If you’re reviewing HIPAA compliance software, confirm the provider truly understands the rules it claims to support. We reviewed every blog post, product page, and training module on AccountableHQ’s site. Then we compared their statements to HIPAA rules (Specifically, § 45 CFR Parts 160, 162, and 164).
We found 19 substantive problems. Some are embarrassing but harmless. Others could lead a business to make compliance decisions based on guidance that directly contradicts what the law requires.
This article is not a feature comparison. We have a separate page for that.
This article is about accuracy. Here we'll discuss where Accountable explains the law correctly. We will also discuss where they get it wrong. Last, we'll review what the law actually says.
What We Found in Our AccountableHQ HIPAA Review

1. There Is No Such Thing as "HIPAA Certification"

Accountable uses the phrase "HIPAA certified" more than 20 times across their site. Their onboarding flow ends with a screen that reads "HIPAA CERTIFIED." They sell a product called an audit protection guarantee that positions this certification as the end result of their process.
The problem: HHS has never created, endorsed, or authorized a HIPAA certification program. No federal agency certifies firms as HIPAA compliant. HHS has stated this in many official sources:
- HHS FAQ #2003: "HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule."
- OCR Misleading Marketing Claims guidance: "HHS and OCR do not endorse any private consultants' or education providers' seminars, materials or systems, and do not certify any persons or products as 'HIPAA compliant.'"
This matters because the word "certification" implies a federally recognized status. It does not exist. An business that believes it has been "certified" may stop performing the ongoing activities that HIPAA actually requires, like periodic risk assessments, policy updates, and workforce training because it thinks the work is done.
Accountable also uses several invented variants of this concept across different pages:
- "HIPAA HITECH Certification" on their call center software page. No such certification exists under either HIPAA or the HITECH Act.
- "HIPAA e-signature compliance" on their e-signature page, presented as a formal standard. HIPAA does not contain e-signature rules. The ESIGN Act and state laws govern electronic signatures; HIPAA's rules focus on access controls and audit trails for ePHI systems.
- "HIPAA encryption standards" referenced four times on their EMR software page. HIPAA does not publish encryption standards. The Security Rule at 164.312(a)(2)(iv) and 164.312(e)(2)(ii) makes encryption an addressable implementation specification. The regulation is intentionally technology-neutral it says "implement a mechanism to encrypt" and names no specific standard. NIST publishes the encryption standards (AES-256, etc.) that firms often adopt, but those are NIST standards, not HIPAA standards. HHS does reference NIST in a separate guidance document issued under the HITECH Act for the breach notification safe harbor at 164.402 but that guidance is not part of the HIPAA regulation itself.
When a compliance platform invents regulatory concepts that do not exist, it raises a basic question about how well the platform understands the law it is teaching.
2. They Got the Name of the Law Wrong

Accountable's introductory training module, which is the first thing a new user sees, identifies the law as the "Health Insurance and Portability and Accountability Act."
The actual name is the Health Insurance Portability and Accountability Act. There is no "and" between "Insurance" and "Portability." Public Law 104-191 is clear on this.
This is a small mistake almost certainly a typo. But it has appeared in training material taken thousands of times without being caught. For a platform whose entire product is regulatory accuracy, that raises a fair question: if the first line of the first lesson was never proofread, what else was missed? Compliance is a discipline of precision. The vendor teaching it should model that standard.
Companies use this training to satisfy their HIPAA workforce training requirements. If an auditor reviews your training records and the training gets the name of the law wrong in the first lesson, it does not inspire confidence in the rest of the curriculum.
3. Their Security Rule Training Omits 1/3 Core Requirements

Accountable's Security Rule training module teaches two of the three objectives that the Security Rule exists to protect. They cover confidentiality and availability of electronic protected health information (ePHI).
They leave out 33% of the topic they are discussing when they omit integrity.
The regulation at 164.306(a) states that covered entities and business associates must "ensure the confidentiality, integrity, and availability of all electronic protected health information." This is not optional language. Integrity (ensuring ePHI is not improperly altered or destroyed) is one of three co-equal objectives.
Omitting integrity from your Security Rule training means your workforce is learning an incomplete version of what the Security Rule requires. This could surface during an OCR audit or investigation as a training gap.
4. The Security Risk Assessment Is in the Wrong Place

Accountable's audit protection page walks users through their compliance onboarding. The Security Risk Assessment (SRA) appears at step 4. This fundamentally sits at odds with why a business would perform an SRA in the first place.
Under the Security Rule at 164.308(a)(1)(ii)(A), the risk analysis is the mandatory first implementation specification. Every other safeguard decision what to encrypt, how to configure access controls, which policies to write, what to include in training comes from the findings of your risk assessment. You cannot make informed decisions about any of those controls until you know what risks you are managing.
Putting the SRA at step 4 means a business completes three steps of compliance work before understanding its own risk profile. That is backwards. The risk assessment comes first because everything else depends on it.
Accountable's SRA page also conflates three distinct assessments:
- Security Risk Assessment (required by the Security Rule)
- Gap analysis (an operational exercise comparing current state to regulatory requirements)
- Data Protection Impact Assessment (a concept from the EU's GDPR, not from HIPAA)
These serve different purposes and produce different outputs. Treating them as interchangeable can lead to a business believing it completed a valid SRA when it actually performed a different type of assessment.
5. Guidance That Could Lead to Compliance Violations

Three pieces of Accountable's content contain guidance that, if followed, could directly create compliance risk for a business.
Data retention: "keep less" is wrong for healthcare. Accountable's data retention article advises firms to retain less data and frames data minimization as a universal best practice. The article conflates GDPR's right-to-erasure with HIPAA.
HIPAA has no right-to-erasure. Under 164.526, patients have the right to amend their records not delete them. The regulation at 164.530(j)(2) requires covered entities to retain HIPAA-related records for six years from the date of creation or the date it was last in effect. State medical records retention laws often require even longer periods.
The article also suggests that more sensitive data should have shorter retention periods. In healthcare, the opposite is often true because clinical records, incident records, and compliance records carry extended or indefinite retention rules. An business that follows Accountable's "keep less" advice could destroy records it is legally required to maintain.
Wellness programs: missing the plan document amendment. Accountable's wellness program article discusses employer access to employee health data but omits the 164.504(f) requirement. When a group health plan shares PHI with the plan sponsor (the employer), the plan documents must be amended with specific provisions restricting how the employer uses and discloses that information. This is not optional. It is a precondition for the disclosure. Accountable's article does not mention it.
Authorization forms: compound authorization rules. Accountable's authorization form article covers the core elements of a valid authorization under 164.508 but is vague on compound authorizations. The regulation at 164.508(b)(3)(i) clearly requires that an authorization for psychotherapy notes cannot be combined with an authorization for other types of PHI. An business using Accountable's checklist could inadvertently create an invalid authorization by combining psychotherapy notes with other disclosures on a single form.
6. The Breach Notification Blind Spot

Accountable publishes at least five articles that discuss breach notification. Across all of them, three critical regulatory rules are consistently absent.
The notification timeline. Under 164.404(b), a covered entity must notify affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach."
The 60 days is an outer limit, not a target.
HHS stated in the 2013 Omnibus Final Rule preamble (78 Fed. Reg. 5648) that "in some cases, it may be an 'unreasonable delay' to wait until the 60th day to provide notification." In other words, if a covered entity has the information it needs to notify by day 10, waiting until day 55 could itself be a violation even though it falls within the 60-day window.
OCR enforced this in 2017 when Presence Health settled for $475,000 after notifying 101 days after discovery. Accountable's articles use phrases like "without unreasonable delay" and "timely notification" but never state the actual regulatory timeline or the 60-day ceiling.
The 500-person media notice. Under 164.406(a), if a breach affects 500 or more individuals in a single state or jurisdiction, the covered entity must notify prominent media outlets in that area. This is a mandatory step that many firms are unaware of until they need it.
Under-500 breach reporting. Under 164.408(c), breaches affecting fewer than 500 individuals must be reported to HHS within 60 days after the end of the calendar year in which they were discovered. This annual reporting duty is easy to miss if your compliance platform does not remind you about it.
An business relying on Accountable for breach response guidance would not know these deadlines or thresholds exist. During an actual breach, when speed and accuracy matter most, that gap could result in a late notification, which is itself an extra HIPAA violation.
7. "Consent" and "Authorization" Are Not the Same Thing

At least four Accountable articles use the words "consent" and "authorization" interchangeably. Under HIPAA, these are legally distinct concepts with different rules.
- Consent (164.506) is an optional mechanism that covered entities may use for treatment, payment, and health care operations (TPO). It is not required.
- Authorization (164.508) is a mandatory mechanism required for uses and disclosures of PHI that fall outside TPO. Activities such as marketing, research, or sharing psychotherapy notes.
An authorization has specific required elements (description of PHI, named parties, purpose, expiration, signature, and required statements about revocation and redisclosure). A consent does not carry these same rules.
When a compliance platform treats these as synonyms, it creates confusion about when a business needs a simple consent versus a full 164.508 authorization. Using a consent form where an authorization is required could render the disclosure impermissible.
8. The Penalty Numbers They Will Not Tell You

Accountable's article on HIPAA violation costs describes the four-tier penalty structure but declines to state actual dollar amounts. The article references "per-violation fines" and "annual caps" without giving the numbers from 160.404, the law specification from the law.
These are public figures, adjusted annually and published in the Federal Register. Companies evaluating their compliance risk need to know what the financial exposure actually is and not just that penalties "scale with culpability." Withholding the numbers makes it harder for a Privacy Officer to brief leadership on the financial stakes of noncompliance.
9. The Enforcement Agency They Leave Out

Every Accountable article that discusses HIPAA enforcement mentions the HHS Office for Civil Rights (OCR). None of them mention the Centers for Medicare & Medicaid Services (CMS).
CMS enforces the HIPAA Administrative Simplification provisions under 45 CFR Part 162. This is the transaction and code set standards that govern how covered entities submit and receive electronic claims, remittance advice, eligibility inquiries, and other standard transactions. If your business handles electronic transactions (and virtually every healthcare business does), CMS has enforcement authority over your compliance with those standards.
Presenting OCR as the only HIPAA enforcement body gives firms an incomplete picture of their regulatory exposure.
10. Their Vendor Monitoring Claims Go Beyond the Law

Accountable's vendor management and third-party monitoring pages describe continuous vendor monitoring as a HIPAA requirement. The regulation does not require this.
HIPAA requires covered entities to enter into Business Associate Agreements with vendors that handle PHI (164.502(e), 164.504(e)). The regulation requires reasonable safeguards and satisfactory assurances. It does not prescribe continuous monitoring, real-time security scoring, or ongoing surveillance of vendor environments.
Continuous vendor monitoring may be a sound operational practice. But presenting it as a regulatory mandate overstates what the law actually requires and could lead firms to believe they are out of compliance simply because they do not use a continuous monitoring tool.
Where Accountable Gets It Right

Accuracy matters in both directions. Several areas of Accountable's content are solid:
- De-identification. Their article on the 18 HIPAA identifiers correctly lists all identifiers, accurately explains Safe Harbor versus Expert Determination, properly describes Limited Data Sets and Data Use Agreements, and gets the ZIP code population threshold (20,000) right.
- Business associate duties. Their BA article covers subcontractor flow-down rules, direct liability provisions, and BAA essentials accurately.
- Content volume. Accountable covers a wide range of HIPAA topics. For firms looking for a general introduction to HIPAA concepts, much of their high-level content gives a reasonable starting point.
- Authorization form basics. Their authorization form article correctly identifies the core elements required under 164.508, even though it misses the compound authorization restrictions.
Credit where it is due. They have built a substantial content library and some of it reflects genuine familiarity with the law.
What This Means for Your Organization

A compliance platform that teaches fabricated regulatory concepts, omits hard deadlines, conflates distinct legal rules, and positions data retention advice that contradicts the law is not a reliable foundation for your compliance program.
This does not mean every business using Accountable is out of compliance. It means that your compliance cannot be better than the accuracy of the guidance you follow. If your platform tells you the SRA goes at step 4, you will build your program on an incomplete risk picture. If it never mentions the 60-day breach notification deadline, you may miss it during an actual incident.
Here is what to look for in any compliance tool or consultant:
- Do they cite the actual regulation? Vague references to "HIPAA requirements" without CFR citations are a red flag.
- Do they distinguish between what HIPAA requires and what they recommend? Good practice and legal mandate are different things.
- Do they acknowledge what HIPAA does not require? Overstating the law to sell features is a disservice to firms trying to right-size their compliance program.
- Do they keep their training materials accurate? If the basics are wrong, the advanced guidance may be unclear too.
Your Privacy Officer, compliance committee, or legal counsel should be able to trace every policy, procedure, and training element back to a specific regulatory provision. If they cannot, the program has gaps, no matter which platform generated it.
FAQs
Is AccountableHQ HIPAA certified?
No, and neither is any other business. HHS has never created or authorized a HIPAA certification program. No federal agency certifies HIPAA compliance. Any vendor that describes its product or its customers as "HIPAA certified" is using a term that has no regulatory meaning.
Does AccountableHQ's training cover the full Security Rule?
Accountable offers a free Security Rule training module at accountablehq.com/free-hipaa-training. The written description on that page states the Security Rule covers "confidentiality and availability" of ePHI omitting integrity, one of the three co-equal objectives required by 164.306(a). The video embedded on the same page does reference all three, which means Accountable's own written content contradicts their own video. Companies using this module for workforce training should be aware that the page-level summary a learner reads before and after the video is incomplete.
What HIPAA breach notification deadlines does AccountableHQ leave out?
Across many articles on breach notification, Accountable does not state the 60-day individual notification deadline (164.404(b)), the 500-person media notification threshold (164.406(a)), or the under-500 annual reporting timeline (164.408(c)). These are mandatory rules with specific deadlines.
Does HIPAA require continuous vendor monitoring?
No. HIPAA requires Business Associate Agreements (164.502(e), 164.504(e)) and reasonable safeguards. It does not require continuous monitoring, real-time security scoring, or ongoing vendor surveillance. These may be useful operational practices, but they are not regulatory mandates.
Conclusion

We reviewed AccountableHQ's entire public content library against the HIPAA Administrative Simplification regulation and found 19 substantive accuracy problems, including fabricated compliance concepts, omitted deadlines, conflated legal terms, and guidance that could lead firms toward compliance violations rather than away from them. Any compliance tool you evaluate should be held to the standard of the law it claims to implement. One Guy Consulting helps firms build HIPAA compliance programs grounded in what the law actually says. Schedule a consultation to see the difference.
One Guy Consulting is NOT representing any law firm and Chuck Weiselberg is NOT an Attorney. This article does not provide legal advice. It merely points out discrepancies between two sets of publicly available information. Please consult an Attorney for interpretations of the law.
Sources
- 45 CFR Part 160 General Administrative Requirements
- 45 CFR Part 164 Security and Privacy
- 164.306(a) Security Standards: General Rules
- 164.308(a)(1) Security Management Process
- 164.404 Notification to Individuals
- 164.406 Notification to the Media
- 164.408 Notification to the Secretary
- 164.506 Uses and Disclosures to Carry Out TPO
- 164.508 Uses and Disclosures for Which an Authorization Is Required
- 164.526 Amendment of PHI
- 164.530(j) Documentation Requirements
- 160.404 Amount of Civil Money Penalty
- HHS FAQ #2003 Are we required to certify compliance?
- OCR Be Aware of Misleading Marketing Claims
- HIPAA Journal — HIPAA Encryption Requirements and the Breach Safe Harbor
- 2013 Omnibus Final Rule (78 Fed. Reg. 5566)
- OCR Enforcement Presence Health Settlement
- Public Law 104-191 Health Insurance Portability and Accountability Act of 1996
Related Reading:
Frequently Asked Questions
Is AccountableHQ HIPAA certified?
No, and neither is any other business. HHS has never created or authorized a HIPAA certification program. No federal agency certifies HIPAA compliance. Any vendor that describes its product or its customers as "HIPAA certified" is using a term that has no regulatory meaning.
Does AccountableHQ's training cover the full Security Rule?
Accountable offers a free Security Rule training module at accountablehq.com/free-hipaa-training. The written description on that page states the Security Rule covers "confidentiality and availability" of ePHI omitting integrity, one of the three co-equal objectives required by 164.306(a) . The video embedded on the same page does reference all three, which means Accountable's own written content contradicts their own video.
What HIPAA breach notification deadlines does AccountableHQ leave out?
Across multiple articles on breach notification, Accountable does not state the 60-day individual notification deadline ( 164.404(b) ), the 500-person media notification threshold ( 164.406(a) ), or the under-500 annual reporting timeline ( 164.408(c) ). These are mandatory requirements with specific deadlines.
Does HIPAA require continuous vendor monitoring?
No. HIPAA requires Business Associate Agreements ( 164.502(e) , 164.504(e) ) and reasonable safeguards. It does not require continuous monitoring, real-time security scoring, or ongoing vendor surveillance. These may be useful operational practices, but they are not regulatory mandates.