet HIPAA-grade standards are exercising good stewardship, and insurers and accreditors increasingly expect exactly that. The difficulty is never the discipline. It is the label.
What should your website say instead?
The remedy is not to say less about privacy. Women deserve to know how their information is handled, and organizations that protect it well should say so. The remedy is to say true and specific things:
- If it is demonstrably true, replace “we are HIPAA compliant” with language such as: “We voluntarily align our privacy and security practices to the standards of the HIPAA Security Rule.” The qualifier is the substance — this phrasing claims the discipline without asserting a legal status that may not exist.
- Describe what you actually do. Who can access client records. How they are stored. The narrow circumstances in which information would ever be shared. How a client can ask questions. Specific statements are both more trustworthy to the woman reading them and more defensible than any label.
- Make your intake forms and your website say the same thing. Two documents, one promise.
- If you are a covered entity — a clinic that bills insurance electronically — the opposite discipline applies: the label must be backed by the full program it implies, including a Notice of Privacy Practices, a current risk analysis, business associate agreements, training records, and breach procedures.
Language like this does more than reduce exposure. It is itself an act of care — the same stewardship we describe in how pregnancy help organizations guard the trust of the women they serve: telling her the truth about how her information is protected, in words your organization can stand behind.
Could you prove every sentence today?
Here is a ten-minute exercise for your next board meeting. Print your website’s privacy statements and your client intake form. Read them side by side and ask one question of every sentence: could we prove this to a skeptical outsider today? Each sentence that fails is one of two things — a claim to revise, or a control to build. Either outcome moves you to firmer ground.
In our experience, every organization that runs this exercise finds at least one sentence. That is not an indictment; it is the ordinary result of websites written in one season and practices that evolved in another. It is also why an independent read matters as governance rather than salesmanship: the sentences an organization can no longer see are the ones it wrote itself. The full treatment of this topic — including the public-record context and the self-assessment — is in our free 2026 executive briefing.