Guide

HIPAA Audit: what to expect

What an OCR investigation looks like, what gets requested first, and what a customer-driven audit demands instead.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

What an OCR investigation looks like, what gets requested first, and what a customer-driven audit demands instead.

The two kinds of audit

The phrase “HIPAA audit” covers two very different events. The first is regulatory: an investigation or compliance review by the HHS Office for Civil Rights, which enforces the Privacy, Security, and Breach Notification Rules. The second is commercial: a customer, partner, or cyber insurer examining your programme before they will do business with you. The regulatory kind is rarer and higher-stakes; the commercial kind is routine and, for most health-tech companies, the one that actually determines revenue. Preparing well for either prepares you for both, because they ask for the same artefacts.

One thing neither of them produces is a certification. HHS operates no certification programme, and any vendor selling a “HIPAA certified” badge is selling decoration. What a good audit produces is documented evidence that your programme meets the rule — which is what customers, insurers, and OCR each accept.

Investigation triggers

A complaint, a reported breach affecting 500 or more individuals, a media report, or a compliance review. Most organisations meet OCR after a breach, not before.

Complaints are the highest-volume trigger — any patient, employee, or former employee can file one online, and OCR reviews every submission. Breach reports are the second: reporting a breach affecting 500 or more individuals reliably draws follow-up questions, and even smaller breaches logged in the annual submission can prompt inquiries if a pattern appears. The practical implication is that your first OCR contact will almost certainly arrive when something has already gone wrong, which is exactly the moment your documentation needs to already exist.

The first document request

The current risk analysis and risk management plan, policies and procedures, training records, and BAAs. Organisations that cannot produce a current risk analysis start the process badly.

The data request letter typically gives a response window measured in weeks, not months, and asks for documents as they existed on relevant dates — meaning you cannot write them after the fact without that being obvious from metadata and version history. Beyond the core four, expect requests for the Notice of Privacy Practices, incident and breach logs, sanction records, and evidence that specific safeguards (encryption, access controls, audit logging) were in place at the time of the incident under review.

How the interaction goes from there depends heavily on posture. Organisations that respond completely, on time, and with organised evidence often resolve investigations with technical assistance or voluntary corrective action. Organisations that respond late, partially, or with obviously retrofitted documents move toward resolution agreements and civil money penalties — which are tiered by culpability, from unknowing violations up to wilful neglect left uncorrected.

Customer audits

Increasingly the more frequent event. Enterprise health systems send 200-question assessments and expect evidence attachments. This is where a trust centre and a pre-built answer library pay for themselves.

A customer security review differs from OCR in three ways. It happens before the relationship rather than after an incident. It usually maps to a framework broader than HIPAA — expect SOC 2, HITRUST, or NIST-flavoured questions alongside the regulatory ones. And it is negotiable in tone but not in substance: a thin answer delays the deal, and deals have deadlines that regulators do not.

The efficient approach is to answer the questionnaire once, properly, and reuse it. Maintain a canonical answer library keyed to common question patterns, keep the evidence attachments (policies, pen test summary, risk analysis executive summary, training completion export) in one place, and version everything so you are never sending last year’s answers about this year’s stack.

Preparing

Keep the four core artefacts current: risk analysis, policy set with acknowledgements, training records, BAA register. Everything else is recoverable; those four are not recoverable retroactively.

That last point is the whole strategy. You can stand up a missing log review process next quarter, but you cannot create a 2024 risk analysis in 2026. The artefacts that prove history — assessments, acknowledgements, training completions, signed agreements — only exist if they were captured at the time. A useful discipline is the internal mock request: once a year, have someone play OCR, issue the standard document list with a two-week deadline, and see what you can actually produce. The gaps you find are your remediation plan, and a gap assessment does the same thing with outside eyes.

During the audit itself

A few rules of engagement that hold for both audiences. Assign a single point of contact so answers stay consistent. Answer the question asked — volunteering unrequested material expands scope. Never guess; “we will confirm and follow up” is always acceptable, an inaccurate answer never is. And involve counsel early for anything regulatory: this page is operational guidance, and an OCR letter is precisely the moment for legal advice.

The timeline, roughly

For an OCR investigation: the notification letter arrives with a data request and a response window of weeks; you acknowledge, assign your point of contact, and involve counsel. Document production follows, sometimes with supplemental requests and interviews. Then a long quiet period — months is normal — before resolution: closure, technical assistance, a voluntary corrective action plan, or in the serious cases a resolution agreement with monitoring. The whole arc commonly runs a year or more, which changes how you should think about it: an investigation is not an event to survive but a relationship to manage, and the organisation that ships organised, timely responses at every step accumulates credibility that shapes the outcome.

Customer audits run on commercial time instead: a questionnaire with a two-to-four-week expectation, a follow-up call on the thin answers, sometimes an evidence review or a right-to-audit clause exercised later. The asymmetry worth planning for is that customer audits recur — every large prospect, every renewal, every insurer — so the answer library and evidence pack you build for the first one is infrastructure, not overhead.

One preparation habit pays into both timelines: date everything. A risk analysis with a version history, training records with completion dates, policies with effective dates — the question in every audit is not only “do you do this?” but “were you doing it then?”, and dated artefacts are the only way to answer it. The organisations that find audits routine rather than existential all share the same underlying property: their evidence is generated continuously by the programme running, not assembled retrospectively because a letter arrived. That property is buildable, and it is cheaper to build than to fake.

Where SuperHIPAA fits

Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is this legal advice?

No. It is operational guidance from practitioners who build HIPAA programs. Regulatory interpretation for your specific situation should come from counsel.

Can we become HIPAA certified?

No. HHS operates no certification program and no private body can confer one. What exists is an independent third-party assessment, which is what customers and insurers actually accept.

How current is this page?

Last reviewed 2026-08-04. We review every guide quarterly and after any HHS rulemaking or significant enforcement action.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo