HomeServicesHIPAA Compliance Audit

HIPAA Compliance Audit for Practices and Business Associates

A HIPAA compliance audit asks the questions an investigator would ask, before anyone else does. We compare what your risk analysis says with what your systems actually do, record each finding with screenshots and exports, and rank the fixes so the first weeks of work close the biggest gaps. The report is yours to keep and to hand to whoever does the remediation.

By The NetSys Group · Published · Editorial policy

The short answer

A HIPAA compliance audit is a point-in-time review of how well a practice or business associate meets the HIPAA Security Rule. NetSys checks your risk analysis, required by 45 CFR 164.308(a)(1)(ii)(A), against the safeguards configured on your systems, then delivers findings, evidence and a prioritized remediation plan. We do not certify compliance; HHS recognizes no private certification.

Closest related page: HIPAA compliance services. That page covers building and running your Security Rule safeguards month to month; this audit is a one-time check of where you stand, with a written fix plan.

Who the audit is for

Medical, dental and specialty practices, and the business associates that handle their patient data: billing services, labs, software vendors and IT providers. The trigger is usually one of these: a risk analysis nobody has touched in years, a new location or EHR, a payer or hospital asking for evidence, or a scare that showed how little was written down.

Official HIPAA audits are run by HHS's Office for Civil Rights, because the HITECH Act requires HHS to audit covered entities and business associates periodically. OCR's 2024-2025 round reviews 50 organizations on the Security Rule provisions most relevant to hacking and ransomware. Its settlements point the same way: in September 2026 it settled an investigation of a phishing breach at a genetic testing company, and the first failure listed was the lack of an accurate and thorough risk analysis. Our audit starts where OCR starts.

What makes a finding

A finding is only useful if someone else can check it. Each one in our report names the Security Rule standard it falls under, shows what we saw (a screenshot, an export or a log extract), states the risk to patient data in plain terms, and sizes the fix in hours, days or a project. Where we could not verify something, the report says so instead of assuming it. Findings are then ranked by risk and effort, so the remediation plan opens with the changes that remove the most exposure for the least work.

What the HIPAA Compliance Audit Covers

Risk Analysis Review

The first document OCR asks for, checked against reality.

  • Whether the analysis covers every system, device and vendor that touches ePHI
  • Likelihood and impact ratings compared with what we find on the systems
  • The risk management plan: which dated fixes were actually made
  • Gaps listed against 45 CFR 164.308(a)(1)(ii)(A) and (B)

Technical Safeguards

Checked in the settings and logs themselves.

  • Unique user IDs, MFA and prompt removal of departed staff in the EHR and email
  • Encryption on laptops, desktops, phones and backup media
  • Audit logs switched on, retained and actually reviewed
  • Transmission security for email, e-fax and patient messaging
  • Automatic logoff on shared workstations

Administrative and Vendor Controls

The paperwork has to match the practice.

  • A business associate agreement on file for every vendor that handles PHI
  • Workforce training records and the sanction policy
  • A contingency plan backed by restore results rather than intentions
  • Security incident procedures, including who makes breach decisions

Audit Deliverables

What stays with you after the fieldwork.

  • Findings list giving the standard, evidence, risk rating and effort for each item
  • Evidence file of screenshots, exports and configuration records
  • Remediation plan in priority order, with owners and target dates
  • Executive summary for the owner or board
  • A walkthrough with the engineer who did the work
Why NetSys

Why practices choose NetSys for a HIPAA audit

Fifteen minutes with a NetSys engineer, not a salesperson, and you will know where your hipaa compliance audit stands and what it would take to fix it. Call 845-203-3914 or request a call to discuss the scope and next steps.

  • We inspect the systems themselves, so the report reflects what is actually configured
  • Every finding is tied to the Security Rule standard it falls under, which is how an investigator reads a file
  • Plain about roles: we are not OCR or a law firm, and not a certifying body or auditor of record for any framework
  • The remediation plan is written for whoever does the work, whether that is your staff, your IT provider or NetSys
  • If you keep NetSys for remediation or ongoing management, the agreement is month to month
  • Founded in 1998, with one office, in Brooklyn

What the audit includes, and what it does not

The scope letter lists every item before work starts. This is the usual starting point.

AreaIncludedNot included
Risk analysisReview of your current analysis and a gap list against the Security RuleWriting a new risk analysis, which is often the first remediation item
Technical safeguardsInspection of access control, audit logging, encryption and transmission settingsChanging settings during the audit
Business associatesAgreement register checked against the vendors you actually useLegal review of agreement wording
TestingRestore evidence, plus vulnerability scans where you authorize themPenetration testing beyond the agreed scope
Privacy RuleSystem-level items, such as who can open records and how PHI leaves by emailNotices, policies and patient-rights processes, which belong to your privacy officer and counsel
ResultFindings, evidence and a prioritized remediation planA certificate, seal or statement that you are HIPAA compliant

An audit describes your systems on the dates we examined them. Keep the report with your compliance records: the Security Rule requires its documentation to be retained for six years (45 CFR 164.316(b)(2)(i)). This is general information, not legal advice.

How the audit runs

Access and vendor replies set the pace, so we arrange them first.

  • Scoping call: locations, headcount, systems holding ePHI, vendors, and what prompted the audit
  • Scope letter listing what we examine, the access we need, any authorized testing and the deliverables
  • Document request: current risk analysis, policies, BAA list, training records and incident log
  • Fieldwork: read-only admin access to your email platform, EHR access reports, device and backup consoles, and site visits where the scope calls for them
  • Draft findings checked with your security officer for accuracy
  • Final report, evidence file and remediation plan, followed by a walkthrough

How a HIPAA audit is priced

We quote a fixed scope after the scoping call and do not publish prices. These are the things that move the quote:

  • Number of locations, and whether any need an on-site visit
  • Workstations, servers and mobile devices that touch ePHI
  • Systems in scope: EHR or practice management, imaging, email, patient messaging and cloud storage
  • Number of business associates
  • Whether a current risk analysis exists for us to review
  • Technical testing you add, such as vulnerability scans

For NetSys managed clients, ongoing safeguard work is part of the monthly agreement. The audit is quoted on its own because it is a point-in-time report.

Common Questions

HIPAA Compliance Audit FAQs

What does a HIPAA compliance audit include?

A HIPAA compliance audit reviews your risk analysis, inspects the technical safeguards on your systems and checks the administrative records behind them. That covers access control, audit logs, encryption, backups, business associate agreements and training records. You receive findings, the evidence for each, and a remediation plan in priority order.

How often should a practice do a HIPAA risk assessment?

The Security Rule sets no fixed interval, but the risk analysis must stay accurate and be updated as your environment changes. HHS guidance says some organizations review it annually and others as needed. Annual is a sensible default. Update it sooner after a security incident, a new EHR or location, a change in ownership or turnover in key staff.

How much does a HIPAA audit cost?

It depends on scope: we quote a fixed scope after a short call and do not publish prices. The main drivers are how many locations, devices and systems hold patient data, how many business associates you use, and whether technical testing is included. A practice with a current risk analysis is quicker to audit than one starting from nothing.

Who performs HIPAA compliance audits?

Official audits are performed by HHS's Office for Civil Rights, which runs the audit program the HITECH Act requires. Everything else, including this service, is a review a practice commissions for itself. When you hire a HIPAA compliance auditor, ask for evidence behind each finding and a plain statement that no private audit makes you certified.

Can NetSys certify that we are HIPAA compliant?

No. HHS does not endorse or recognize private certifications under the Security Rule, and a certificate does not stop OCR from finding a violation later. What our audit gives you is a dated record of what was checked, what was found and what you fixed, which is the kind of evidence an investigator asks for.

Do business associates need a HIPAA compliance audit?

Business associates have their own Security Rule duties for the ePHI they handle, including the risk analysis, so an audit is just as useful for them. Billing services, labs, software vendors and IT providers can be asked by healthcare clients for proof of safeguards. We scope the audit to the systems and people that touch client data.

What happens after the audit?

You own the report and decide who fixes what. Your staff, your current IT provider or NetSys can work through the remediation plan, and each item carries an effort estimate so you can budget. We suggest closing the highest-risk items first, then scheduling a follow-up check on those items to confirm the fixes held.

HIPAA compliance audit

Find the gaps before an investigator does.

Tell us your locations, the systems that hold patient data and what prompted the audit. We will send a scope letter listing what we will examine, the access we need and the deliverables before any work starts.