HIPAA Technical Security

HIPAA Device and IT Audits

Every device that touches ePHI needs a record. It also needs encryption and the right settings. We review your devices, systems, and technical controls against 45 CFR §164.312.

What Is a HIPAA Device and IT Audit?

What is a HIPAA Device and IT Audit? A systematic evaluation of all systems that store, process, or transmit ePHI, measured against the five technical safeguard standards in 45 CFR Section 164.312.

A device and IT audit reviews each system that stores, uses, or sends electronic protected health information. It checks your controls against the five HIPAA technical safeguard standards.

Five HIPAA Technical Safeguard Standards

  1. Access Control - 45 CFR §164.312(a). Implement technical policies and procedures for systems that maintain ePHI, allowing access only to authorized persons and software programs.
  2. Audit Controls - 45 CFR §164.312(b). Implement hardware, software, and procedural mechanisms to record and examine activity in systems that contain or use ePHI.
  3. Integrity - 45 CFR §164.312(c). Implement policies and procedures to protect ePHI from improper alteration or destruction.
  4. Person or Entity Authentication - 45 CFR §164.312(d). Implement procedures to verify that a person or entity seeking access to ePHI is who they claim to be.
  5. Transmission Security - 45 CFR §164.312(e). Implement technical security measures to guard against unauthorized access to ePHI being transmitted over an electronic network.

The majority of breaches reported to the HHS Breach Portal involve electronic records. Hacking and IT incidents account for the largest share of reported breaches by both volume and individuals affected. A device and IT audit identifies these vulnerabilities before they become reportable incidents.

Who Needs a HIPAA IT Audit?

A device and IT audit applies to any covered entity or business associate that handles ePHI. If your organization matches any of the following, a structured IT audit is indicated:

  • 💻
    Organizations without a formal HIPAA device inventory
  • 🔍
    Practices that use personal devices, cloud services, and office systems
  • 📈
    Growing teams that add devices or software without a clear approval process
  • 🔁
    Groups that failed, or almost failed, technical safeguard reviews
  • 🔗
    Business associates that handle ePHI across several systems

Device & IT Compliance Benchmarks

Typical findings from organizations before a structured IT audit. Your actual results will reflect your specific environment.

IT Audit Gap Distribution

Where most organizations have incomplete technical controls

5
GAP
CATEGORIES

    Technical Control Maturity

    Average maturity score by control area (0–100)

    Technical Safeguard Compliance: Before vs. After

    Typical improvement after structured IT audit and fixes

    0%
    Before
    0%
    After

    Typical 90-day post-audit improvement

    Five-Step IT Audit Process

    Each step produces a documented deliverable that maps to specific HIPAA technical safeguard requirements under 45 CFR §164.312.

    1

    Device Inventory

    Catalog each device that stores accesses sends or touches ePHI. This includes workstations, laptops, phones, servers, and network equipment. This step supports the device and media controls standard under 45 CFR §164.310(d).

    Deliverable: Complete device inventory with encryption status, OS version, and ePHI exposure level for each device.

    Need the device catalog handled on its own? See our IoT device inventory service.

    2

    Encryption and Transmission Security Assessment

    Check encryption on stored data (data at rest) and transmitted data (data in transit). Review every device and channel that handles ePHI against 45 CFR §164.312(e) transmission security requirements.

    Deliverable: Encryption status report showing each device's at-rest and in-transit encryption state, with fix steps for unencrypted endpoints.

    3

    Access Control Review

    Review how users sign in. Check role-based access, automatic logoff, emergency access procedures, and unique user identification against 45 CFR §164.312(a).

    Deliverable: Access control audit documenting user accounts, MFA status, role assignments, and any stale or former employee accounts still active.

    4

    Audit Log Analysis

    Check log settings, log retention periods, and whether your team reviews audit logs on a regular schedule. Audit controls under 45 CFR §164.312(b) require mechanisms to record and examine activity in systems that contain ePHI.

    Deliverable: Audit log assessment showing which systems have logging enabled, retention periods, and a recommended review schedule.

    5

    Findings Report and Remediation Plan

    Provide a clear report with device findings, risk ratings, and technical fix steps. Each gap is mapped to the applicable regulatory standard, including §164.310(d), §164.312(a), §164.312(b), §164.312(c), and §164.312(e).

    Deliverable: Written findings report with risk-ranked corrective actions, regulatory citations, owner assignments, and target dates.

    IT Audit Case Study

    Scenario

    A 15-person medical practice had grown from 5 to 15 staff in two years. New laptops, tablets, and cloud services were added as needed with no formal tracking. The practice had no device inventory and was unsure which devices had encryption enabled.

    Key Gaps Found

    Four laptops had no disk encryption. Three cloud services lacked MFA. Audit logs were enabled but never reviewed. Two former employee accounts were still active. Patient data was being transmitted over unencrypted email.

    Result

    Complete device inventory established with 23 devices cataloged. All devices encrypted within 30 days. MFA enabled on all cloud services. Former employee access revoked. Encrypted email solution implemented. Quarterly audit log reviews scheduled.

    Implementation Timeline

    Most IT audits take two to three weeks. Larger teams or groups with several cloud platforms may need more time for a full inventory.

    Phase 1
    Week 1
    • Device discovery and inventory
    • Network scan
    • Cloud service list
    Phase 2
    Week 2
    • Encryption and access control testing
    • Authentication review
    • Audit log settings check
    Phase 3
    Week 3
    • Findings summary
    • Risk ratings
    • Technical fix recommendations
    • Draft report review
    Phase 4
    Week 4
    • Final report delivery
    • Fix priority list
    • Quick-win implementation support

    Most IT audits take two to three weeks. Larger teams or groups with several cloud platforms may need more time for a full inventory.

    IT Audit Patterns by Healthcare Specialty

    Audit findings differ by specialty. We tailor the review to match how your practice uses technology. These six practice types are the most common settings we audit. Each one has its own device, software, and access control risks.

    🏥

    Medical Practices

    EHR system access, multi-device workflows, lab system integrations, and referral platform security.

    🧠

    Behavioral Health

    Telehealth platform security, session recording controls, and heightened patient data sensitivity.

    🦷

    Dental Practices

    Imaging system encryption, practice management software access, and operatory workstation security.

    💊

    Pharmacies

    POS system security, medication management software, and controlled substance tracking system access.

    🔗

    Business Associates

    Multi-client data segregation, cloud infrastructure security, and remote access controls.

    📱

    Telehealth Providers

    Video platform encryption, mobile device management, and home network security verification.

    What Your IT Audit Includes

    Every engagement gives you a written record of your technical safeguard posture. These five deliverables create a clear evidence package. You can use it for internal fixes and during a HIPAA compliance review.

    Complete Device Inventory

    Each device is listed with its encryption status, OS version, access controls, and ePHI exposure level.

    Technical Safeguard Assessment

    Review of access controls, audit logs, integrity controls, authentication, and transmission security.

    Encryption Status Report

    Check encryption device by device. List fix steps for any unencrypted endpoint.

    Access Control Audit

    Review user accounts, MFA status, role-based access, and former employee access.

    Remediation Action Plan

    Rank technical fixes by risk. Include setup guidance and target dates.

    Why This Approach Delivers Better Outcomes

    Technology changes faster than policies. New devices, cloud services, and integrations get added between annual reviews, creating gaps in your technical safeguard documentation.

    An IT audit identifies specific control deficiencies against the five technical safeguard standards in 45 CFR §164.312. It produces a current, documented view of your ePHI environment.

    Many findings have same-day remediation paths. Enabling encryption on a laptop, turning on MFA for a cloud service, or deactivating a former employee's account are common corrective actions that close gaps immediately.

    Under 45 CFR §164.306(a), covered entities must conduct periodic technical evaluations. Organizations that audit their technology annually identify and remediate gaps before they result in reportable breaches under §164.404.

    Common Pitfalls We Help You Avoid

    • ⚠️
      Incomplete inventory: You cannot secure devices you do not know about. Shadow IT is the leading technical audit gap.
    • ⚠️
      Encryption assumptions: Many organizations assume encryption is enabled when it is not, especially on older devices
    • ⚠️
      Audit log neglect: Having logs enabled but never reviewing them does not satisfy the audit control requirement
    • ⚠️
      Stale access: Former employees and role changes create access rights that persist long after they should have been revoked
    • ⚠️
      Personal device blindspot: BYOD policies without technical controls create unmanaged ePHI exposure on personal phones and tablets

    Tracking Progress After Your IT Audit

    Track a small set of technical metrics each month so findings turn into results.

    Measure the percent of devices inventoried, percent of devices encrypted, MFA adoption across cloud services, and stale accounts removed.

    % Devices inventoried
    % Encrypted
    % MFA enabled
    Stale accounts removed

    Keep a leadership view that shows the trend, not just one point in time. Technical controls drift quickly as new devices and services are added.

    Technical controls drift quickly. New devices get added, employees change roles, and software updates change settings. Annual IT audits keep your inventory accurate and your controls current.

    Deep-Dive Resources

    Use these guides to align IT audit findings to realistic implementation plans:

    Frequently Asked Questions

    Include every device that stores, accesses, or sends ePHI. This includes desktops, laptops, tablets, phones, servers, network equipment, storage devices, cloud services, and apps that handle patient data. The device and media controls standard at 45 CFR §164.310(d) requires policies for hardware and electronic media that contain ePHI. Your inventory should be current and complete, not estimated. After a gap analysis identifies which systems are in scope, the device inventory becomes the base for your audit.
    Encryption is an addressable implementation specification under the Security Rule. If you do not encrypt, you must document why another option is reasonable and appropriate. In practice, most reviewers expect encryption for stored data and sent data. Under 45 CFR §164.312(a)(2)(iv), encryption and decryption of ePHI is an addressable specification within the access control standard. Under 45 CFR §164.312(e)(2)(ii), encryption of ePHI in transit is also addressable. If you do not use encryption, your remediation plan must document the alternative and the reason. You must keep that documentation for at least six years.
    At least once a year. You should also review your systems after major changes, such as new software, cloud migrations, security incidents, or major updates. The HIPAA Security Rule does not set one fixed audit schedule. But 45 CFR §164.312(b) requires controls that record and examine activity in systems with ePHI. HHS guidance points to regular, documented review, not one-time setup. Quarterly reviews of access rights and audit logs are standard practice. If audit findings create open gaps, use a structured remediation plan with clear timelines.
    BYOD environments need clear rules and technical controls. When possible, use mobile device management. Confirm that personal devices have encryption, authentication, and remote wipe before they access ePHI. Under 45 CFR §164.312(a), access controls apply to any system that stores or uses ePHI. This includes personal phones and tablets used for work. The access control standard requires unique user identification, automatic logoff, and encryption where feasible. Physical safeguards under §164.310 also apply to mobile devices. A mobile device management (MDM) solution is the most practical way to enforce these rules in a BYOD environment.
    Yes. Any cloud service that stores or processes ePHI must be listed. It should have a BAA and meet HIPAA technical safeguard rules for access control, encryption, and audit logging. Cloud service providers that handle ePHI for a covered entity are business associates under HIPAA. A signed Business Associate Agreement is required before ePHI is shared. The access controls (§164.312(a)), audit controls (§164.312(b)), and transmission security (§164.312(e)) standards all apply to cloud-hosted ePHI. During an IT audit, each cloud service is reviewed for MFA, data residency, encryption, and audit logging.

    Ready to Audit Your Devices and Systems?

    We will inventory your devices, test your technical controls, and give you a clear report. You will know where you stand and what needs to change.

    Book Your Free 30 Minute HIPAA Compliance Review

    Questions About Device and IT Audits?