Your statement illustrates a misunderstanding of what HIPAA even requires.
HIPPA is not a compliance program. It is a law and set of regulations. There is no such thing as a way to "certify" software as being "HIPAA Compliant" because it is a meaningless term.
To be "HIPAA compliant", the entire software + solution stack needs to comply with the regulations.
In this case, he most likely made a dashboard that redacted PII from the eyes of consumers except on a need-to-know basis - because that is the heart of HIPAA. There is no need to inspect the code to illustrate this kind of "compliance", you look at the solution and what it provides.