Deliverable Example

HIPAA Compliance Gap Analysis Remediation Plan

A sample remediation plan that shows what comes after a gap analysis: how each gap is found, ranked, handed to someone, and closed out in a small practice.

Understanding the HIPAA Gap Analysis

A HIPAA gap analysis holds your program up against every HIPAA rule that applies to you, to find what is missing, half done, or never written down. It spans the full set of federal rules:

  • Security Rule — Administrative safeguards (45 CFR §164.308), physical safeguards (§164.310), and technical safeguards (§164.312)
  • Privacy Rule — How you may use and disclose protected health information, the minimum necessary standard, and what rights a patient has
  • Breach Notification Rule — Who you have to tell after a breach of unsecured PHI, and when: the people affected, HHS, and the press, under §164.404

What you get back is a list of findings: the places where the practice does not yet meet a HIPAA rule. Each one goes into a remediation plan with the CFR it maps to, a risk level, the fix, the person who owns it, and a due date.

Gap analysis vs. risk assessment: A gap analysis is wider. It asks whether the pieces you need are there at all. A Security Risk Assessment under §164.308(a)(1)(ii)(A) digs into the threats and weak points around electronic PHI. Most practices need both. One shows what is missing. The other shows what is at risk.

What a Remediation Plan Looks Like

After the gap analysis, each finding goes into a remediation plan. The table below shows the kind of findings a small practice tends to see. Yours will differ.

Finding CFR Reference Risk Level Remediation Action Owner Timeline
No documented Security Risk Assessment §164.308(a)(1)(ii)(A) High Complete SRA using structured methodology Privacy Officer 30 days
Missing written policies and procedures §164.316(a) High Draft and implement 38 required policies Office Manager 45 days
No staff training records on file §164.308(a)(5)(i) High Enroll staff in training modules, document completion HR Lead 30 days
BAAs missing for 3 vendors §164.502(e) High Execute digital BAAs for all PHI-touching vendors Privacy Officer 14 days
No breach notification procedure §164.404(b) Medium Document incident response workflow Privacy Officer 21 days
Workstation screens visible to patients §164.310(b) Medium Install privacy screens, reposition monitors Office Manager 7 days

This is a short example, meant to show the shape of it. A real plan may run 15 to 40 findings or more, based on how far along your program is. Each one points back to a CFR citation, so you know which rule it answers.

How the Remediation Process Works

1

Gap Analysis Identifies All Compliance Gaps

We check every HIPAA rule against what you have now. Policies you lack, steps no one wrote down, training records with holes, BAAs no one signed, security controls no one set up: each is logged with the CFR it maps to.

2

Findings Ranked by Risk Severity

Each finding gets a risk level of High, Medium, or Low. That rests on how likely the issue is and how much it could hurt PHI. The high ones, such as a missing risk assessment or no policies at all, go first.

3

Each Finding Assigned an Owner and Deadline

Every item gets one named owner and a due date. That is what keeps a finding from sitting there for a year.

4

Implementation with Consulting Support

The practice works down the list. On the Full-Scope plan, one consultant stays with you to finish the risk assessment, draft the policies, run the training, and get BAAs signed.

5

Evidence Documented for Six-Year Retention

Every finished item, signed document, training record, and risk assessment output is filed and kept for the six years §164.530(j) calls for. That file is what you reach for if OCR ever audits you or opens a case.

What to Do If Your Clinic Has No Risk Assessment

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. For a step-by-step walkthrough, see how small clinics handle risk assessments.

The Security Rule at 45 CFR §164.308(a)(1)(ii)(A) says every covered entity and business associate has to run a risk assessment. Section §164.316(a) says the policies and procedures have to be in writing. Neither one waits until you have time.

Here is a practical starting sequence:

  1. Inventory your PHI. Where does electronic protected health information get made, come in, sit, and go out? Count your EHR, email, fax, cloud storage, and every phone or tablet.
  2. List your vendors. Name every one that handles PHI for you: your EHR, your billing company, cloud hosting, IT support, the shredding service. Each is one of your business associates, so each needs a signed Business Associate Agreement.
  3. Document the risks. For each system and each workflow, write down what could go wrong (someone gets in, a laptop walks off, ransomware) and what you have in place (passwords, encryption, locks).
  4. Write your policies. Start from policy templates and build the written set you need: who can get in, what to do when something breaks, how staff are trained, and how devices are handled.
  5. Assign a Security Officer. HIPAA calls for a named security official under §164.308(a)(2). It can be the owner, the office manager, or someone you bring in.

Do not wait for a perfect program. Work that is written down and under way beats nothing at all. In its enforcement actions, OCR has pointed to a missing risk assessment as one of the gaps it cites most. Starting now, even with the basics, shows good faith and cuts your risk.

This content is for educational and informational purposes only and should not be construed as legal advice. Organizations should consult legal counsel for guidance specific to their situation.

HIPAA Gap Analysis and Remediation Questions

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. The Security Rule under 45 CFR §164.308(a)(1)(ii)(A) requires a risk assessment, and §164.316(a) requires written policies and procedures. These are not optional steps that can wait. Organizations should consult legal counsel for guidance specific to their situation.
A gap analysis compares your current compliance program against all HIPAA requirements to identify what is missing. It covers the Security Rule (§164.308, §164.310, §164.312), Privacy Rule, and Breach Notification Rule. A Security Risk Assessment under §164.308(a)(1)(ii)(A) focuses on identifying threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. A gap analysis is broader in scope. A risk assessment is deeper on security threats. Most practices need both.
Remediation for a small practice often takes 60 to 90 days when working with a structured remediation plan. High-risk findings like missing risk assessments and absent written policies are addressed in the first 30 days. Medium-risk items like breach notification procedures and physical safeguard improvements follow in weeks four through eight. Low-risk items and records cleanup are completed by day 90. Timelines vary depending on practice size, number of findings, and staff availability. Evidence of remediation must be retained for six years per §164.530(j).
One Guy Consulting offers full-scope HIPAA help for small practices and business associates, including a Security Risk Assessment under §164.308(a)(1)(ii)(A), gap analysis and remediation plans, custom policies and procedures per §164.316(a), staff training with tracking per §164.308(a)(5)(i), site and IT audits under §164.310 and §164.312, vendor and BAA management per §164.502(e), incident handling and breach notification support per §164.404(b), and audit-readiness support with records retention per §164.530(j). Everything is included in one flat annual rate with no per-user fees.

Learn More About HIPAA Compliance

Ready to Identify and Close Your Compliance Gaps?

Book a free 30-minute call. We will look at where you stand and walk you through what a gap analysis and a remediation plan would mean for your practice.

Book Your Free 30 Minute HIPAA Compliance Review