How to Conduct a HIPAA Gap Analysis for Small Practices

Practical guidance for healthcare teams and business associates

What a HIPAA Gap Analysis Actually Involves

A HIPAA gap analysis compares your organization's current compliance posture against the requirements of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. It identifies where you meet the standard, where you fall short, and where you have no controls at all.

For small healthcare practices, the gap analysis is where compliance stops being abstract and starts getting specific. It takes the broad requirements of 45 CFR Part 164 Subpart C and translates them into concrete findings about your practice.

A gap analysis is not a risk assessment. The Security Risk Assessment (SRA) evaluates threats and vulnerabilities to electronic protected health information (ePHI). The gap analysis evaluates whether your policies, procedures, training, and safeguards actually align with what HIPAA requires. Many organizations complete an SRA and assume they are done. They are not. The SRA tells you what could go wrong. The gap analysis tells you what is already wrong.

Key Distinction

An SRA asks: "What are the risks to our ePHI?" A gap analysis asks: "Are we meeting the specific requirements of the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule?" Both are necessary. Neither replaces the other.

Step 1: Start With What HIPAA Actually Requires

Before you can identify gaps, you need a clear inventory of what HIPAA expects. The Security Rule alone has 54 implementation specifications spread across administrative, physical, and technical safeguards under §164.308, §164.310, and §164.312. The Privacy Rule adds requirements for notice of privacy practices, individual rights, minimum necessary use, and authorization. The Breach Notification Rule adds requirements for incident detection and reporting.

A practical approach for a small practice is to organize the evaluation by safeguard category:

  • Administrative Safeguards (§164.308) — security management process, assigned security responsibility, workforce security, information access management, security awareness and training, security incident procedures, contingency planning, and evaluation.
  • Physical Safeguards (§164.310) — facility access controls, workstation use, workstation security, and device and media controls.
  • Technical Safeguards (§164.312) — access controls, audit controls, integrity controls, person or entity authentication, and transmission security.
  • Privacy Rule Requirements — notice of privacy practices, individual access rights, minimum necessary standard, Business Associate Agreements, and authorization requirements.
  • Breach Notification Rulebreach detection, notification timelines, and documentation.

Do not try to evaluate all of these in a single afternoon. For a practice with 5 to 20 staff members, plan on working through the evaluation over two to three weeks. Rushing the process produces incomplete findings that do not hold up under scrutiny.

Step 2: Document Your Current State Honestly

For each HIPAA requirement, document what your practice actually does today. Not what your policies say you do. Not what you plan to do. What happens in reality.

This is where most gap analyses fall apart. The person conducting the analysis writes "we have a password policy" and marks the access control requirement as met. But when you look closer, the password policy was written four years ago, it does not require multi-factor authentication, three staff members share a login to the practice management system, and terminated employees still have active accounts.

For each requirement, answer three questions:

  1. Do we have a written policy or procedure? If yes, when was it last reviewed or updated?
  2. Is the policy being followed? Can you point to evidence that staff are actually doing what the policy describes?
  3. Can we prove it? Do you have documentation, logs, training records, or signed acknowledgments that demonstrate compliance?

If the answer to any of those three questions is "no" or "I'm not sure," you have found a gap.

Step 3: Identify the Five Categories Where Gaps Hide

After working through hundreds of gap analyses for small practices, the same five categories account for the majority of findings:

  • Policy gaps (typically 25-30% of findings) — policies that were never created, were copied from a template and never customized, or have not been reviewed since initial creation. The most common missing policies in small practices are sanction policy, contingency/disaster recovery, and device and media disposal.
  • Process gaps (typically 20-25%) — procedures that exist on paper but are not followed consistently. The front desk verifies identity before releasing records on Tuesday but not on Thursday. Access reviews happen when someone remembers, not on a schedule.
  • Evidence gaps (typically 20-25%) — compliance activities that happen but are not documented. Training occurs but completion is not tracked. BAAs are signed but not stored in a central location. Risk assessments are discussed but the analysis is not written down.
  • Training gaps (typically 15-20%) — workforce members who have not completed HIPAA training, training that covers only Privacy and skips Security, or no documentation of training content, attendance, or acknowledgment.
  • Vendor gaps (typically 10-15%)Business Associates operating without current BAAs, IT vendors with access to ePHI who are not recognized as Business Associates, or cloud services storing PHI without appropriate agreements.

Step 4: Rank Findings by Risk

Not every gap is equally dangerous. A missing breach notification policy is a more urgent problem than a training acknowledgment form that lacks a date field. After documenting all findings, sort them into three priority tiers:

  • Critical — fix within 30 days. These gaps create direct exposure to a HIPAA violation, a data breach, or an OCR enforcement action. Examples: no current risk assessment, no BAAs with key vendors, unencrypted devices storing ePHI, no breach notification process.
  • High — fix within 90 days. Significant compliance weaknesses that do not pose an immediate threat but would be difficult to defend in an investigation. Examples: outdated policies, incomplete training documentation, access reviews that have not been conducted in over a year.
  • Moderate — fix within 6 months. Real gaps that should be closed but represent lower risk. Examples: documentation formatting issues, minor procedural inconsistencies, enhancements to an existing program.

This tiered approach prevents the paralysis that happens when an organization sees 30 findings and treats them all as equally urgent. It also helps justify budget and staff time to leadership by showing which items carry the most risk.

Step 5: Build the Remediation Roadmap

A gap analysis without a remediation plan is a list of problems with no path forward. For each finding, document a specific corrective action, assign an owner, set a deadline based on the priority tier, and define what evidence of completion looks like.

The remediation plan is the document you will reference monthly to track progress. It is also the document OCR would review in an investigation to determine whether your organization took reasonable steps to address known compliance weaknesses.

For a detailed walkthrough of the remediation process, see What Happens After a HIPAA Gap Analysis?

Practical Tip

Do not try to close all gaps at once. Organizations that attempt to fix everything simultaneously typically fix nothing well. Start with critical findings, build momentum, and work through high and moderate findings in sequence. Documented progress matters more than instant perfection.

Common Mistakes That Undermine a HIPAA Gap Analysis

Five patterns consistently reduce the effectiveness of gap analyses in small practices:

  1. Using a generic template without customization. A gap analysis that asks the same 50 questions for a solo dental practice and a 200-bed hospital is not evaluating your actual compliance posture. The analysis needs to reflect your specific workflows, technology, workforce size, and patient population.
  2. Listing findings without ranking them. An unranked list of 40 findings tells leadership nothing about where to start or how to allocate resources. Every finding needs a risk rating.
  3. No ownership model. If every finding is assigned to "the practice manager," nothing gets done. IT-related findings go to IT. Training findings go to whoever manages onboarding. BAA findings go to whoever manages vendor relationships.
  4. Treating it as a one-time exercise. HIPAA compliance changes. Your workforce changes. Your technology changes. A gap analysis from two years ago does not reflect your current compliance posture. Annual reassessment is a practical minimum.
  5. Skipping the evidence check. The most common gap in small practices is not a missing policy. It is a missing proof that the policy is being followed. A gap analysis that only checks for the existence of policies without verifying implementation evidence will miss the majority of real-world gaps.

How Often Should You Conduct a HIPAA Gap Analysis?

At minimum, annually. The gap analysis should also be triggered by significant changes to your practice: new technology systems, office moves, staffing changes, mergers or acquisitions, or any security incident. HHS guidance on risk analysis emphasizes that compliance evaluation should be ongoing, not a one-time event.

Many organizations align the gap analysis with their annual SRA update. Complete the risk assessment first, then conduct the gap analysis to evaluate whether the controls you identified in the SRA are actually in place and functioning. Our HIPAA risk assessment template guide covers what the SRA must include and how to avoid common template pitfalls.

Frequently Asked Questions

What is the difference between a HIPAA gap analysis and a HIPAA audit?

A gap analysis is an internal evaluation you conduct to identify compliance weaknesses before a problem arises. A HIPAA audit is an external evaluation conducted by OCR (the Office for Civil Rights) or a third-party auditor to determine whether your organization meets HIPAA requirements. The gap analysis is how you prepare. The audit is the test. Organizations that conduct regular gap analyses are better positioned to demonstrate compliance during an audit because they have documented evidence of identifying and addressing weaknesses.

Can a small practice conduct a HIPAA gap analysis without a consultant?

Yes, but with limitations. A practice manager or HIPAA officer can work through the safeguard categories and document current practices against HIPAA requirements. Where internal assessments typically fall short is in identifying gaps the team does not know to look for. Someone inside the organization may not recognize that a shared login is an access control violation if shared logins have always been the norm. A consultant brings pattern recognition from working across multiple organizations and an understanding of what OCR enforcement actions have targeted.

What does a HIPAA gap analysis cost?

Costs vary widely based on the size and complexity of the organization. For small practices with one to three locations, a professional gap analysis typically ranges from $650 to $3,250. The range depends on the number of systems, the number of workforce members, and the maturity of the existing compliance program. For a detailed breakdown, see our HIPAA compliance cost guide, or visit our pricing page to see current service options.

Is a HIPAA gap analysis required by law?

HIPAA does not use the term "gap analysis" in its regulations. However, the Security Rule at §164.308(a)(8) requires covered entities to perform a periodic "technical and nontechnical evaluation" of their compliance. A gap analysis satisfies this requirement when it systematically evaluates the organization's policies, procedures, and safeguards against the standards in the Security Rule, Privacy Rule, and Breach Notification Rule.

What is the difference between a HIPAA gap analysis and a risk assessment?

A risk assessment (SRA) identifies threats and vulnerabilities to ePHI and evaluates the likelihood and impact of those threats materializing. A gap analysis evaluates whether your organization's policies, procedures, and controls meet the specific requirements of HIPAA. The SRA asks "what could go wrong?" The gap analysis asks "are we doing what HIPAA says we should?" Both are necessary components of a complete compliance program.

Conclusion

A HIPAA gap analysis is the bridge between knowing what HIPAA requires and knowing whether your practice actually meets those requirements. For small practices without dedicated compliance staff, the five-step process outlined here provides a structured path through what can otherwise feel like an overwhelming set of regulations. If you want a quick starting point, take our free HIPAA checkup to see where your biggest compliance gaps are before committing to a full analysis.

The key is honesty in the assessment, documentation of findings, and a prioritized plan to close the gaps that carry the most risk. One Guy Consulting provides HIPAA gap analysis services built specifically for small practices and Business Associates. Book a free 30-minute intro to walk through your compliance posture.

Sources

This content is for educational and informational purposes only and should not be construed as legal advice.