A personal injury file is full of it. So is a custody file with mental health evaluations in it. That constraint shaped the database before the first feature was written — which is a different thing from adding a compliance page later.
No government body issues one. No auditor can grant one. If a vendor tells you they are “HIPAA certified,” they are describing something that does not exist.
HIPAA compliance is what you actually implement — and what you can prove you implemented. So rather than claim a badge, here is the list. Ask any vendor you are evaluating for theirs — the answer tells you a great deal.
The security question attorneys ask out loud is about data. The one they ask next is about trust in the output — and after a few well-publicized sanctions, they are right to ask it.
Under the rules of professional conduct the work is yours no matter what produced the first draft. So the product is built to be checked — that is the point of citing every page, and the point of the approval step before anything reaches a client or a court.
Firms handling protected information often need documentation for their own records or their carrier’s. Ask and you get it — the architecture in writing, the business associate agreement to review, and a direct answer about anything not covered here.
You will be talking to the person who designed the architecture, not to a sales engineer relaying the answer. If something is not built yet, you will hear that too.