HIPAA Security Audit
A structured review of the controls, policies and configurations you actually have in place — measured against the framework you are actually being held to.
What We Review
The HIPAA Security Rule organises safeguards into three categories. An audit covers those, plus the operational areas an investigator asks about first.
Administrative Safeguards
Risk analysis, workforce training, sanction policy, incident response and the assigned security responsibility — the paperwork that has to exist and be current, not merely have existed once.
Technical Safeguards
Access control, audit logging, integrity controls and encryption in transit and at rest — and whether the logs anybody would need after an incident are actually being kept.
Physical Safeguards
Facility access, workstation use and security, and device and media disposal — including what happens to a laptop or drive when it leaves the organisation.
Access & Identity
Who has access to what, how it was granted, whether it is reviewed, and whether leavers really lose it. Stale access is the finding that turns up in almost every audit.
Backups & Recovery
Whether backups exist, whether they are encrypted, and — the part that is usually skipped — whether a restore has ever actually been tested.
Third-Party & Vendor Risk
Which vendors touch protected health information, whether a business associate agreement is in place with each of them, and what those agreements actually commit anybody to.
How It Works
Three stages, scoped around the framework you are being measured against.
Scope & Evidence
We agree what is in scope and which framework applies, then collect the policies, configurations and evidence that exist today — including the honest answer where something does not exist yet.
Assess
We measure what we find against the framework you are working to, separating what is genuinely missing from what exists but is not evidenced — because those need very different fixes.
Report
Findings ranked by risk, with what to fix and in what order. Written so you can hand it to whoever asked for it, and act on it without needing us in the room.
Request a Quote
Eight short questions. We use them to scope the engagement and come back with a quote — usually within one business day.
Frequently Asked Questions
A structured review of your security controls, policies and configurations against a framework, producing a written record of where you stand and what to fix. It covers what exists and whether it is working, rather than only what a tool can detect.
An audit asks whether the right controls exist and are working. A penetration test asks whether an attacker can get through them anyway. They answer different questions and are often run together, because passing one says very little about the other.
The request form asks which apply to you, including HIPAA, PCI DSS, SOC 2 and insurance questionnaires. The engagement is scoped around your answer rather than run against a fixed checklist that may not be the one you are measured on.
They cover different ground. A clean penetration test says nothing about whether your risk analysis, workforce training, policies or business associate agreements meet the HIPAA Security Rule — and those are what an investigator asks for first.
Related Reading
Where an audit fits alongside the rest of a HIPAA security programme.
Know Where You Actually Stand
Tell us which framework you are being measured against and what is in scope. We will come back with a quote.