CompyMax

HIPAA compliance audits

Three different things get called a HIPAA audit, and they want different preparation. Knowing which one you are facing decides what you should be doing this week — and in two of the three cases, the answer is not “hire someone.”

Last reviewed .

If you are already under investigation, start with a lawyer

This page is for preparation, not for people holding a data request with a deadline on it. We do not provide legal advice or act for anyone before a regulator — if OCR has contacted you, engage counsel experienced in these matters before you respond. What follows is about the records you should already have, which is a different problem and a much cheaper one.

The three kinds, and what each one asks for

The HHS Office for Civil Rights

An OCR investigation or compliance review

Usually prompted by a complaint or a breach report rather than arriving at random. 45 CFR 160.310 sets out what you owe: records and compliance reports on request, cooperation with the review, and access to books, records and other sources of information. What it asks for is contemporaneous evidence — documents that existed before the request, with dates that predate it.

Have ready: A current risk analysis, your policy set with version history, training completion records, executed agreements, and your incident log including the incidents you assessed and concluded were not reportable.

A hospital, health system, payer or prime contractor

A client auditing you

Far more common than an OCR investigation, and the one with money attached — it usually arrives as a security questionnaire during procurement or at contract renewal. The reviewer is not testing whether you are perfect. They are deciding whether choosing you is defensible to their own compliance team.

Have ready: A signed business associate agreement, evidence of a dated risk analysis, written policies with acknowledgement dates, per-person training certificates, and your subprocessor list.

You, on a schedule

Your own periodic evaluation

45 CFR 164.308(a)(8) requires a periodic technical and non-technical evaluation establishing the extent to which your security policies and procedures meet the rule's requirements — especially following environmental or operational change. A new practice management system, a second location or a shift to remote work all trigger it.

Have ready: A dated evaluation record showing what was reviewed, by whom, what changed since last time, and what you decided to do about the gaps.

The rule that catches people out

Documentation has to be retained for six years from when it was created or when it was last in effect, whichever is later — 45 CFR 164.316(b)(2)(i). For a policy, the clock starts when the policy stopped being in effect, not when you wrote it. A policy written in 2019 and replaced in 2026 has to be kept until 2032.

That is why overwriting a policy document in place is a problem: it destroys the very record the retention rule requires. Superseded versions have to survive, which in practice means version history rather than a folder of files named policy-final-v3.docx.

The same applies to incidents you assessed and concluded were not reportable breaches. Those determinations and the reasoning behind them are exactly what the burden of proof at 45 CFR 164.414(b) expects you to be able to produce. An empty incident log does not demonstrate that nothing happened — it demonstrates that nothing was recorded.

What actually makes this cheap

  • Evidence that predates the request

    A risk analysis dated last quarter is worth more than a thorough one produced the week after a letter arrives. Contemporaneous records are the point; anything assembled reactively reads as exactly that.

  • Dates on everything, per person

    “We train our staff annually” is an assertion. A list of names with completion dates and certificate numbers is evidence. The difference is what separates a short exchange from a long one.

  • Gaps with owners and dates

    An open remediation item with a named owner and a target date is a functioning programme. The same gap with nothing attached to it is a finding. Reviewers are used to imperfection and are assessing whether you have a process.

  • A log of the incidents that came to nothing

    Most incidents are not reportable breaches. Recording the ones you assessed and closed is what shows the assessment happens at all.

Common questions

Does HIPAA compliance require an audit?
Not an external certification audit — no such certification exists and no government body issues one. What the Security Rule requires, at 45 CFR 164.308(a)(8), is a periodic technical and non-technical evaluation of how well your security policies still meet the rule's requirements, which you can perform internally. That is a distinct obligation from the risk analysis at 164.308(a)(1)(ii)(A), and organizations routinely do one and assume it covers the other.
Who performs HIPAA audits?
It depends which of the three kinds you mean. The HHS Office for Civil Rights performs investigations and compliance reviews, usually triggered by a complaint or a reported breach. Your clients — hospitals, health systems, payers — audit you before and during contracts. And you perform your own periodic evaluation. Independent firms can be hired for a mock audit, but no firm can issue an official certification.
How often is a HIPAA audit done?
OCR investigates in response to complaints and breach reports rather than on a calendar. Client audits typically arrive at contract signing and on renewal, often annually. Your own evaluation is required periodically and after material changes to your systems or operations — annual is the defensible convention. Whatever the trigger, the documentation you produce must have been retained for six years (45 CFR 164.316(b)(2)(i)).
How much does a HIPAA audit cost?
OCR does not charge for an investigation — the cost there is your time, remediation and any penalty. A client's audit of you costs whatever a stalled contract costs. A third-party assessment firm typically charges four to five figures for a small organization. Your own required internal evaluation costs staff hours plus whatever keeps the records — which is the version this page is about preparing for.

The records are the whole job. Keep them current and dated.

Run the risk assessment, track the gaps you find, keep policies versioned and training recorded per person, and log every incident including the ones that came to nothing. Then producing evidence is an export rather than a fortnight. 14 days free, no credit card, no sales call.

Informational only, based on the published text of 45 CFR Parts 160 and 164 as of 29 July 2026. This is not legal advice, and no organization or product can be “HIPAA certified” — no such designation exists. We do not provide audit defence, representation before regulators, or any assurance as to the outcome of an investigation. Compliance depends on your own configuration, documentation and executed agreements. See our editorial standards.