HIPAA-Compliant Security Vendors
Security vendors that hold HIPAA certification
Okta
21/32Identity and access management platform providing secure authentication, authorization, and single sign-on for enterprises.
CrowdStrike
17/32Cloud-native endpoint protection platform providing threat intelligence, incident response, and cybersecurity solutions.
Zscaler
14/32Cloud-native zero trust security platform (ZIA/ZPA) for secure internet and application access.
Wiz
13/32Cloud-native application protection platform (CNAPP) for cloud security.
Splunk
11/32Data platform for security, observability, and IT operations (SIEM, log analytics), owned by Cisco.
Netskope
11/32Security service edge (SSE) and cloud security platform (CASB, SWG, ZTNA).
Palo Alto Networks
10/32Cybersecurity platform spanning network security, cloud security, and SOC automation.
BAA supported on select products; not listed as a formal certification on trust center page
1Password
9/32Password manager and secure digital wallet that stores passwords, documents, and sensitive information with end-to-end encryption.
AgileBits is not defined as a Business Associate pursuant to HIPAA nor subject to a BAA
Fortinet
9/32Network security and cybersecurity platform (firewalls, SASE, endpoint security).
Keeper
9/32Password management and privileged access security platform.
Auth0
8/32Identity and access management (authentication-as-a-service) platform, owned by Okta.
BAA available
Varonis
8/32Data security platform for data classification, access governance, and threat detection.
Bitdefender
8/32Cybersecurity platform for consumer and enterprise endpoint protection.
Bitwarden
7/32Open-source password manager and secrets management platform.
Annual third-party audits against Security Rule
Trend Micro
6/32Cybersecurity platform for endpoint, cloud, and network security.
BAA available
Mimecast
5/32Email and collaboration security platform for threat protection and data resilience.
Plus HITECH
Clerk
4/32Authentication and user management platform for developers.
BAA available on Enterprise plan
WorkOS
3/32Enterprise-readiness platform for SSO, directory sync, and authentication.
BAA available for enterprise-plan customers
Check Point
2/32Cybersecurity platform for network, cloud, and endpoint security.
Referenced in compliance solutions navigation
Cisco Duo
1/32Multi-factor authentication (MFA) and zero-trust access security platform from Cisco.
Supports HIPAA use cases (protects PHI access); not itself a HIPAA certification
These security vendors do not currently hold HIPAA certification:
- Snyk (not documented)
- SentinelOne (not documented)
- Rapid7 (not documented)
- Tenable (not documented)
- Qualys (not documented)
- Proofpoint (not documented)
- KnowBe4 (not documented)
- OneLogin (not documented)
- Ping Identity (not documented)
- JumpCloud (not documented)
- LastPass (not documented)
- Dashlane (not documented)
- Orca Security (not documented)
- Lacework (not documented)
- Darktrace (not documented)
- Cybereason (not documented)
- VMware Carbon Black (not documented)
- McAfee (not documented)
- Symantec (not documented)
- Sophos (not documented)
- ESET (not documented)
- Malwarebytes (not documented)
- Keeper Security (not documented)
- Ivanti (not documented)
- Tailscale (not documented)
- Checkmarx (not documented)
- Veracode (not documented)
- GitGuardian (not documented)
- Semgrep (not documented)
Know a vendor we're missing?