One Guy Consulting is NOT representing any law firm and Chuck Weiselberg is NOT an Attorney. This article does not provide legal advice. It merely points out discrepancies between two sets of publicly available information. Please consult an Attorney for interpretations of the law.
If you are evaluating HIPAA compliance software, you need to know whether the vendor actually understands the law it claims to help you follow. We read every blog post, product page, and training module on AccountableHQ's website and compared their claims to the HIPAA Administrative Simplification regulation; 45 CFR Parts 160, 162, and 164.
We found 19 substantive problems. Some are embarrassing but harmless. Others could lead an organization to make compliance decisions based on guidance that directly contradicts what the regulation requires.
This is not a feature comparison. We have a separate page for that. This article is strictly about accuracy; where Accountable gets the law right, where they get it wrong, and what the regulation actually says.
What We Found in Our AccountableHQ HIPAA Review
1. There Is No Such Thing as "HIPAA Certification"
Accountable uses the phrase "HIPAA certified" more than 20 times across their site. Their onboarding flow ends with a screen that reads "HIPAA CERTIFIED." They sell a product called an audit protection guarantee that positions this certification as the end result of their process.
The problem: HHS has never created, endorsed, or authorized a HIPAA certification program. No federal agency certifies organizations as HIPAA compliant. HHS has stated this in multiple official sources:
- HHS FAQ #2003: "HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule."
- OCR Misleading Marketing Claims guidance: "HHS and OCR do not endorse any private consultants' or education providers' seminars, materials or systems, and do not certify any persons or products as 'HIPAA compliant.'"
This matters because the word "certification" implies a federally recognized status. It does not exist. An organization that believes it has been "certified" may stop performing the ongoing activities that HIPAA actually requires, like periodic risk assessments, policy updates, and workforce training because it thinks the work is done.
Accountable also uses several invented variants of this concept across different pages:
- "HIPAA HITECH Certification" on their call center software page. No such certification exists under either HIPAA or the HITECH Act.
- "HIPAA e-signature compliance" on their e-signature page, presented as a formal standard. HIPAA does not contain e-signature requirements. The ESIGN Act and state laws govern electronic signatures; HIPAA's requirements focus on access controls and audit trails for ePHI systems.
- "HIPAA encryption standards" referenced four times on their EMR software page. HIPAA does not publish encryption standards. The Security Rule at §164.312(a)(2)(iv) and §164.312(e)(2)(ii) makes encryption an addressable implementation specification. The regulation is intentionally technology-neutral — it says "implement a mechanism to encrypt" and names no specific standard. NIST publishes the encryption standards (AES-256, etc.) that organizations typically adopt, but those are NIST standards, not HIPAA standards. HHS does reference NIST in a separate guidance document issued under the HITECH Act for the breach notification safe harbor at §164.402 — but that guidance is not part of the HIPAA regulation itself.
When a compliance platform invents regulatory concepts that do not exist, it raises a basic question about how well the platform understands the regulation it is teaching.
2. They Got the Name of the Law Wrong
Accountable's introductory training module, which is the first thing a new user sees, identifies the law as the "Health Insurance and Portability and Accountability Act."
The actual name is the Health Insurance Portability and Accountability Act. There is no "and" between "Insurance" and "Portability." Public Law 104-191 is clear on this.
This is a small mistake — almost certainly a typo. But it has appeared in training material taken thousands of times without being caught. For a platform whose entire product is regulatory accuracy, that raises a fair question: if the first line of the first lesson was never proofread, what else was missed? Compliance is a discipline of precision. The vendor teaching it should model that standard.
Organizations use this training to satisfy their HIPAA workforce training requirements. If an auditor reviews your training documentation and the training gets the name of the law wrong in the first lesson, it does not inspire confidence in the rest of the curriculum.
3. Their Security Rule Training Omits 1/3 Core Requirements
Accountable's Security Rule training module teaches two of the three objectives that the Security Rule exists to protect. They cover confidentiality and availability of electronic protected health information (ePHI).
They leave out 33% of the topic they are discussing when they omit integrity.
The regulation at §164.306(a) states that covered entities and business associates must "ensure the confidentiality, integrity, and availability of all electronic protected health information." This is not optional language. Integrity (ensuring ePHI is not improperly altered or destroyed) is one of three co-equal objectives.
Omitting integrity from your Security Rule training means your workforce is learning an incomplete version of what the Security Rule requires. This could surface during an OCR audit or investigation as a training gap.
4. The Security Risk Assessment Is in the Wrong Place
Accountable's audit protection page walks users through their compliance onboarding. The Security Risk Assessment (SRA) appears at step 4. This fundamentally sits at odds with why an organization would perform an SRA in the first place.
Under the Security Rule at §164.308(a)(1)(ii)(A), the risk analysis is the mandatory first implementation specification. Every other safeguard decision — what to encrypt, how to configure access controls, which policies to write, what to include in training comes from the findings of your risk assessment. You cannot make informed decisions about any of those controls until you know what risks you are managing.
Putting the SRA at step 4 means an organization completes three steps of compliance work before understanding its own risk profile. That is backwards. The risk assessment comes first because everything else depends on it.
Accountable's SRA page also conflates three distinct assessments:
- Security Risk Assessment (required by the Security Rule)
- Gap analysis (an operational exercise comparing current state to regulatory requirements)
- Data Protection Impact Assessment (a concept from the EU's GDPR, not from HIPAA)
These serve different purposes and produce different outputs. Treating them as interchangeable can lead to an organization believing it completed a valid SRA when it actually performed a different type of assessment.
5. Guidance That Could Lead to Compliance Violations
Three pieces of Accountable's content contain guidance that, if followed, could directly create compliance risk for an organization.
Data retention: "keep less" is wrong for healthcare. Accountable's data retention article advises organizations to retain less data and frames data minimization as a universal best practice. The article conflates GDPR's right-to-erasure with HIPAA.
HIPAA has no right-to-erasure. Under §164.526, patients have the right to amend their records — not delete them. The regulation at §164.530(j)(2) requires covered entities to retain HIPAA-related documentation for six years from the date of creation or the date it was last in effect. State medical records retention laws often require even longer periods.
The article also suggests that more sensitive data should have shorter retention periods. In healthcare, the opposite is often true because clinical records, incident documentation, and compliance records carry extended or indefinite retention requirements. An organization that follows Accountable's "keep less" advice could destroy records it is legally required to maintain.
Wellness programs: missing the plan document amendment. Accountable's wellness program article discusses employer access to employee health data but omits the §164.504(f) requirement. When a group health plan shares PHI with the plan sponsor (the employer), the plan documents must be amended with specific provisions restricting how the employer uses and discloses that information. This is not optional. It is a precondition for the disclosure. Accountable's article does not mention it.
Authorization forms: compound authorization rules. Accountable's authorization form article covers the core elements of a valid authorization under §164.508 but is vague on compound authorizations. The regulation at §164.508(b)(3)(i) specifically requires that an authorization for psychotherapy notes cannot be combined with an authorization for other types of PHI. An organization using Accountable's checklist could inadvertently create an invalid authorization by combining psychotherapy notes with other disclosures on a single form.
6. The Breach Notification Blind Spot
Accountable publishes at least five articles that discuss breach notification. Across all of them, three critical regulatory requirements are consistently absent.
The notification timeline. Under §164.404(b), a covered entity must notify affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." The 60 days is an outer limit, not a target. HHS stated in the 2013 Omnibus Final Rule preamble (78 Fed. Reg. 5648) that "in some cases, it may be an 'unreasonable delay' to wait until the 60th day to provide notification." In other words, if a covered entity has the information it needs to notify by day 10, waiting until day 55 could itself be a violation — even though it falls within the 60-day window. OCR enforced this in 2017 when Presence Health settled for $475,000 after notifying 101 days after discovery. Accountable's articles use phrases like "without unreasonable delay" and "timely notification" but never state the actual regulatory timeline or the 60-day ceiling.
The 500-person media notice. Under §164.406(a), if a breach affects 500 or more individuals in a single state or jurisdiction, the covered entity must notify prominent media outlets in that area. This is a mandatory step that many organizations are unaware of until they need it.
Under-500 breach reporting. Under §164.408(c), breaches affecting fewer than 500 individuals must be reported to HHS within 60 days after the end of the calendar year in which they were discovered. This annual reporting obligation is easy to miss if your compliance platform does not remind you about it.
An organization relying on Accountable for breach response guidance would not know these deadlines or thresholds exist. During an actual breach, when speed and accuracy matter most, that gap could result in a late notification, which is itself an additional HIPAA violation.
7. "Consent" and "Authorization" Are Not the Same Thing
At least four Accountable articles use the words "consent" and "authorization" interchangeably. Under HIPAA, these are legally distinct concepts with different requirements.
- Consent (§164.506) is an optional mechanism that covered entities may use for treatment, payment, and health care operations (TPO). It is not required.
- Authorization (§164.508) is a mandatory mechanism required for uses and disclosures of PHI that fall outside TPO. Activities such as marketing, research, or sharing psychotherapy notes.
An authorization has specific required elements (description of PHI, named parties, purpose, expiration, signature, and required statements about revocation and redisclosure). A consent does not carry these same requirements.
When a compliance platform treats these as synonyms, it creates confusion about when an organization needs a simple consent versus a full §164.508 authorization. Using a consent form where an authorization is required could render the disclosure impermissible.
8. The Penalty Numbers They Will Not Tell You
Accountable's article on HIPAA violation costs describes the four-tier penalty structure but declines to state actual dollar amounts. The article references "per-violation fines" and "annual caps" without giving the numbers from §160.404, the regulation specification from the law.
These are public figures, adjusted annually and published in the Federal Register. Organizations evaluating their compliance risk need to know what the financial exposure actually is and not just that penalties "scale with culpability." Withholding the numbers makes it harder for a Privacy Officer to brief leadership on the financial stakes of noncompliance.
9. The Enforcement Agency They Leave Out
Every Accountable article that discusses HIPAA enforcement mentions the HHS Office for Civil Rights (OCR). None of them mention the Centers for Medicare & Medicaid Services (CMS).
CMS enforces the HIPAA Administrative Simplification provisions under 45 CFR Part 162. This is the transaction and code set standards that govern how covered entities submit and receive electronic claims, remittance advice, eligibility inquiries, and other standard transactions. If your organization handles electronic transactions (and virtually every healthcare organization does), CMS has enforcement authority over your compliance with those standards.
Presenting OCR as the only HIPAA enforcement body gives organizations an incomplete picture of their regulatory exposure.
10. Their Vendor Monitoring Claims Go Beyond the Law
Accountable's vendor management and third-party monitoring pages describe continuous vendor monitoring as a HIPAA requirement. The regulation does not require this.
HIPAA requires covered entities to enter into Business Associate Agreements with vendors that handle PHI (§164.502(e), §164.504(e)). The regulation requires reasonable safeguards and satisfactory assurances. It does not prescribe continuous monitoring, real-time security scoring, or ongoing surveillance of vendor environments.
Continuous vendor monitoring may be a sound operational practice. But presenting it as a regulatory mandate overstates what the law actually requires and could lead organizations to believe they are out of compliance simply because they do not use a continuous monitoring tool.
Where Accountable Gets It Right
Accuracy matters in both directions. Several areas of Accountable's content are solid:
- De-identification. Their article on the 18 HIPAA identifiers correctly lists all identifiers, accurately explains Safe Harbor versus Expert Determination, properly describes Limited Data Sets and Data Use Agreements, and gets the ZIP code population threshold (20,000) right.
- Business associate obligations. Their BA article covers subcontractor flow-down requirements, direct liability provisions, and BAA essentials accurately.
- Content volume. Accountable covers a wide range of HIPAA topics. For organizations looking for a general introduction to HIPAA concepts, much of their high-level content provides a reasonable starting point.
- Authorization form basics. Their authorization form article correctly identifies the core elements required under §164.508, even though it misses the compound authorization restrictions.
Credit where it is due. They have built a substantial content library and some of it reflects genuine familiarity with the regulation.
What This Means for Your Organization
A compliance platform that teaches fabricated regulatory concepts, omits hard deadlines, conflates distinct legal requirements, and positions data retention advice that contradicts the regulation is not a reliable foundation for your compliance program.
This does not mean every organization using Accountable is out of compliance. It means that your compliance cannot be better than the accuracy of the guidance you follow. If your platform tells you the SRA goes at step 4, you will build your program on an incomplete risk picture. If it never mentions the 60-day breach notification deadline, you may miss it during an actual incident.
Here is what to look for in any compliance tool or consultant:
- Do they cite the actual regulation? Vague references to "HIPAA requirements" without CFR citations are a red flag.
- Do they distinguish between what HIPAA requires and what they recommend? Good practice and legal mandate are different things.
- Do they acknowledge what HIPAA does not require? Overstating the law to sell features is a disservice to organizations trying to right-size their compliance program.
- Do they keep their training materials accurate? If the basics are wrong, the advanced guidance may be unreliable too.
Your Privacy Officer, compliance committee, or legal counsel should be able to trace every policy, procedure, and training element back to a specific regulatory provision. If they cannot, the program has gaps, regardless of which platform generated it.
FAQs
Is AccountableHQ HIPAA certified?
No, and neither is any other organization. HHS has never created or authorized a HIPAA certification program. No federal agency certifies HIPAA compliance. Any vendor that describes its product or its customers as "HIPAA certified" is using a term that has no regulatory meaning.
Does AccountableHQ's training cover the full Security Rule?
Accountable offers a free Security Rule training module at accountablehq.com/free-hipaa-training. The written description on that page states the Security Rule covers "confidentiality and availability" of ePHI — omitting integrity, one of the three co-equal objectives required by §164.306(a). The video embedded on the same page does reference all three, which means Accountable's own written content contradicts their own video. Organizations using this module for workforce training should be aware that the page-level summary a learner reads before and after the video is incomplete.
What HIPAA breach notification deadlines does AccountableHQ leave out?
Across multiple articles on breach notification, Accountable does not state the 60-day individual notification deadline (§164.404(b)), the 500-person media notification threshold (§164.406(a)), or the under-500 annual reporting timeline (§164.408(c)). These are mandatory requirements with specific deadlines.
Does HIPAA require continuous vendor monitoring?
No. HIPAA requires Business Associate Agreements (§164.502(e), §164.504(e)) and reasonable safeguards. It does not require continuous monitoring, real-time security scoring, or ongoing vendor surveillance. These may be useful operational practices, but they are not regulatory mandates.
Conclusion
We reviewed AccountableHQ's entire public content library against the HIPAA Administrative Simplification regulation and found 19 substantive accuracy problems, including fabricated compliance concepts, omitted deadlines, conflated legal terms, and guidance that could lead organizations toward compliance violations rather than away from them. Any compliance tool you evaluate should be held to the standard of the regulation it claims to implement. One Guy Consulting helps organizations build HIPAA compliance programs grounded in what the law actually says. Schedule a consultation to see the difference.
Sources
- 45 CFR Part 160 — General Administrative Requirements
- 45 CFR Part 164 — Security and Privacy
- §164.306(a) — Security Standards: General Rules
- §164.308(a)(1) — Security Management Process
- §164.404 — Notification to Individuals
- §164.406 — Notification to the Media
- §164.408 — Notification to the Secretary
- §164.506 — Uses and Disclosures to Carry Out TPO
- §164.508 — Uses and Disclosures for Which an Authorization Is Required
- §164.526 — Amendment of PHI
- §164.530(j) — Documentation Requirements
- §160.404 — Amount of Civil Money Penalty
- HHS FAQ #2003 — Are we required to certify compliance?
- OCR — Be Aware of Misleading Marketing Claims
- HHS Guidance — Technologies That Render PHI Unusable, Unreadable, or Indecipherable
- 2013 Omnibus Final Rule (78 Fed. Reg. 5566)
- OCR Enforcement — Presence Health Settlement
- Public Law 104-191 — Health Insurance Portability and Accountability Act of 1996
Related Reading: