Why Healthcare Organizations Need a HIPAA GAP Analysis

After conducting numerous HIPAA gap analyses, we’ve seen what happens when necessary safeguards are missing or ignored. This post explains what a HIPAA…

Read More

Jim Hook, MPH

By Jim Hook, MPH | May 29, 2025

Five wooden blocks with letters on them that spell "HIPAA", with a space between the P and A representing a HIPAA Gap Analysis.

After conducting numerous HIPAA gap analyses, we’ve seen what happens when necessary safeguards are missing or ignored. This post explains what a HIPAA gap analysis involves, who should conduct it, and why it’s essential. For any organization handling PHI, a proactive approach can prevent costly mistakes.

What Is a HIPAA Gap Analysis and Why Does It Matter?

A gap analysis is usually defined as the process of an accurate and thorough assessment of a business entity to compare current performance to expected or desired performance. So for covered entities — health care provider organizations, health care insurance companies and healthcare claims clearinghouses — a HIPAA gap analysis would consist of an accurate and thorough assessment of how the Covered Entity is complying with the HIPAA Privacy and Security Rules.

For medical groups, hospitals, and other provider organizations who must be HIPAA compliant, a HIPAA gap analysis is an important tool to help determine the current performance of your organization in relation to the desired level of HIPAA compliance

What Are Some Issues Covered in a HIPAA Gap Analysis?

A HIPAA gap analysis helps by asking and answering several important questions, including:

  • Have I created and implemented HIPAA privacy policies and procedures that staff members are aware of and follow? Do my employees understand the parts of the HIPAA privacy and security rules that apply to their specific duties? 
  • Has my organization created and implemented the policies and technology for compliance with HIPAA Security Rules, including Technical SafeguardsAdministrative Safeguards and Physical Safeguards? Are these safeguards performing up to expectations? Is my emphasis on cybersecurity potential risks understood by staff members? 
  • If I am creating and maintaining electronic protected health information (ePHI), have I completed a HIPAA Risk Analysis? (Note: this is a specific type of analysis that focuses on risks to ePHI; we will address it in a separate post. It is also referred to as a HIPAA risk assessment.)
  • Have I identified every outside business or other entities with whom I am sharing ePHI, and have I executed an agreement with each of these business associates?
  • Do I know the process for responding to a potential breach and unauthorized disclosure of PHI/ePHI?

Of course, these issues are only the tip of a very large iceberg that the HIPAA Rules represent!

Who Should Perform Your HIPAA Gap Analysis?

In our experience, even capable internal teams can overlook critical gaps without repeated exposure to HIPAA audits. It might seem practical to rely on your staff, provided they’ve conducted multiple compliance evaluations and understand how to deliver an unbiased report. These reports, after all, will be used to close privacy and security gaps.

Relying on a reputable, third-party firm to perform your HIPAA gap analysis is a good course of action. A reputable consulting firm means the difference between some experience and expert level experience. With a HIPAA gap analysis, you want experts who have done this many times as well as experts who will notice hard-to-detect deficiencies that are easy to miss.

Preparing for a HIPAA Gap Analysis

After you have assigned a third-party auditor or assembled a team, it’s time to properly prepare and assemble materials within your organization, including:

  • Policies and procedures covering the requirements of the HIPAA Privacy and Security Rules, especially in relation to how PHI/ePHI is created, maintained and disclosed.
  • Copies of HIPAA and state laws/regulations kept handy for reference during the gap analysis.
  • Existing insurance policies for coverage of breaches in HIPAA privacy compliance.
  • Manuals, repair/update logs and inventory of IT systems and devices containing ePHI to evaluate how your current measures are protecting patient data.
  • Employee training records to make sure employees are receiving the best and latest information for HIPAA compliance. Copies of a sanction policy and results of investigations where employee conduct was an issue.
  • Inventory of Business associates and copies of individual or template BA agreement.
  • Contracts with Data Centers and/or data storage facilities where ePHI is maintained.
  • Copies of reports of investigations into unauthorized disclosure of PHI/ePHI.

Key Issues Addressed in a HIPAA Gap Analysis Report

The final report you receive should cover privacy and security issues discovered through the HIPAA gap analysis. Examples of issues you may encounter include:

  • HIPAA Risk assessment results.(Note: this type of assessment is required under the HIPAA Security Rule.)
  • Recommendations on changes/updates to policies and practices to reduce identified risks and improve risk management processes.
  • Outline of worker sanctions for policy and procedure going forward, including emergency procedures.
  • Clear procedures for instituting ongoing systems reviews.
  • Clarification of the roles of the HIPAA Security Officer and the HIPAA Privacy officer.
  • Recommendations on critical and routine updates to information security procedures and individual applications containing protected health information. 
  • How security incidents and other unauthorized disclosures of PHI/EPHI are/were documented and emergency response protocols in place.
  • Information on data backup procedures and recovery.

It’s important to note that data sharing is not limited to one department when running a gap analysis.

The final report will give you the necessary tools to manage or improve risks, such as (1) putting security measures in place to diminish risks and close gaps, (2) implementing immediate policies or taking fast disciplinary action against employees who are not in line with privacy/security regulations, and (3) incorporating review procedures to regularly evaluate information system activity.

Lessons Learned from Multiple HIPAA Gap Analyses

The Fox Group has perform literally dozens of HIPAA gap analyses. The gap analysis is often paired with developing a comprehensive HIPAA Privacy Manual to address all of the HIPAA Privacy Rule regulations, as well as a HIPAA Security Compliance Manual. Although some of our previous clients have had policy and procedure manuals, most of the time they only addressed a portion of all of the regulations that must be addressed by any health care provider Covered Entity that utilizes a electronic health record system.

A few of the more egregious things we have seen:

  • Employees sharing common user credentials to access electronic protected health information.
  • No internal controls for removing users from electronic systems in a timely manner after termination.
  • No inventory of devices utilized to access ePHI.
  • Software patches not installed, put through assurance testing and installed per implementation specifications.
  • No Business Associate agreements with entities receiving ePHI from a Covered Entity. 
  • No cyber insurance policy to protect against extreme financial costs after a large scale breach of PHI.
  • No policies (or inadequately enforced policies) on employee sanctions after unauthorized access to ePHI.

Compliance by healthcare providers with HIPAA regulations is an expectation of literally everyone, from patients to licensing/regulatory bodies to community members in general. A HIPAA gap analysis is a good place to start if you are at all worried about how your organization would to fare if it were subject to an audit by the Office for Civil Rights (OCR) of the Health and Human Services Department (HHS). Those are the folks who come to investigate if/when they get reports of unauthorized disclosures large and small. They are also the people who decide how big your fine will be, and if you belong on the “Wall of Shame“! Hint: don’t get top billing on the Wall of Shame!


Summary of Key Areas to Review in a HIPAA Gap Analysis

Below is a summary you can refer to as a high-level checklist when evaluating how well your organization is addressing HIPAA’s privacy and security requirements. Or use it as a high-level guide to what should be included if outsourced to a qualified consulting firm. They reflect what we’ve found to be among the most critical items.

Section 1: Organizational Accountability

Focus Area

What to Look For or Ask

Rule

Privacy & Security Oversight

Are Privacy and Security Officers assigned and empowered?

Privacy / Security

Risk Analysis & Governance

Are risk and gap analyses conducted regularly and acted upon?

Security

Policies, Training & Notice of Privacy Practices

Do policies address all relevant portions of the HIPPA regulations; is staff trained, and NPPs distributed?

Privacy / Security

Section 2: Protecting PHI Across Environments

Focus Area

What to Look For or Ask

Rule

Facility & Device Controls

Are physical access points and ePHI devices inventoried and secured?

Security

Access Controls & Logins

Are credentials unique, deactivation timely, and role-based access enforced?

Security

System Security Measures

Are encryption, audit logs, and patches properly implemented and tested?

Security

Backup and Disaster Recovery

Are daily backups completed reliably; are disaster procedures in place and tested?

Security

Section 3: Respecting Patients and Managing Risk

Focus Area

What to Look For or Ask

Rule

Uses and Disclosures

Are PHI uses/disclosures tracked, minimal, and patient authorizations documented?

Privacy

Patient Rights

Can patients access, request amendments or request restrictions on disclosures of their PHI?

Privacy

Business Associate Oversight

Are BAAs in place, and do vendors meet HIPAA expectations?

Privacy / Security

Incident Response & Insurance

Are breaches logged and managed, and is insurance in place for regulatory and recovery costs?

Security