Deliverable Example

HIPAA Compliance Gap Analysis Remediation Plan

A sample remediation plan showing what happens after a gap analysis — how compliance gaps are identified, prioritized, assigned, and resolved for small healthcare practices.

Understanding the HIPAA Gap Analysis

A HIPAA gap analysis maps your current compliance program against all applicable HIPAA requirements to identify what is missing, incomplete, or undocumented. It covers the full scope of federal requirements:

  • Security Rule — Administrative safeguards (45 CFR §164.308), physical safeguards (§164.310), and technical safeguards (§164.312)
  • Privacy Rule — Permitted uses and disclosures of protected health information, minimum necessary standards, and patient rights
  • Breach Notification Rule — Requirements for notifying individuals, HHS, and media following a breach of unsecured PHI under §164.404

The output of a gap analysis is a list of findings — specific areas where the practice does not yet meet a HIPAA requirement. Each finding is then documented in a remediation plan with a CFR reference, risk level, corrective action, responsible owner, and deadline.

Gap analysis vs. risk assessment: A gap analysis is broader — it checks whether required elements exist. A Security Risk Assessment under §164.308(a)(1)(ii)(A) goes deeper on security threats and vulnerabilities to electronic PHI. Most practices need both. The gap analysis shows what is missing. The risk assessment shows what is at risk.

What a Remediation Plan Looks Like

After the gap analysis, each finding is documented in a remediation plan. The table below shows a representative set of findings from a typical small practice assessment. Actual findings vary by organization.

Finding CFR Reference Risk Level Remediation Action Owner Timeline
No documented Security Risk Assessment §164.308(a)(1)(ii)(A) High Complete SRA using structured methodology Privacy Officer 30 days
Missing written policies and procedures §164.316(a) High Draft and implement 38 required policies Office Manager 45 days
No staff training records on file §164.308(a)(5)(i) High Enroll staff in training modules, document completion HR Lead 30 days
BAAs missing for 3 vendors §164.502(e) High Execute digital BAAs for all PHI-touching vendors Privacy Officer 14 days
No breach notification procedure §164.404(b) Medium Document incident response workflow Privacy Officer 21 days
Workstation screens visible to patients §164.310(b) Medium Install privacy screens, reposition monitors Office Manager 7 days

This is a simplified example for illustration. An actual remediation plan may include 15 to 40 or more findings depending on the maturity of the existing compliance program. Each finding links back to a specific CFR citation so the practice knows exactly which regulation it addresses.

How the Remediation Process Works

1

Gap Analysis Identifies All Compliance Gaps

Every HIPAA requirement is reviewed against your current program. Missing policies, undocumented procedures, incomplete training records, unsigned BAAs, and unaddressed security controls are all catalogued with their specific CFR references.

2

Findings Ranked by Risk Severity

Each finding is assigned a risk level — High, Medium, or Low — based on the likelihood of a compliance issue and the potential impact on PHI. High-risk findings like missing risk assessments and absent policies are prioritized first.

3

Each Finding Assigned an Owner and Deadline

Every remediation item gets a named responsible party and a specific completion date. This creates accountability and prevents findings from being deferred indefinitely.

4

Implementation with Consulting Support

The practice works through each remediation item. With the Full-Scope plan, a dedicated consultant provides hands-on guidance for completing the risk assessment, drafting policies, delivering training, and executing BAAs.

5

Evidence Documented for Six-Year Retention

All completed remediation actions, signed documents, training records, and risk assessment outputs are stored and organized for the six-year retention requirement under §164.530(j). This documentation is critical if the practice is ever subject to an OCR audit or investigation.

What to Do If Your Clinic Has No Risk Assessment

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security.

The Security Rule under 45 CFR §164.308(a)(1)(ii)(A) requires every covered entity and business associate to conduct a risk assessment. Section §164.316(a) requires written policies and procedures. These are not optional steps that can be deferred.

Here is a practical starting sequence:

  1. Inventory your PHI. Where is electronic protected health information created, received, stored, and transmitted? Include your EHR, email, fax, cloud storage, and any mobile devices.
  2. List your vendors. Identify every vendor that handles PHI on your behalf — EHR provider, billing company, cloud hosting, IT support, shredding service. Each needs a signed Business Associate Agreement.
  3. Document the risks. For each system and workflow, note the threats (unauthorized access, device loss, ransomware) and existing controls (passwords, encryption, locks).
  4. Write your policies. Use policy templates to create the required written documentation covering access controls, incident response, workforce training, and device management.
  5. Assign a Security Officer. HIPAA requires a designated security official under §164.308(a)(2). This can be the practice owner, an office manager, or an outside consultant.

Do not wait for a perfect program. A documented, in-progress compliance effort is significantly better than nothing. OCR has noted in enforcement actions that the absence of any risk assessment is one of the most common and most cited compliance failures. Starting now — even with basic steps — demonstrates good faith and materially reduces risk.

This content is for educational and informational purposes only and should not be construed as legal advice. Organizations should consult legal counsel for guidance specific to their situation.

HIPAA Gap Analysis and Remediation Questions

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. The Security Rule under 45 CFR §164.308(a)(1)(ii)(A) requires a risk assessment, and §164.316(a) requires written policies and procedures. These are not optional steps that can wait. Organizations should consult legal counsel for guidance specific to their situation.
A gap analysis compares your current compliance program against all HIPAA requirements to identify what is missing. It covers the Security Rule (§164.308, §164.310, §164.312), Privacy Rule, and Breach Notification Rule. A Security Risk Assessment under §164.308(a)(1)(ii)(A) focuses on identifying threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. A gap analysis is broader in scope. A risk assessment is deeper on security threats. Most practices need both.
Remediation for a small practice typically takes 60 to 90 days when working with a structured remediation plan. High-risk findings like missing risk assessments and absent written policies are addressed in the first 30 days. Medium-risk items like breach notification procedures and physical safeguard improvements follow in weeks four through eight. Low-risk items and documentation cleanup are completed by day 90. Timelines vary depending on practice size, number of findings, and staff availability. Evidence of remediation must be retained for six years per §164.530(j).
One Guy Consulting offers full-scope HIPAA help for small practices and business associates, including a Security Risk Assessment under §164.308(a)(1)(ii)(A), gap analysis and remediation plans, custom policies and procedures per §164.316(a), staff training with tracking per §164.308(a)(5)(i), site and IT audits under §164.310 and §164.312, vendor and BAA management per §164.502(e), incident handling and breach notification support per §164.404(b), and audit-readiness support with documentation retention per §164.530(j). Everything is included in one flat annual rate with no per-user fees.

Learn More About HIPAA Compliance

Ready to Identify and Close Your Compliance Gaps?

Book a free 30-minute intro call. We will review your current compliance status and walk through what a gap analysis and remediation plan would look like for your practice.

Book Your Free HIPAA Compliance Review