Award-winning MFT Software - Diplomat MFT
Award-winning MFT Software - Diplomat MFT

Conducting an Internal HIPAA Audit? This Checklist will Help.

by | Nov 6, 2025

According to the Ponemon Institute/IBM 2025 Cost of a Data Breach Report, the average financial hit for a data breach affecting healthcare organizations is now $7.42 million. Tack on an extra $173,692 when the breach is found to be in violation of applicable regulations like the Health Insurance Portability and Accountability Act (HIPAA). That’s a hard pill to swallow. And it’s a good reason to conduct an internal HIPAA audit to assess compliance practices and gaps–especially with expected changes to compliance mandates coming next year.

One big challenge for healthcare is that, perhaps more than any other industry, it relies on the movement of a lot of data to a lot of different internal and external organizations. Any hiccup affecting any protected information at any time might compromise a patient’s protected health information (PHI) and electronic protected health information (ePHI), their personally identifiable information (PII), or other sensitive data.

Basic HIPAA Compliance Guidelines

HIPAA sets minimum standards for data management best practices to minimize the risk of an incident, but those standards have fallen behind the technology curve and threat environment that conspire to expose data to prying eyes. Currently the U.S. Department of Health and Human Services sets the following guidelines for technical controls to safeguard PHI:

  • Access Control. A regulated entity must implement technical policies and procedures for its electronic information systems that maintain ePHI to allow only authorized persons to access ePHI.
  • Audit Controls. A regulated entity must implement hardware, software, and/or procedural mechanisms to record and examine activity in information systems that contain or use ePHI.
  • Policies and Procedures. A regulated entity must implement policies and procedures to ensure that ePHI is not improperly altered or destroyed. Electronic measures must be put in place to confirm that ePHI has not been improperly altered or destroyed.

  •  

    Authentication. A regulated entity must implement procedures to verify that a person seeking access to ePHI is who they say they are.

  • Transmission Security. A regulated entity must implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic network.

These are all standard minimum expectations for a cybersecurity program. Tools for enforcing multi-factor authentication and access control mechanisms based on the

principle of least-privilege are commonplace, as are the means to record and archive the activities users and processes involved in data management. Written policies outlining an organization’s expectations for keeping data safe, and training to ensure users are aware of those policies are standard fare. And any competent IT manager understands that transmission security requires both file and transport encryption both to protect the data and its veracity.

Going Beyond the Basics for HIPAA Compliance

And yet, data breaches in healthcare continue apace, even for organizations that follow HIPAA’s minimum standards. Why? In part, the issue is staring us in the mirror. Human beings make errors, and there is a lot of dirty money to be made capitalizing on those mistakes, so cybercriminals spend a lot of time on industries that are resource constrained and where IT and information security staff are beleaguered.

The risks of non-compliance are revealed in our recent survey of healthcare IT leaders, Healthcare Data Transfer in 2025: The File Transfer Gap and the Race to Close It, where we learned that only 9% of organizations have fully automated file transfer processes. That puts a lot of unnecessary pressure on front line administrative staff to send sensitive electronic files to other departments or external partners and other third-parties in a manner consistent with HIPAA. That means encrypting files before transmission, only sending files over channels that are protected by SFTP, and affirming the recipient is correct. If it’s a bad day in the office and that staffer sends an unencrypted file in the clear, or to the wrong location, it may well result in a breach and trigger an HHS audit.

To close this gap, there is an update of HIPAA security rules in progress that is expected to strengthen security by imposing a set of new requirements. These are likely to include:HIPAA Audit

  • Maintain a written inventory of technology assets and a current network map
  • Conduct annual risk analyses with more detailed descriptions of results
  • Adopt more robust technical controls to like
    • IT configuration change management
    • Network segmentation.
    • Patch management
    • Multi-factor authentication
    • Stricter encryption, including support for NIST-standard quantum-resistant cryptography
  • Uphold stringent incident response policies and procedures
  • Deploy anti-malware protection, remove extraneous software, and disable ports in accordance with the risk analysis.
  • Conduct vulnerability scanning at least every six months and penetration testing at least once every 12 months.
  • Deploy technical controls to create and maintain backups of relevant IT systems and to review and test the effectiveness of such controls once every six months.

Questions to Ask Yourself about HIPAA Compliant File Transfers

To prepare your organization’s file transfer processes for these changes, we suggest a thorough review of your current tools and policies, guided by this simple checklist:

  • Does your current file transfer program rely on staff to conduct manual file transfer?
  • Are your current file transfer workflows fully automated?
  • Do you have a complete map of your digital supply chain?
  • If you use a managed file transfer solution, does it include the following features:
    • Automated PGP encryption management and SFTP support
    • Unlimited concurrent job scheduling and automation
    • Automated process data capture and one-click audit reporting
    • Threat intelligence for automated IP scanning and blocking
    • IP whitelisting and destination authentication
    • Secure by design architecture
    • Multi-factor authentication (MFA)
    • Administration with least-privilege access
    • Dry-run workflow testing and affirmation
    • Post-quantum computing cryptographic support

Coviant Software can help with a no-obligation review of your current file transfer technologies and practices. We can demonstrate how our Diplomat MFT managed file transfer solution can address your organization’s file transfer needs, and we can assure you a no-hassle transition to Diplomat MFT if you determine that your current solution is inadequate.  Contact us today for more information.