Business Strategy

Are You Ready for a HIPAA Audit?

Post by
Net Friends Icon
Susanna Perrett
Are You Ready for a HIPAA Audit thumbnail

Back in 2024, the Office for Civil Rights (OCR) resumed HIPAA compliance audits after a long pause. The current phase of audits started with an initial round of fifty reviews, and the OCR's enforcement posture has grown noticeably more assertive since.  

In 2025 alone, the OCR resolved 21 settlements and civil monetary penalties, its second-highest annual total on record, which collected more than $8.3 million. If your organization has been coasting, now is a good time to get more serious.

What the OCR Is Actually Looking At

The OCR's priorities are very clear. Two areas that keep coming up are the Security Rule and the Right of Access initiative.

What to focus on before a HIPAA audit micrographic with list
What to Focus on Before a HIPAA Audit

The Security Rule: The OCR launched a dedicated Risk Analysis Initiative in 2024, and it remains the agency's top enforcement driver. A huge share of settlements still trace back to incomplete or outdated risk analysis.

Right of Access Initiative: This deals with how quickly you honor patients' requests for their own records. This one also now includes a fresh emphasis on parental access to minors' records, an area the OCR has flagged for added scrutiny.

We will focus on the Security Rule in this article. Here are some key resources you should be familiar with:

1. Security Officer

Someone in your organization needs to be the named point of contact and responsible party for your security posture. An auditor will want to see a job description for this role along with clear evidence that the person has been doing the job, not just holding the title.

Bonus points if you name a Privacy Officer and a Compliance Officer. All three roles matter and each should have continuous coverage. In many instances, you do not need three separate individuals to fulfill these roles.

2. Risk Assessment

A risk assessment is rigorous, well documented, and shows that key stakeholders grappled with specific risks, weighed how likely each one is and how bad the impact would be, and built a plan to mitigate it.  

A risk assessment does not have to be perfect on the first try. Start by tackling the risks right in front of you, then revisit the list on a regular schedule to keep it fresh. Every time the Net Friends team sits down to do a risk assessment, we think we have seen it all and will not find anything new. We are always proven wrong (in the best way), and something fresh turns up every single time.

Bonus points if you have a Risk Register that tracks your mitigation work, and if you can provide evidence that you acted on what the risk assessment found. The OCR has been explicit that it looks for a living program.

3. Asset Inventory

Aim to keep three distinct and current inventories you can hand to an auditor without scrambling.  

  • Hardware: Workstations, servers, medical devices, and anything on your network that stores or transmits Protected Health Information (PHI).
  • Software: Installed applications, web portals, and SaaS tools touching PHI.
  • Data: This is where your PHI lives.
Bonus points for accounting for every storage location, including your cloud accounts. Assume any data on your systems could contain PHI unless you have proven otherwise.

4. Vendor Inventory

Keep a list of every third-party vendor you work with and flag which ones touch PHI. Make sure you have a countersigned Business Associate Agreement (BAA) on file for each one, along with a current point of contact.

Bonus points if you can show that every vendor signed your most recent BAA version. Longstanding vendors are the usual culprits here, sometimes with agreements old enough that they predate the HITECH Act.

5. Plans and Procedures

Ensure you have documentation covering secure operating procedures, contingency plans, and security incident response steps. Given how often ransomware shows up in healthcare breach reports, incident response deserves particular attention. If your team is starting from scratch, bringing in HIPAA compliance specialists to help build the core documents is recommended.

Bonus points if you can prove these plans were reviewed and tested within the last twelve months. An auditor wants to see documents that are used.

6. Staff Training

Your people are one of your best defenses. The OCR looks for evidence of regular staff education on handling electronic PHI, password hygiene, secure communication, and cybersecurity. Purpose built Security Awareness Training tools are worth the investment, both for tracking compliance and for running simulated phishing attempts to see whether the training stuck.

Bonus points for a training log your HR team can maintain, showing that everyone received standardized training on a consistent schedule.

Office for Civil Rights (OCR) quote graphic

HHS proposed sweeping changes in a Notice of Proposed Rulemaking published in January 2025. It would remove the addressable versus required flexibility, mandate encryption, enforce multi-factor authentication, require faster incident reporting, and add regular penetration testing.

Over one hundred hospital systems and provider groups formally asked HHS to withdraw or scale back the proposal, and HHS has since pushed its target for a final rule out to July 2027.  

That said, we recommend getting ahead of the changes. Encryption, MFA, and a tested incident response plan are good practice regardless of what happens to the proposed rule. Organizations that already have them in place will have a much shorter list of homework when the rule does eventually land.

The Time to Prepare Is Now

Touch base with your IT team or vendor and ask them if they are confident that they could respond well to an OCR audit today. If the answer is anything less than a clear yes, reach out to Net Friends. We would rather help you get audit ready now than have your first conversation with us start after a certified letter from the OCR lands on your desk.  

What to Read Next

How We Became HIPAA Experts  
How An MSP Helps You Prep for HIPAA Audits
 
Mastering Risk Assessments for Small Businesses

Take IT Off Your To-Do List.

Tech holding you back? Losing productivity to downtime?
Discover how we can simplify your tech and free up your time, contact us today.

Start a Conversation

At Net Friends, we believe in the power of human expertise. While we leverage AI to enhance our content and processes, all blog posts are written and edited by our knowledgeable staff. You can trust you are getting insights directly from our team.