top of page
Search

What an Auditor Actually Looks For: Lessons From the Other Side of the Table

Most healthcare organizations prepare for an audit the way a student crams for an exam. They pull policies together, refresh a risk assessment, assemble a binder, and hope the questions land where they are strong. Then the proposed HIPAA Security Rule is going to make annual compliance audits a permanent fixture, and cramming does not survive an annual cadence. To pass every year, you have to understand what an auditor is actually looking for, and that looks very different from the inside of the assessor's chair than it does from the organization being assessed.


I have sat in that chair. As a HITRUST evaluator working with DirectTrust and EHNAC, I assessed healthcare organizations against rigorous control frameworks. Before that, as CISO and CIO at the National Committee for Quality Assurance, I built and operated a certified ISO/IEC 27001 program that passed external surveillance audits for more than a decade with zero non-conformities. And through MTC Group, I have taken multiple healthcare organizations through initial SOC 2 Type 1 and Type 2 examinations and repeat Type 2 renewals. From all of that, here is what I can tell you an auditor is really evaluating.



Auditors Do Not Grade Intentions. They Grade Evidence.


The single biggest misconception I encounter is the belief that a well-written policy demonstrates a control. It does not. A policy demonstrates intent. An auditor is trained to close the gap between what you say you do and what you can prove you did, and that gap is where findings live.


When I evaluated an organization's access control, I did not want to read the access control policy. I wanted to see the actual list of who had access to ePHI, the approval records showing how they got it, and the review records showing that access was recertified on schedule. The policy was table stakes. The evidence was the assessment. Under the proposed rule, with its mandate for current asset inventories, enforced MFA, and recurring testing, this evidence-first posture becomes the whole exercise. Every mandated control is now a control the auditor will ask you to prove with an artifact.



The Three Questions Behind Every Finding


Strip away the framework language and every audit finding traces back to one of three failures. Understanding them tells you exactly where to focus.


First, does the control exist at all? This is the obvious one, and it is the least common source of serious findings in a mature organization. Most healthcare entities have implemented most controls in some form.


Second, does the control operate consistently? This is where mature-looking programs fail. The control exists, but it has exceptions, gaps, or periods where it lapsed. MFA is enforced, except on three legacy systems. Access reviews happen, except last quarter when the reviewer was on leave. Encryption is applied, except to the backup tier. An auditor lives in these exceptions, because a control that operates inconsistently is a control an attacker can route around.


Third, can you prove the control operated over the entire audit period? This is the question that separates a one-time pass from a program that survives an annual cycle. It is not enough that MFA is enforced today. The auditor wants evidence it was enforced throughout the period. This is precisely why the recurring SOC 2 Type 2 renewals I run for clients are so instructive: a Type 2 examination tests operating effectiveness over time, not at a single moment, which is exactly the standard an annual HIPAA audit will impose.




Healthcare information security

Where I See Organizations Fail Most Often


Three patterns recur across nearly every assessment.


The stale inventory. The asset inventory and network map do not match reality, so the scope of the audit itself is in question. If you cannot reliably say what systems hold ePHI, you cannot credibly claim any control is applied everywhere it should be. The proposed rule's inventory mandate exists precisely because this failure is so common.


The evidence gap. The control operates, but no one captured the proof as it happened, so the team scrambles to reconstruct it after the auditor arrives. Reconstructed evidence is weak evidence, and experienced auditors can tell the difference between an artifact generated in the ordinary course of operations and one assembled the night before.


The remediation that never closed. A prior assessment or scan identified a finding, a remediation plan was written, and the loop was never closed. This is the most damaging pattern, because it documents that the organization knew about a risk and did not resolve it. In an enforcement context, that is the raw material of a willful neglect determination.



What Leaders Should Do


Prepare for the audit you will actually face, not the one you hope for. That means building your program so that evidence is generated continuously, in the normal course of operations, rather than assembled reactively. It means treating your asset inventory as a living operational record, not a compliance artifact. And it means closing every remediation loop and keeping the proof that you did.


The fastest way to see where you stand against the questions an auditor will ask is my free "Big Rocks" Information Security Risk Assessment, a 10-question, five-minute survey linked from the MTC Group homepage. It will not replace a formal readiness review, but it will show you your biggest exposures quickly and at no cost.


Passing an audit once is achievable for almost anyone with enough runway. Passing every year, under a rule that now demands it, is a discipline. Building that discipline, and the evidence engine underneath it, is the work we do at MTC Group. If you want an assessment run by someone who has sat on both sides of the table, reach out at rick@mtcgroupllc.com.




Sources & Further Reading


  1. HIPAA Security Rule, HHS Office for Civil Rights

  1. ISO/IEC 27001 Information Security Management, International Organization for Standardization

 
 
 

Comments


bottom of page