What is HIPAA Compliance? What Auditors Know That the Checklists Don’t Tell You

By Rob Pierce Published on July 22, 2026
In this Article
An auditor's guide to HIPAA compliance

When considering HIPAA compliance, it still feels a bit like the Wild West out there right now. As an auditor, I frequently review the landscape of healthcare data security. I continue to see a significant amount of confusion among organizations of all sizes. The Office of Civil Rights (OCR) enforces fines and sanctions for HIPAA violations, but this enforcement is mostly on a reactionary basis. You can review the HIPAA cases currently under investigation to get a sense of the incidents and breaches that lead to fines. At the time of this article, there are many hacking and IT incidents resulting in breaches of health data.

If proactive enforcement does not come from the OCR, where does it come from? It has to come from healthcare organizations requiring more assurance than they received historically. Alternatively, it comes from a large enough breach, fine, or incident to raise public awareness of the issue.

Over the past few years, our firm has seen a massive increase in companies providing healthcare IT services being required to provide greater assurance to business partners than has historically been provided. In the technology space, taking an organization’s word that they meet regulatory standards is no longer enough. This brings us back to the wild west of HIPAA compliance.

The Truth About HIPAA Certification

Although there is no such thing as a HIPAA certification, a quick Google search confirms that many companies are offering them. It is unfortunate because after paying a significant amount for this alleged badge of honor, companies discover that marketing themselves as certified does not provide as much assurance as they hoped. Smart business partners know a true certification simply does not exist.

So how can you demonstrate your standing to skeptical business partners? Here are the primary paths organizations take:

  • Identify relevant requirements, perform a self-assessment, remediate any gaps, and attest to business partners that you meet the standards. This is the least expensive route. It also carries the least amount of external validation.
  • Engage a third party to assist with performing a readiness assessment and remediate gaps identified by the third party. Then, attest to business partners that you are compliant.
  • Engage a third party to perform a readiness assessment, remediate any gaps, and obtain a third-party attestation. The AICPA offers a method for CPA firms to attest to a client’s compliance with rules and regulations. Other companies offer similar services, but they may not have equivalent workpaper standards or oversight as a CPA firm. Buyer beware. Verify that the firm you choose is reputable and that the auditor has significant experience.
  • Obtain a HITRUST assessment. HITRUST assessments and certifications are gaining traction because large healthcare organizations see HITRUST as a way to verify that business associates comply with HIPAA. A HITRUST assessment is more involved than a typical audit because it may include other requirements from NIST or ISO. A HITRUST assessment is unique to each organization because scoping questions drive the exact requirements.

 

Three rules of HIPAA compliance

HIPAA 101: The Three Rules You Need to Know

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) required the Secretary of the U.S. Department of Health and Human Services (HHS) to develop regulations protecting the privacy and security of protected health information. In response, HHS created the Privacy and Security rules. The Privacy Rule established certain rights that all US citizens have regarding their health-related information. Below is a simple summary table to help keep the main rules straight.

Rule What It Covers Who It Applies To
Privacy Rule Protects US citizens’ personally identifiable health information from unauthorized disclosure or use. Covered entities and business associates of covered entities.
Security Rule Addresses the technical and non-technical safeguards organizations must put in place to secure electronic protected health information (ePHI). Covered entities and business associates.
Breach Notification Rule Outlines the requirements for reporting unauthorized disclosures or breaches of unsecured PHI. Covered entities and business associates.

If you need a deeper dive into specific implementation guidelines, my colleague Danielle recently updated our guide on HIPAA Security Rule Requirements and Implementation Specifications.

What Does HIPAA Compliance Mean?

Being compliant depends on the type of entity or healthcare organization you are. Covered entities have additional requirements. The American Recovery and Reinvestment Act of 2009 (ARRA) expanded requirements to include business associates or service organizations for covered entities. To hold your organization out as compliant, you must comply with any applicable requirements for your specific organization type.

2026 HIPAA Update: What is Changing?

A frequent question we hear from prospective clients is, “Is HIPAA changing in 2026?” The short answer is that major changes have been proposed, but they are not final yet. On January 6, 2025, a Notice of Proposed Rulemaking (NPRM) was published.

This NPRM proposes some significant shifts in how organizations approach data protection. Key points to address include eliminating the addressable versus required distinction entirely. It also proposes mandating multi-factor authentication (MFA), requiring encryption at rest and in transit, and imposing a strict 72-hour ePHI restoration requirement.

As of this publication, the final rule has not been issued. While you might see competitors writing as if these changes are already finalized, they are strictly proposed at this stage. However, it is an excellent time to start evaluating your systems against these proposed considerations so you are not caught unprepared when the finalized updates eventually drop.

 

HIPAA compliance in action

HIPAA Audit Observations: What We Actually See in the Field

What does the OCR actually cite in enforcement investigations? HIPAA risk analysis failures are the most-cited finding by a wide margin.

In my own first-person experience working through various assessments, risk analysis is where I see clients get it wrong most frequently. Companies often mistake a basic vulnerability scan for a comprehensive risk analysis. A true risk analysis evaluates the likelihood and impact of potential risks to all ePHI across your entire environment. When we sit down with clients, we frequently discover undocumented shadow IT or legacy systems containing ePHI that the security team did not even know existed. Taking the time to properly map your data flow and assess risks accurately is one of the most critical steps you can take. If your risk assessment does not explicitly evaluate the unique threats to your ePHI, you are leaving the door wide open for regulatory scrutiny.

The Cost of Non-Compliance: Penalty Tiers

The OCR enforces financial penalties through a tiered system based on the level of culpability. These figures adjust annually for inflation to reflect the current economic landscape. The table below demonstrates what the 2026 penalty tiers look like based on recent adjustments.

Tier Violation Type Per-Violation Cap Annual Cap
Tier 1 No Knowledge $73,011 $2,190,294
Tier 2 Reasonable Cause $73,011 $2,190,294
Tier 3 Willful Neglect (Corrected within 30 days) $73,011 $2,190,294
Tier 4 Willful Neglect (Not Corrected) $2,190,294 $2,190,294

Note: OCR has exercised enforcement discretion to lower annual caps for lower tiers in the past, but the published statutory maximum caps shown above represent the ultimate potential exposure.

 

HIPAA compliance FAQs

Frequently Asked Questions About HIPAA Compliance

Have more questions about HIPAA compliance? Here are quick answers to what we hear most often from clients and prospects.

What Is the Full Form of HIPAA Compliance?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996.

What Does Being HIPAA Compliant Mean?

It means adhering to the national standards set forth to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge.

Who Needs HIPAA Compliance?

It protects US citizens’ health records from unauthorized use and disclosure and applies to covered entities and business associates of covered entities.

Who Enforces HIPAA Compliance?

The U.S. Department of Health and Human Services (HHS) oversees it. Within HHS, the Office for Civil Rights (OCR) has responsibility for enforcing the Privacy and Security Rules with voluntary compliance activities and civil money penalties.

Does HIPAA Apply to Everyone?

No. It specifically applies to covered entities (like healthcare providers, health plans, and healthcare clearinghouses) and their business associates (vendors that handle ePHI on their behalf).

What Are the Top 5 HIPAA Violations?

While the specific ranking fluctuates, common violations include failing to perform an organization-wide risk analysis, unauthorized access or disclosure of PHI, failure to manage business associate agreements, failure to implement access controls, and improper disposal of PHI.

What Are Common HIPAA Compliance Mistakes?

Beyond the massive risk analysis failures mentioned earlier, another common mistake is relying entirely on a software vendor claiming their tool is fully compliant out of the box. Software can support your program, but it cannot automatically make your business operations compliant.

How Do I Confirm HIPAA Compliance?

You can verify it internally or by using a third party. Third parties are used to provide greater assurance to business partners that requirements are being met. Consistent execution of controls is the real key to success.

The Bottom Line on HIPAA Compliance

To summarize, there are a variety of ways to demonstrate your adherence to these rules. The correct answer is to determine the level of assurance your business partners require. Does a contract depend on having a third-party report? Or perhaps the contract requires a HITRUST certification.

Our firm provides HIPAA attestation reports (AT-C 315) that our clients use to satisfy business partner requirements. We also perform HITRUST validated assessments. If you have questions about demonstrating your security posture or want to discuss assessment options, feel free to reach out. We enjoy helping to provide peace of mind to our clients, knowing they are thoroughly prepared.

About The Author

Rob Pierce
Rob Pierce

Rob started with Linford & Co., LLP in 2011 and helps lead the HITRUST and ISO practices as well as performs SOC audits, NIST 800-171, and HIPAA assessments. He has spoken at Data Center World on compliance-related topics and has completed over 800 SOC examinations. He started his career as an IT auditor in 2003 with PwC in the Systems and Process Assurance group, and has worked in a variety of industries in internal audit as well as for the City and County of Denver.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**