Practice administrator reviewing HIPAA compliance documents at a modern medical office workstation

How Often Should You Audit HIPAA Compliance? A 2026 Guide

August 19, 2026

A South Florida medical practice got its cyber insurance renewal notice in March. The broker's checklist had one line that stopped everything: "Provide documentation of your most recent HIPAA risk assessment." The office manager spent two hours searching before finding a PDF dated 2019. That PDF became the submitted answer. Six months later, the practice received a corrective action notice from OCR.

This is not a rare story. The gap between "we did a risk assessment once" and "we have an active compliance program" is where most enforcement actions live. So: how often should you audit HIPAA compliance? At least once a year, with additional checkpoints after any meaningful change in your operations, staff, or technology. Here's what that looks like in practice.

Key Takeaways

  • HIPAA requires "periodic" risk assessments but doesn't define a specific frequency. Most compliance experts recommend at least annually.
  • Staff changes, new software, security incidents, and operational changes require an immediate reassessment outside the annual cycle.
  • A HIPAA compliance audit covers more than a risk analysis. It includes policies, access controls, audit logs, and training records.
  • Business Associate Agreements need to be reviewed every year, not just when a vendor relationship starts.
  • Small practices can run a structured annual audit in-house with the right checklist, or use managed IT support for continuous compliance monitoring.

What Does a HIPAA Compliance Audit Cover?

The Risk Analysis Is Not the Whole Picture

The HIPAA Security Rule requires covered entities to conduct a thorough assessment of risks and vulnerabilities to electronic protected health information (ePHI). That's the risk analysis, required under 45 CFR 164.308(a)(1). But the Security Rule also requires you to implement controls to reduce those risks and document that you've done so. The Privacy Rule adds policies around use and disclosure of patient information, patient rights, and separate training requirements.

The Four Areas Every Audit Must Address

  • Risk Analysis and Risk Management: Identifying threats to ePHI and documenting the controls in place to mitigate them.
  • Policies and Procedures: Verifying that written policies reflect current operations and have been updated for recent regulatory changes.
  • Access Controls and Audit Logs: Reviewing who has access to ePHI, whether that access is appropriate, and whether systems are logging access activity as required.
  • Training Records: Confirming that all staff have received HIPAA training and that completion is documented, including for new hires.

Missing any one of these areas means your audit is incomplete. OCR investigations consistently find practices with solid risk analyses that still face enforcement actions because their policies were outdated, training records were missing, or access logs weren't being reviewed.

Actionable tip: Before your next audit, pull your most recent HIPAA policies and check the "last revised" date on each one. Any policy older than two years should be flagged for immediate update before the audit begins.

How Often Should You Audit HIPAA Compliance?

What "Periodic" Means in Practice

HIPAA requires "periodic" evaluations of security controls but doesn't define periodic as annually. In practice, the industry has converged on annual as the baseline because healthcare operations change every year. Staff turn over. New software gets added. Threats evolve. A compliance program with an audit cycle longer than 12 months is almost certainly operating with an outdated risk assessment that doesn't reflect the current environment.

Our compliance management services help practices establish a structured audit cycle that fits their size and risk profile, without turning it into a months-long project each time.

Event-Driven Reassessments

Certain events require an immediate reassessment regardless of when the last annual audit was completed:

  • Security incidents or suspected breaches: Any unauthorized access to ePHI, even without a breach notification, requires a review of the controls that failed.
  • New technology or software: Adding an EHR module, switching billing platforms, or adopting patient communication tools changes your risk profile and your BAA obligations.
  • Significant staff changes: New or departing employees with ePHI access require review of access controls and training records.
  • Operational changes: New locations, practice mergers, or telehealth additions change the scope of your compliance program.
  • Vendor changes: Any change to a business associate relationship requires reviewing your BAA inventory to confirm current agreements are in place.

I sat with a practice administrator last year who had just switched EHR platforms. She'd done a thorough annual audit four months earlier and assumed she was covered. When we reviewed the new system's access controls together, we found three staff members who had retained admin-level permissions from the data migration that nobody had noticed. That's exactly the kind of gap event-driven reassessments are designed to catch.

Actionable tip: Keep a running log of operational changes throughout the year, including new vendors, new software, and staff departures with ePHI access. Review this log at the start of each annual audit to identify any event-driven gaps that need to be addressed first.

If you're not sure your current compliance posture reflects recent changes in your practice, our team offers a free workflow and security assessment that covers HIPAA compliance touchpoints specific to your practice type and size.

What Most Small Practices Get Wrong

Treating the Risk Analysis as a One-Time Event

The most common mistake is completing a risk analysis once, usually after a near-miss or system change, and treating it as permanent documentation. A risk analysis captures your environment at a specific point in time. OCR's guidance is explicit that the risk analysis is an ongoing process. If your environment has changed, the analysis is no longer accurate, and submitting a five-year-old document as current compliance evidence is a problem.

The BAA Review Most Practices Skip

Business Associate Agreements are often executed correctly when a vendor relationship starts and then never revisited. Many BAAs from several years ago don't meet current HIPAA requirements following Omnibus Rule updates. Practices also frequently have active vendor relationships without any BAA in place, because the relationship grew informally over time. Your annual audit should include a complete inventory of every vendor that touches ePHI, and verification that a current, compliant BAA exists for each one.

For a deeper look at where BAA gaps typically appear, our post on vendor BAA gaps and the HIPAA risk most practices miss covers the most common scenarios.

Ignoring the Audit Log Review

The HIPAA Security Rule requires mechanisms that record and examine activity in systems containing ePHI. Most practices have systems that generate these logs. Very few actually review them. Audit log review doesn't have to be a daily task, but it needs to happen regularly, and it needs to be documented. A quarterly review of access logs combined with automated alerting for anomalous activity is a reasonable approach for most small practices.

Actionable tip: Ask your EHR vendor or IT provider to pull an access log report for the last 90 days. Look for access outside normal business hours, access by former employees, or large exports of patient data. Document what you found and any follow-up actions taken, even if the answer is "nothing unusual."

How to Run an Annual HIPAA Compliance Audit

Here's a practical four-step structure that a small practice can run without a dedicated compliance team. Each step should be documented, because documentation is what proves compliance if OCR comes calling.

Step 1: Risk Analysis

Identify every location where ePHI lives: your EHR, billing system, email platform, patient portal, third-party integrations, and physical devices. For each system, document the potential threats, the likelihood and impact of those threats, and the controls you have in place. Assign a risk rating and document your reasoning. A clear spreadsheet is defensible. OCR looks for evidence that you took the assessment seriously and acted on the findings.

Step 2: Policy and Procedure Review

Pull every HIPAA-related policy your practice has and verify it reflects how you actually operate. Common policies that get outdated: acceptable use of devices, workforce sanctions for violations, incident response procedures, and media disposal. Your cybersecurity posture and your HIPAA policies need to be aligned. If policy says all devices are encrypted but you can't verify it's enforced, that's a gap. Update any policy that doesn't match current practice and document the revision date.

Step 3: Access Controls and Audit Logs

Review who has access to ePHI systems and whether access levels match current roles. Minimum necessary access is a core HIPAA principle. Run a user access report from your EHR and other systems, and flag anyone with access that doesn't match their current job. Our managed IT services include automated access control monitoring so this review is continuous rather than annual.

Step 4: Training Records

Confirm that every current staff member has completed HIPAA training and that completion is documented. Check that your training content is current with recent regulatory guidance, not a general overview from several years ago. Verify that new hires were trained before accessing patient data. Our healthcare IT services include managed HIPAA training that tracks completion and updates content as regulations change.

Frequently Asked Questions

Does HIPAA require annual compliance audits?

HIPAA requires "periodic" risk assessments and evaluations of security controls, but doesn't specify annual as a mandatory frequency. In practice, annual is the industry standard because healthcare environments change quickly enough that longer cycles produce outdated risk assessments. Most HIPAA legal advisors treat annual as a baseline minimum.

What triggers a HIPAA risk assessment outside the annual cycle?

Any significant change in your environment: new technology, vendor changes, staff turnover in roles with ePHI access, new locations, added services like telehealth, or any security incident or suspected breach. The Security Rule's risk management provisions make these reassessments required, not optional.

What's the difference between a HIPAA risk analysis and a HIPAA audit?

A risk analysis identifies threats and vulnerabilities to ePHI and documents your controls. It's one component of a full HIPAA compliance audit, which also covers policies and procedures, access controls, audit log reviews, and training records. Completing only the risk analysis leaves significant compliance gaps.

How much does a HIPAA compliance audit cost?

Small practices can run a structured annual audit internally using templates and checklists at minimal direct cost, though it requires significant staff time. Managed IT providers typically include HIPAA compliance support as part of their service package, which is often more cost-effective than hiring a standalone compliance consultant annually.

Can a small practice conduct a HIPAA audit without outside help?

Yes, with the right structure. The four-step framework above is manageable for a practice with a dedicated person who has time to run it. The challenge is that most small practices don't have that dedicated time, which is why compliance management services are often a better fit. Our guide on HIPAA audit readiness and what small practices get wrong covers the most common gaps in more detail.

Ready to Build a Compliance Program That Holds Up?

An annual HIPAA compliance audit isn't a checkbox exercise. It's a structured review of everything that could put your practice and your patients at risk, and it needs to reflect your current environment. If you've had operational changes since your last audit, or aren't sure your current program is current and documented, the right first step is an honest look at where you stand.

Start with a free security and compliance assessment from Gradient Data Solutions. We work with healthcare practices in South Florida to build compliance programs that are current, documented, and defensible when it matters.

healthcarehipaacomplianceauditcybersecurity
Back to Blog

Get Your Questions Answered

We're happy to help. Call us at (786) 386-1092 or send us a message.