10 Audit Gaps Healthcare Cybersecurity Teams Usually Find Too Late

The proposed updates to the HIPAA Security Rule make the implications of poor security processes even more critical for any organization in the healthcare industry, with large fines and potential criminal exposure for breaches. Organizations will need to positively prove their security safeguards of electronic protected health information (ePHI), and cybersecurity audits will be a key part of demonstrating this proof. 

Unfortunately, the audit process isn’t always as smooth as planned, which can lead to considerable delays, overruns and duplicate work. Gaps in the audit process rarely begin as obvious security failures, and what’s more likely is that an organization enters an assessment believing its core controls are covered, only to discover that the audit scope is incomplete, a policy no longer reflects day-to-day operations, or the evidence available can't show that a control worked consistently throughout the review period.

Because an auditor needs evidence of how a control operated – not just confirmation that the organization corrected it after the request arrived – these gaps are often difficult to address once testing is underway. So, an earlier review gives the team more time to resolve issues without delaying the report, or creating an avoidable fire drill which can lead to sleepless nights for the infosec and broader IT teams. 

Knowing some of these pitfalls before they occur may help your organization to avoid audit hell - here are 10 of the gaps healthcare teams most often need to address before a HIPAA, HITRUST, SOC 2, and PCI DSS audit.

Learn more: Healthcare Cybersecurity in 2026: Why HIPAA Readiness Now Requires Proof

1. The ePHI footprint is broader than the audit scope

Healthcare environments change quickly as new applications, cloud services, specialized tools, and vendors are introduced. An inventory that was accurate six months ago may no longer represent where ePHI is created, received, maintained, or transmitted. If a system, integration, location, or vendor is missing from the documented environment, the risk analysis and related controls may also be incomplete. HHS guidance states that a HIPAA risk analysis should cover all ePHI, regardless of its source or location.

2. The risk analysis exists, but it no longer reflects the business

Many organizations can produce a risk analysis, but the harder question is whether it reflects the current environment and connects identified risks to decisions, owners, and remediation. An acquisition, product launch, infrastructure change, or new vendor relationship can quickly make the analysis incomplete. An auditor will look beyond the document itself to understand whether the organization has an active risk management process behind it.

3. Separate audits create inconsistent answers to the same control question

Healthcare organizations frequently need to support several assurance requirements at once. HIPAA, HITRUST, SOC 2, or PCI DSS have different purposes, but they can draw on many of the same controls and evidence. When each assessment is managed separately, teams may define scope differently, submit different policy versions, or answer similar requests inconsistently. Mapping shared controls and evidence across frameworks helps expose conflicts earlier and reduces duplicated work.

Learn more: Multi-Framework Compliance Is Not the Problem in Healthcare … It’s Duplicated Work

4. Policies describe a process that teams don't consistently follow

A well-written policy is only one part of the evidence. Auditors also test whether the control described in that policy is implemented and operating as stated. Responsibilities may have moved between teams, review frequencies may have changed, or a new tool may have replaced a manual process. The gap becomes visible when the auditor compares the policy with tickets, system records, approvals, and other evidence of what actually happened.

5. The control operated, but the evidence doesn't prove it

Healthcare teams often perform the right activity without retaining the evidence an auditor needs. The organization may be unable to show who completed the work, when it happened, what was reviewed, or how exceptions were handled. Evidence created near the end of an audit period may not prove that a recurring control operated throughout it. Teams should understand the expected evidence, frequency, and owner for each control before the testing window begins.

6. Access controls work for standard users, but not every exception

Automated provisioning and offboarding can make routine access easier to manage. Gaps tend to appear around contractors, privileged administrators, service accounts, shared clinical devices, and applications outside the central identity provider. Auditors test how access is approved, reviewed, changed, and removed across the full population. A small number of exceptions can reveal that the control population is incomplete or ownership is unclear.

7. Vendor oversight stops with the business associate agreement

A signed business associate agreement is important, but it doesn't by itself show that third-party risk is being managed. Healthcare organizations also need to identify which vendors handle ePHI, assess each relationship, review appropriate assurance, and track follow-up issues. When procurement, legal, privacy, and security teams maintain different records, an audit can expose missing assessments, expired reports, unresolved findings, or vendors that never entered the review process.

8. Recovery and incident plans are documented but haven't been tested

An incident response or contingency plan can look complete while leaving operational questions unanswered. Teams may not know whether backups can be restored within the required timeframe or how clinical, security, legal, communications, and executive teams will coordinate under pressure. Testing shows that the organization can execute the plan and creates evidence of the results and corrective actions. Waiting until an auditor requests those records leaves little time to run a meaningful exercise.

9. The audit scope extends beyond what the organization can support

A broad scope can appear to offer greater assurance, but every additional system, location, service, or business unit adds controls, evidence owners, and testing. If the organization hasn’t operated or documented those controls consistently, the audit may produce avoidable exceptions or stall while teams gather missing evidence. Scope should reflect the assurance the business actually needs and the environment it can support today, with a deliberate path to expand as customer, regulatory, or commercial requirements change.

10. No one owns the audit internally

An audit may involve security, IT, privacy, legal, HR, and operational teams, but one internal lead should coordinate their work. Without a main point of contact, evidence requests can remain unassigned, deadlines can slip, and auditors may receive conflicting answers from different control owners. The lead’s role is to maintain the overall view, assign responsibilities, resolve blockers, escalate delays, and provide a consistent line of communication that reduces dropped work and finger-pointing.

Finding gaps before the audit starts

The best time to identify an audit gap is while the team still has time to respond. Healthcare organizations need early agreement on scope, control ownership, testing periods, evidence expectations, dependencies, and the way exceptions will be evaluated.

The audit partner plays an important role. Independence means the auditor shouldn't implement controls or make management decisions for the organization, but it shouldn't prevent clear communication. An experienced healthcare auditor can explain how requirements will be tested and identify where the available evidence may be insufficient while there is still time to respond.

Thoropass brings readiness, evidence collection, auditor review, issues, and milestones into one connected audit experience. Our healthcare audit team supports HIPAA, HITRUST e1, i1, and r2, SOC 2, and PCI DSS, helping organizations reuse relevant evidence while maintaining the scope and rigor each assessment requires.

If you're preparing for a healthcare audit, talk to a Thoropass audit expert about the gaps your team should look for first.

In this post:

Stay Connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Lucas Baiocchi

Sr Manager, HITRUST InfoSec Assurance

See all Posts

Related Posts

No items found.

Stay connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Want to join our team?

Help Thoropass ensure that compliance never gets in the way of innovation.

View Open Roles

Have any feedback?

Drop us a line and we’ll be in touch.

Contact us