QAreMed
MenuClose

Situation

What to do after HIPAA audit findings

Sort the findings first. A finding that names a missing control has no closing date anywhere in the Security Rule. A finding that evidences an impermissible access is presumed to be a breach under 45 CFR 164.402 until a four-factor risk assessment says otherwise, and 164.404(b) then caps individual notice at 60 calendar days from discovery.

What has happened
A report has arrived naming findings against your handling of electronic protected health information, sent by a customer's assessor, by an internal evaluation or by a regulator, and somebody is now asking you for a date against each line.
If nothing changes
Nothing in the Security Rule sets a date by which a finding has to be closed, so an unanswered finding does not expire. It is read again at the next evaluation under 45 CFR 164.308(a)(8), and it sits in your own file for the six years 164.316(b)(2)(i) requires of the documentation beside it.

What has changed now that the finding is written down?

The status of your paperwork. Until somebody wrote the finding, the records required by 45 CFR 164.316 were a standing obligation with no particular reader. From the moment a finding exists, the same records are the only evidence of what you did about it, and what you did is assessed separately from the defect that was found. Two things are now open where one was open before.

The word audit covers three senders that do not carry the same weight. A finding can come from a customer's assessor working through a security questionnaire, from your own periodic evaluation, or from a regulator. The Security Rule names only the middle one. section 164.308(a)(8), Evaluation is a Required standard, and it asks for one thing: a periodic technical and nontechnical exercise establishing how far your own policies and procedures reach Subpart C. The rule fixes no interval for it and names nobody to run it. The safeguard standards themselves, and the way software testing reaches them, live on HIPAA testing requirements for software. This page begins one step later, at the finding.

The response obligation is not implied. It is written into two places that most remediation plans never cite. section 164.306(e), Maintenance puts the entity under a standing duty to keep its Subpart C security measures under review and to change them where continued protection of ePHI needs it, and to bring the documentation of those measures along in accordance with 164.316(b)(2)(iii). That cross-referenced specification asks for periodic review and update of the documentation in response to environmental or operational change, and a remediation is such a change. The fix you ship this month therefore lands back inside the documentation obligation on the way out.

section 164.316(b)(1) then decides what the response is worth. It asks for the policies and procedures in writing, electronic writing included, and for a written record of every action, activity and assessment the subpart says must be documented. A measure put in under 164.308(a)(1)(ii)(B) is such an action. Implemented without a record, it satisfies the engineering half of the finding and leaves the documentary half where it was.

What does it cost to close a finding quietly?

Three things, and they are separable. Which of them you are carrying decides what moves first.

The first is the breach presumption. Where a finding shows PHI was reached in a way Subpart E does not permit, section 164.402 treats the event as a breach until the entity demonstrates a low probability of compromise through a risk assessment on the four factors that paragraph lists, and 164.414(b) assigns the demonstrating to the entity. Doing nothing does not hold the question open. It leaves the presumption where the rule put it. The move is narrow and cheap: run the four factors against that finding, write the outcome down, and date it the day you reached it.

The second is retention. Under 164.316(b)(2)(i) the documentation Subpart C asks you to create is kept for six years, measured from whichever is later of its creation and the last day it was in effect. Your own file therefore holds the finding for six years. What sits beside it is a choice you make this month.

The third is the next evaluation. 164.308(a)(8) is triggered by environmental or operational change as well as by a calendar, so the same finding is read again by the next evaluator, along with whatever the intervening period produced. An unanswered finding gets raised twice, by two readers who do not share notes. Getting the evidence in place before the second reading is what healthcare software audit preparation covers on the way in.

Which findings start a clock, and which ones do not?

One question separates them: does the finding describe a condition, or does it evidence an event. A missing automatic logoff is a condition. A log line showing a support account opening charts outside its assignment is an event, and it fits the 164.304 definition of a security incident, which reaches an attempted access as readily as a successful one.

Only the event side carries statutory dates. Most of them count from the day of discovery, and the log for breaches affecting fewer than 500 individuals counts from the end of the calendar year. They live in the Breach Notification Rule at Subpart D, one rulebook away from the safeguard sections a finding is usually written against:

Notification dates the HIPAA Breach Notification Rule fixes in Subpart D, by number of individuals affected and for a business associate reporting to its customer.
Where the finding landsThe date Subpart D fixes
Impermissible access confirmed, individuals affected164.404(b): notice to each individual, with 60 calendar days from discovery of the breach as the outer limit and no unreasonable delay inside it
More than 500 residents of one State or jurisdiction164.406(a) adds notice to prominent media outlets, on the same 60-day outer limit at 164.406(b)
500 or more individuals in total164.408(b): notice to the Secretary contemporaneously with the individual notice
Fewer than 500 individuals164.408(c): a log, submitted no later than 60 days after the end of the calendar year
You are the business associate, and the covered entity is your customer164.410(b): tell the covered entity, on the same outer limit of 60 calendar days from discovery

Everything on the condition side has no date in Subpart C at all. Say so to whoever is asking for one, because the absence changes who owns the schedule. 164.306(b) leaves the choice of measures to the entity and gives it four things to weigh: how large and capable the entity is, what its infrastructure and its hardware and software can do, what a measure costs, and how probable and how critical the risk to ePHI is. Cost is on that list by name, in the rule itself. A remediation sequence built from those four factors is defensible; one built from the order the findings happen to appear in the report is a sequence somebody else chose for you.

Mapping each finding onto the safeguard standard it sits under is the step that makes the sorting possible, and the mapping for the technical half is mechanical enough to generate: the HIPAA technical safeguards checklist produces it for a given product type.

Which finding do you touch first?

The sequence for the days after the report lands

  1. Read every finding for evidence that ePHI was actually reached. Split the list into events and conditions.
  2. Run the four factors at 164.402 against each event. Write down the outcome, the day and the person who decided.
  3. Open the notification path for any event that fails those factors. The 60-day limit at 164.404(b) counts from discovery, not from the report date.
  4. Give each remaining finding a section of Subpart C. Mark the ones that fit no section.
  5. Read the Required or Addressable marking on each section you assigned. The two markings lead to different answers.
  6. Order the work by how probable each risk is and how much it costs the ePHI if it happens. 164.306(b)(2)(iv) names both.
  7. Record the decision for each finding under 164.308(a)(1)(ii)(B): a measure, an alternative measure, or an acceptance with a name against it.
  8. Date every entry above on the day it was written.

Step 4 produces a category people do not expect. Some findings attach to no section, because an assessor's template covers more ground than Subpart C does. Those findings are still defects and they still cost you something. Keeping them in the register with the marking visible is what stops them from being answered as if the rule demanded them, and from being dropped because it does not.

Step 8 is the one that fails silently. A remediation record with no date cannot show that the response came after the finding, and the sequence is the only thing that distinguishes a response from a coincidence.

Which findings can you answer without changing the product?

More than the report implies, and the rule says so in three separate places.

The first is the Required and Addressable split at 164.306(d). Of the implementation specifications in the Security Rule as codified, 17 are Required and 22 are Addressable. Six standards have nothing underneath them and are Required in their own right. A finding sitting on one of the 17 has one answer: implement it. A finding sitting on one of the 22 has the documented exit above, and taking that exit is an answer the rule wrote for you. Under 164.312 the split falls two against five. Unique user identification and emergency access procedure are Required. The remaining five, both encryption specifications among them, are Addressable, which is why an encryption finding and a unique-identifier finding call for different answers even where the assessor gave them the same severity.

The second is the flexibility of approach at 164.306(b). The rule accepts whichever measures implement its standards reasonably and appropriately where you have put them. An assessor's recommended control is one such measure. It is not the measure the rule names, because the rule names none. Where a cheaper control reaches the same standard, the response is the reasoning and the record, not the recommended product.

The third is what the text does not say. Four things findings are commonly written against are absent from Subpart C in the form the report assumes:

Four assertions common in HIPAA audit reports, on log retention, multi-factor authentication, corrective action plans and background checks, set against what the Security Rule says.
What the report assertsWhat the text of Subpart C says
Logs must be retained for a set period164.312(b) fixes no retention period and no log format, and lists no events that must appear. The period is set by your own policy, and 164.316(b)(1) then makes that policy the thing you are measured against
Multi-factor authentication is required164.312(d) goes as far as verifying that a party reaching for ePHI is the party it claims to be, and no further. The rule names no second factor anywhere, so the answerable version of the finding is whether every route to ePHI is covered, and which factor covers it is yours to justify
The corrective action plan in the assessor's template is the deliverableWhat Subpart C obliges is risk management at 164.308(a)(1)(ii)(B), measures sufficient to bring the risk down to a level that is reasonable and appropriate, and the written record at 164.316(b)(1). A plan holds both conveniently. The obligation is the measure and the record, and the plan is the container somebody chose for them
Background checks must meet a stated bar164.308(a)(3)(ii)(B), workforce clearance procedure, is Addressable and asks for procedures to determine that a workforce member's access to ePHI is appropriate. It names no criterion, no record and no frequency

Placing a finding in the right column is not an argument for leaving it alone. The cheap defects are worth fixing whether or not a section compels them. The column changes what you write beside each finding, and the order in which the money goes out.

One class of finding is worth checking before you answer its substance at all: the finding that cites a provision which is not there. The clearest example is 164.308(b)(4). That paragraph was removed in 2013 and the section now stops at (b)(3), yet the number is still reachable through a cross-reference the CFR never corrected, so assessor templates keep quoting it. A finding written against a deleted paragraph cannot be closed, because there is no provision to close it against. Ask in writing which obligation is meant, record the answer beside the finding, and answer that.

What does a closed finding have to leave behind?

A record that ties the measure to the finding, on a named build, with a date. Nothing in Subpart C names the document, so the requirements have to be read off the sections the record answers.

Six records that close a HIPAA Security Rule audit finding, each matched to the section of the rule it answers.
The recordThe section it answers
The finding restated as a risk to named ePHI164.308(a)(1)(ii)(A). The risk analysis assesses risks to the ePHI your organisation holds, so a finding with no ePHI attached to it has nowhere to sit inside one
The decision: fix, alternative measure or acceptance, with the name against it164.308(a)(1)(ii)(B), risk management
The written assessment for an Addressable specification left out, and the alternative measure164.306(d)(3)(ii)(B), which requires both
Evidence that the measure behaves as intended on a stated build164.306(e), which puts the entity under a standing duty to revisit and change its measures, and 164.316(b)(1), which turns the change into a record
The updated policy or procedure, with the date the previous version stopped being in effect164.316(b)(2)(iii) for the update, 164.316(b)(2)(i) for the six years that then start running
The log evidence that the fixed path is now recorded164.312(b), audit controls, feeding the review of information system activity that 164.308(a)(1)(ii)(D) requires

The last row is the one that turns a fix into something a later reader can verify without your help. A finding about access control is closed by changing who can reach a record; that the change holds is shown by the log. Where the finding was about the logging itself, the check has a shape of its own, and building it is covered in audit trail testing.

Retesting a fix hands somebody outside the team that owns the finding an account on the system the finding came from, and the terms of that account belong in writing before it is created. The answers we give to that question are collected at how we work with protected health information. We sign a Business Associate Agreement before any engagement that touches PHI. We do not need production PHI to test. Environments run on synthetic and de-identified data.

How long does this run for?

The fixed dates all sit in Subpart D and all attach to a breach: 60 calendar days from discovery for individual notice under 164.404(b), the same limit for a business associate under 164.410(b), and 60 days after the end of the calendar year for the log of breaches involving fewer than 500 individuals under 164.408(c). Subpart C, where the safeguards live, states two periods of its own, and neither closes a finding: the compliance dates at 164.318, which passed in 2005 and 2006, and the six-year retention at 164.316(b)(2)(i). The schedule for the condition-side findings is therefore yours to set and yours to defend.

Two dates then run past the remediation itself. The six years at 164.316(b)(2)(i) start again each time a procedure is superseded, counted from the last day the old version had effect. And the evaluation at 164.308(a)(8) is due again on the operational change your own fix created, which is the reason a remediation programme that ends at the last closed ticket tends to reopen at the next assessment: the evidence stopped at the fix and the obligation did not.

What does a testing supplier add once the findings exist?

Two things: the retest that shows the measure holds, and the record that ties it back to the finding. The engineering work is usually the smaller half; the half that goes wrong is the record, because it has to name the ePHI, the section, the build and the date, and it has to exist before anyone asks for it.

What that looks like as an engagement over the whole Addressable specification register and the material behind the periodic evaluation is HIPAA compliance testing. Where the findings are technical and the question is whether the measure holds against the thing that found it, that is PHI security testing, which carries the retest and the finding register keyed to Subpart C sections.

The evaluation at 164.308(a)(8) and the risk analysis behind it are signed inside your organisation, and so is the position that rests on them. Our output is the evidence a later reader needs in order to agree with that signature.

Provisions quoted here were checked on 3 September 2026 against parts 160 and 164 of title 45 as the eCFR held them on 31 August 2026, and the 164.308(b) paragraph numbering was confirmed a second time in the printed title 45 revised to 1 October 2025. The codified safeguards are in Subpart C of part 164.

What do buyers ask about this?

Does the Security Rule give us a deadline to close a finding?
No. Subpart C states two periods and neither one closes a finding: the compliance dates at 164.318, 20 April 2005 and 20 April 2006, and the six-year retention at 164.316(b)(2)(i). The 60-day limits people quote come from a different rulebook, the Breach Notification Rule at Subpart D, and they attach to a breach. A date on your remediation ticket comes from a contract, a customer or the assessor's template, and which of the three it came from decides whether it can be renegotiated.
Is an audit finding itself a reportable security incident?
Usually not. 45 CFR 164.304 defines a security incident as the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. A finding that a control is absent describes a condition. A finding that somebody reached records they held no rights to describes an event of exactly that kind, and it belongs in the response and reporting procedure at 164.308(a)(6)(ii), which is Required.
Our assessor says encryption at rest is mandatory. Is it?
Encryption and decryption at 45 CFR 164.312(a)(2)(iv) is marked Addressable, as is encryption in transmission at 164.312(e)(2)(ii). 164.306(d)(3) lets an entity record why a specification is not reasonable and appropriate in its environment and put an equivalent alternative measure in its place. Encryption still carries weight from a different direction: 164.402 defines unsecured protected health information by whether it was rendered unusable, unreadable or indecipherable through a methodology the Secretary specifies, and breach notification turns on that definition.
The finding cites 45 CFR 164.308(b)(4). Where is that?
Nowhere in the current text. 164.308(b) stops at paragraph (b)(3), the Required written contract specification, and has done since 2013. The dead number survives in a single cross-reference at 164.314(a)(2)(iii), printed that way in the eCFR current to 31 August 2026 and in the printed CFR for title 45 revised to 1 October 2025. Ask the assessor in writing which obligation the finding means before you draft anything against it.
How long do we have to keep the remediation record?
45 CFR 164.316(b)(2)(i) requires six years, counted from whichever is later of the day the record was created and the last day it was in effect. A procedure you replace this month therefore starts its six years now, not on the day somebody first wrote it. 164.316(b)(2)(ii) adds that the documentation has to be available to the people who implement what it covers, so a remediation file only the compliance team can open answers half of the specification.

Which standards does this touch?

Which product types does this apply to?

Which of our services test it?

What does validating your product actually involve?

Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.