Skip to main content

HIPAA Security Audit

A structured review of the controls, policies and configurations you actually have in place — measured against the framework you are actually being held to.

What We Review

The HIPAA Security Rule organises safeguards into three categories. An audit covers those, plus the operational areas an investigator asks about first.

Administrative Safeguards

Risk analysis, workforce training, sanction policy, incident response and the assigned security responsibility — the paperwork that has to exist and be current, not merely have existed once.

Technical Safeguards

Access control, audit logging, integrity controls and encryption in transit and at rest — and whether the logs anybody would need after an incident are actually being kept.

Physical Safeguards

Facility access, workstation use and security, and device and media disposal — including what happens to a laptop or drive when it leaves the organisation.

Access & Identity

Who has access to what, how it was granted, whether it is reviewed, and whether leavers really lose it. Stale access is the finding that turns up in almost every audit.

Backups & Recovery

Whether backups exist, whether they are encrypted, and — the part that is usually skipped — whether a restore has ever actually been tested.

Third-Party & Vendor Risk

Which vendors touch protected health information, whether a business associate agreement is in place with each of them, and what those agreements actually commit anybody to.

Medical professional reviewing compliance documents at a desk

How It Works

Three stages, scoped around the framework you are being measured against.

1

Scope & Evidence

We agree what is in scope and which framework applies, then collect the policies, configurations and evidence that exist today — including the honest answer where something does not exist yet.

2

Assess

We measure what we find against the framework you are working to, separating what is genuinely missing from what exists but is not evidenced — because those need very different fixes.

3

Report

Findings ranked by risk, with what to fix and in what order. Written so you can hand it to whoever asked for it, and act on it without needing us in the room.

Request a Quote

Eight short questions. We use them to scope the engagement and come back with a quote — usually within one business day.

Your details
About the engagement
Are there specific requirements or frameworks involved? (optional)

Testing can only begin once somebody able to authorise it has signed off in writing. “No” or “I need to confirm” is a fine answer — we will work through it with you.

Please do not include patient names, clinical details, or other protected health information in this inquiry. We will arrange an appropriate secure process if your request requires it.

Frequently Asked Questions

A structured review of your security controls, policies and configurations against a framework, producing a written record of where you stand and what to fix. It covers what exists and whether it is working, rather than only what a tool can detect.

An audit asks whether the right controls exist and are working. A penetration test asks whether an attacker can get through them anyway. They answer different questions and are often run together, because passing one says very little about the other.

The request form asks which apply to you, including HIPAA, PCI DSS, SOC 2 and insurance questionnaires. The engagement is scoped around your answer rather than run against a fixed checklist that may not be the one you are measured on.

They cover different ground. A clean penetration test says nothing about whether your risk analysis, workforce training, policies or business associate agreements meet the HIPAA Security Rule — and those are what an investigator asks for first.

Healthcare data protection and security monitoring dashboard

Related Reading

Where an audit fits alongside the rest of a HIPAA security programme.

Know Where You Actually Stand

Tell us which framework you are being measured against and what is in scope. We will come back with a quote.