There is no HIPAA certificate. There is doing the work.
01:55 · CHART ACCESS AUDITED — CLEAN01:55 · CHART ACCESS AUDITED — CLEANNobody certifies HIPAA compliance — not HHS, not a seal vendor, nobody. What exists is the work: a real risk analysis, controls with logs behind them, a business-associate agreement your IT provider signs instead of dodges. We run IT and security for small practices — the ones big providers price out — and we do the work.
The work, itemized
A BAA we sign, not dodge — an IT provider that touches PHI is a business associate whether or not they admit it. We put it in writing as a matter of course — and when the real question is whether HIPAA even applies to a line of work (some practice work sits outside it entirely), we raise it for your counsel and build to their answer.
PHI where it belongs — encryption at rest and in transit, access by role, audit logs on every chart. Your Microsoft tenant configured under Microsoft's BAA — the license most practices already pay for, finally set up like it holds patient data.
The front desk, defended — MFA everywhere, mail protection tuned for the billing-and-referral fraud that hunts practices, and staff trained as the first control.
The risk analysis, done for real — the Security Rule's first requirement and the first thing OCR asks for after an incident. Documented, kept current, and yours to show — not a checkbox in a seal vendor's portal.
Backup that answers to the contingency plan — endpoint, server, and cloud, restores tested on a schedule and documented. An untested backup is a finding waiting for its incident.
Compliance, in a practice's terms — the insurer's questionnaire, the hospital system's security addendum, the breach-notification clock. The answering is our job — you see patients instead of filling out forms.
About AI: patient context in a free chatbot is a disclosure, not a shortcut. Adoption here starts with boundaries — then the benefits. → AI & AUTOMATION
About those HIPAA badges. HHS certifies no one. There is no federal HIPAA certification, seal, or registry — every badge you've seen is a self-assessment, sometimes laundered through a seal vendor, and regulators have pursued companies for displaying them deceptively. So ask any provider — including us — for the things that are real: their risk analysis, their signed BAA, their control documentation. Ask us and we'll show you ours — or put a clinician we serve on the phone.
You won't find a compliance badge on this page. That's deliberate — ask to see the work instead.
See patients. We'll mind the rest.
Bring us one question: if OCR asked for your risk analysis tomorrow, who hands it over? We'll answer it specifically.
Prefer email? info@ithryn.tech · or call 833.4.ITHRYN
NEW YORK · GREENWICH · WEST PALM BEACH
The practices: