HIPAA Gap Analysis: A Step-by-Step Guide for Practices
Your cyber liability renewal packet arrives with one question that quietly decides your premium and your coverage limits: Has the applicant completed a documented security risk analysis and remediation plan within the past 12 months? If you check yes without a file to back it up, you have created a problem larger than the one you were trying to solve. A HIPAA gap analysis is the exercise that lets you answer honestly — a standard-by-standard comparison of what the Security Rule and Privacy Rule require against what your practice actually does on a Tuesday afternoon.
This article is the operational version: who does the work, what they look at, how long it takes, and what the finished evidence file contains when an investigator, an auditor, or an underwriter asks to see it.
What a HIPAA Gap Analysis Is, and How It Differs From a Risk Analysis
A HIPAA gap analysis is a documented comparison of your practice's current safeguards against every applicable standard and implementation specification in the HIPAA Security Rule (45 CFR 164.308–164.316) and the administrative requirements of the Privacy Rule (45 CFR 164.530). It produces a list of deficiencies. A risk analysis, required under 45 CFR 164.308(a)(1)(ii)(A), goes further: it identifies threats and vulnerabilities to electronic protected health information, estimates likelihood and impact, and assigns risk levels.
Put plainly: the gap analysis tells you what is missing. The risk analysis tells you how badly it could hurt you. OCR requires the second one. The first one is how most practices get there without drowning.
You cannot substitute one for the other. HHS has stated repeatedly in enforcement resolutions that a checklist of implemented controls does not satisfy the risk analysis standard. Read the agency's Guidance on Risk Analysis Requirements under the HIPAA Security Rule before you scope the project, because it defines the boundaries you will be measured against.
Step 1: Build the ePHI Inventory Before You Build the Checklist
Every gap analysis that fails, fails here. Teams open a spreadsheet of 54 implementation specifications and start marking yes/no without knowing where the data lives. You end up certifying safeguards for systems you forgot you had.
Spend the first week producing a written inventory. For each system that creates, receives, maintains, or transmits ePHI, record:
- System name, vendor, and hosting model (on-premise, cloud, hybrid)
- What ePHI elements it holds and roughly how many records
- Who has access, by role, and who provisions that access
- Whether a Business Associate Agreement is on file and when it was last executed
- Where backups go and who controls the encryption keys
Do not stop at the EHR. The inventory that matters includes the practice management system, the clearinghouse connection, the patient texting tool the front desk started using in 2023, the transcription service, the answering service, the shared scanner that emails PDFs to a staff inbox, the two laptops a departed biller took home, and the flash drive in the credentialing coordinator's desk. Walk the floor. Ask what people actually use, not what policy says they use.
The three questions that surface shadow systems
Ask each department lead: What do you use when the EHR is down? What do you use to send something to a patient quickly? What do you use to send something to another practice? The answers routinely produce two or three tools nobody on the compliance side had heard of.
Step 2: Walk the Standards, One Implementation Specification at a Time
With the inventory done, work the Security Rule in order. Administrative safeguards at 164.308, physical at 164.310, technical at 164.312, organizational requirements at 164.314, and policies and documentation at 164.316. Then run the Privacy Rule administrative requirements at 164.530 and the breach notification obligations at Subpart D.
For each specification, record four things: the requirement, what you currently do, the evidence that proves it, and the gap. "Evidence" is the column people skip and the column investigators read. A screenshot of your access control settings is evidence. "We have unique logins" is an assertion.
Required versus addressable — and what changed in 2025
Implementation specifications are marked required or addressable. Addressable does not mean optional. It means you must assess whether the specification is reasonable and appropriate for your environment, implement it if it is, and if it is not, document why and implement an equivalent alternative. That written rationale is itself a compliance artifact. Missing rationales are one of the most common findings in any HIPAA gap analysis.
Worth flagging for planning purposes: in January 2025, HHS published a notice of proposed rulemaking to strengthen the Security Rule, including a proposal to eliminate the required/addressable distinction and make specifications mandatory with limited exceptions. That rule was still proposed, not final, as of this writing. Do not remediate to a rule that hasn't landed — but if you are choosing between two remediation paths, choose the one that survives the tighter standard.
Step 3: Score Each Gap So Remediation Has an Order
A list of 41 gaps with no priority is a list nobody works. Score each finding on two axes: likelihood that the deficiency gets exploited or discovered, and impact if it does. A three-by-three grid is enough. Resist the urge to build something more elaborate than your team will maintain.
Impact should include regulatory exposure, not just clinical or operational damage. A missing BAA with a vendor holding 40,000 records is a high-impact gap even if that vendor has never had an incident, because the deficiency itself is a violation independent of any breach.
NIST Special Publication 800-66 Revision 2 maps HIPAA Security Rule requirements to the NIST Cybersecurity Framework and gives you defensible language for how you assessed likelihood and impact. Cite your method in the report. "We used a qualitative three-tier scale informed by NIST SP 800-66r2" reads far better than an unexplained number.
Step 4: Convert Gaps Into a Dated Plan With Names Attached
The risk management standard at 164.308(a)(1)(ii)(B) requires you to implement security measures sufficient to reduce risks to a reasonable and appropriate level. That is the remediation plan. It is not optional follow-up work; it is the second half of the same regulatory obligation.
Every gap gets four fields: owner (a person, not a department), target date, remediation action, and status. Review the plan monthly at a standing meeting with a written record of attendance and decisions. When a target date slips, document why and set a new one. A plan showing honest slippage with documented reasons is far stronger than a plan that mysteriously shows everything closed.
Realistic timing for a 15-provider practice: two weeks for inventory, three weeks for the standard-by-standard walk, one week for scoring and drafting, then six to nine months of remediation depending on how many technical gaps require vendor work or capital spend.
The Business Associate Gaps That Show Up in Nearly Every Practice
When you cross-reference your vendor list against your executed agreements, expect to find three categories of trouble. Vendors with no BAA at all — often the ones onboarded by a clinical department without routing through administration. Vendors with an agreement so old it predates the 2013 Omnibus Rule and lacks the required breach notification and subcontractor provisions. And vendors where you have the agreement but nobody can locate the signed copy.
All three are findings. The third one is a finding because 164.316(b)(2) requires you to retain documentation for six years from creation or last effective date, and an agreement you cannot produce is an agreement you do not have.
Closing this category is usually the fastest visible win in a HIPAA gap analysis, and it is where a lot of practices stall because drafting agreements feels like legal work. If you need to paper a handful of vendors quickly, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — then route it for signature the same week you identify the gap. That turns a six-month legal queue into a same-month closure.
Also check the direction of the agreement
If your practice receives PHI from another covered entity to perform a service — reading images, providing billing support, hosting a portal — you may be acting as a business associate yourself. That obligation flows downstream to your subcontractors under 164.314(a)(2)(iii). Map both directions.
What the Finished Documentation Package Actually Contains
When OCR opens an investigation after a breach report, the initial data request is predictable. Assemble these now so you are not reconstructing them under a 30-day response deadline:
- The gap analysis report itself, dated and signed by the privacy or security officer
- The ePHI inventory that scoped it
- The risk analysis with likelihood/impact determinations
- The risk management plan with owners, dates, and status history
- Current policies and procedures, with version dates and approval records
- Workforce training rosters with dates and content covered
- Executed BAAs for every vendor on the inventory
- Sanction policy and any applied sanctions
- Prior-year gap analysis and evidence of what changed
That last item carries disproportionate weight. A single assessment shows you did something once. A dated sequence shows an ongoing program, which is the standard the Security Rule actually sets.
Note that no government body certifies a gap analysis, and HHS does not endorse any product or vendor. Anyone telling you they will make your practice "HIPAA certified" is describing a private attestation, not a federal credential.
Who Does What, and On What Calendar
Privacy officer: owns the Privacy Rule and breach notification portions, the training roster, and the patient rights workflows including the 30-day access response window under 164.524.
Security officer: owns the technical and physical safeguards review, the ePHI inventory, and coordination with IT or the managed service provider.
Practice administrator: owns the vendor list, contract execution, and the budget line for remediation. Nothing closes without this role.
Department leads: answer the workflow questions and validate that documented procedures match reality.
Run the full gap analysis annually, and out of cycle whenever you change EHR systems, open a location, acquire a practice, adopt a new patient communication channel, or experience a reportable incident. HHS's Security Risk Assessment Tool, developed with ONC, is free and structured around the same specifications if you want a starting framework. If you would rather have the risk analysis, policies, and full document set produced from your answers, automated HIPAA compliance documentation covers the same ground with less spreadsheet maintenance.
Four Mistakes That Make the Whole Exercise Worthless
Scoping to the EHR only. Breaches reported to OCR routinely involve email, backups, and third-party vendors — not the clinical system itself.
Marking items compliant based on a vendor's marketing page. A vendor being "HIPAA compliant" says nothing about how your practice configured the product. Access controls, audit log review, and session timeouts are your findings, not theirs.
Finishing the analysis and never touching the remediation plan. An identified, documented, unremediated gap is worse in an enforcement posture than one you never found — it shows knowledge without action.
Letting it go stale. An assessment dated more than 12 months back, with no interim updates, reads as a one-time project rather than an ongoing program.
Start With the Gaps You Can Close This Month
Pull your vendor list today. Mark every entry where you cannot immediately produce a signed, current Business Associate Agreement. That list is the first section of your HIPAA gap analysis, and it is the section you can close fastest — draft and export a compliant BAA in a few minutes, send it for signature, and file the executed copy in your evidence folder. Then move to the ePHI inventory and work the standards in order.