Why there is no HIPAA auditor registry
HIPAA is a federal regulation (the Health Insurance Portability and Accountability Act, plus the HITECH Act and the Omnibus Rule), not a certification standard. The enforcement body is HHS OCR, which conducts its own audits but does not certify private-sector assessors. As a result, there is no equivalent of the PCI SSC QSA list or the AICPA SOC 2 registry. The de facto market is SOC 2 audit firms: any CPA firm can perform a HIPAA Security Risk Analysis, and most of the 168 SOC 2 firms in our directory do exactly that. Some firms also hold HITRUST External Assessor credentials, which is the deepest healthcare-specific expertise.