The Health Insurance Portability and Accountability Act (HIPAA) sets national rules for protecting health information. It applies to covered entities, such as providers, health plans, and clearinghouses, and to the business associates that create, receive, store, or transmit protected health information (PHI) on their behalf, including many SaaS and IT vendors.
There is no official HIPAA certification. Compliance is enforced by the HHS Office for Civil Rights (OCR), and it starts with an accurate, thorough risk analysis of where your electronic PHI lives and how it could be exposed.