What is a HIPAA Security Rule Gap Analysis and Why It Matters Now

All covered entities within U.S. healthcare, and their business associates, must hold controls that adhere to the Health Insurance Portability and Accountability Act (HIPAA) security standards or risk data breaches and non-compliance enforcement from the Office for Civil Rights (OCR). One of the best ways to ensure that business controls comply with these standards is to run a HIPAA security gap analysis to remedy any vulnerabilities and weaknesses before OCR audits find them.
The "now" matters more than usual. The U.S. Department of Health and Human Services (HHS) proposed the most significant update to the HIPAA Security Rule in over a decade in January 2025, and while the final rule has been delayed—federal regulatory agendas now target July 2027 for final action—OCR is already enforcing existing requirements with a focus on whether organizations run functioning, continuous risk management programs. A gap analysis is the lowest-cost way to find out where you stand before either the regulator or the new rule does.
What a HIPAA gap analysis actually is.
A HIPAA gap analysis compares a company’s data safeguards against those required by HIPAA. The analysis finds areas where coverage may fall short. It is not a regulatory requirement, but a valuable control evaluation tool, nonetheless.
HIPAA gap analyses measure control standards in line with HIPAA’s Privacy, Security, and Breach Notification Rules. Covered entities and business associates use them to self-assess their compliance with HIPAA and identify areas for improvement.
For example, a gap analysis is useful for designing remediation plans to improve internal privacy, security, and breach preparedness programs. Crucially, a HIPAA gap analysis is for internal use, not external enforcement.
How gap analysis differs from risk analysis.
Risk analyses are required under the HIPAA Security Rule and are comprehensive, enterprise-wide investigations into how Electronic Protected Health Information (ePHI) is safeguarded. HIPAA gap analyses are optional and provide guidance on internal safeguarding.
A HIPAA risk analysis must evaluate potential threats and vulnerabilities to ePHI—in particular, to its confidentiality, integrity, and availability. The intent is to determine the likelihood and impact of potential threats and vulnerabilities to inform control selection to safeguard against risks identified. Failing to perform a risk analysis or failing to conduct a legitimate assessment is a common finding after a HIPAA complaint and OCR investigation.
A gap analysis is a review of the policy design and/or operational effectiveness of controls put in place, as a result of a risk assessment and control selection.
A gap analysis doesn't replace the obligation to perform a risk analysis, but it is highly valuable in shaping how an organization responds to the risks a risk analysis uncovers. Our guide to the HIPAA risk assessment process explains the mandatory requirement in detail.
A risk analysis evaluates companies in line with current and emerging threats, while a gap analysis measures the effectiveness of controls against the standards HIPAA expects from companies.
Understanding the difference between the two, and overseeing a balance of either type, is vital in helping avoid enforcement action, something which impacts even the largest healthcare organizations:
“Between October 21, 2009, when OCR first started publishing summaries of data breach reports on its “Wall of Shame”, and April 30, 2026, 7,670 large healthcare data breaches were reported to OCR.”
Steve Alder, The HIPAA Journal
Setting the scope of a HIPAA gap analysis
Setting the scope of a HIPAA gap analysis early means a company clearly defines what an analysis covers (e.g., systems that handle ePHI) and why. Setting a clear scope ensures that, in the event of an audit, a company can operationally justify the steps it takes to analyze HIPAA gaps.
A HIPAA analysis should cover all systems that come into contact with ePHI. That includes workflows, locations, endpoints, and devices—and whether it creates, receives, maintains, or transmits this information, it should be analyzed for compliance gaps.
HIPAA defines three main types of safeguards that a gap analysis should be split into so that all dimensions are covered:
- Administrative safeguards, such as security policies, assigned data officers, and contingency plans.
- Physical safeguards, such as access controls for buildings, hardware locking, and device controls.
- Technical safeguards, such as individual user IDs, transmission protection, and audit controls.
The full ePHI data flow should also extend to any third parties and partners who come into contact with the data. For example, a covered entity’s gap analysis scope should cover:
- Cloud-hosted environments.
- Business associates (e.g., billing providers and legal teams).
- Subcontractors (e.g., anyone working with the above, coming into contact with ePHI).
Who owns the gap analysis within an organization.
Ownership of a HIPAA security gap analysis is shared across an organization and across multiple departments. However, the organization's designated Security Officer — often working jointly with the Privacy Officer, and in smaller organizations frequently the same person—holds primary accountability for the formal analysis, its execution, and any remediation that follows.
The shared ownership applies when critical areas of a business—such as clinical leadership, IT, legal, HR, and compliance—provide feedback on existing controls within their domains to build towards an analysis and report.
The Privacy and Security Officers are responsible for rolling out a remediation plan, but it must first be signed off by executive leadership, by the board in organizations with board-level compliance oversight. Leadership also agrees on any resource decisions made tied to gaps found.
How to prepare for and run a gap analysis.
A HIPAA gap analysis should be repeatable, comprehensive, and open to review and adjustment. The process should always be anchored in three core areas: preparation, gathering evidence, and building a review.
To prepare for a gap analysis, teams should gather strong evidence covering:
- Any current policies and procedures that apply to HIPAA safeguards.
- Records of previous risk assessments, scans, penetration testing, and other analyses.
- Details of related training logs, modules assessed, and any details corresponding with related onboarding, sanctions, and terminations.
- Complete incident response documentation.
- Business Associate Agreements (BAAs), third-party due diligence, and relevant external notifications.
- Complete mapping of ePHI flow, systems, and infrastructure impacted.
- Detailed records of encryption standards, control directories, and data backups.
Note that evidence expectations may soon expand: the proposed HIPAA Security Rule updates would introduce explicit HIPAA vulnerability scan requirements—including scanning at least every six months—so organizations that build scan records into their gap analysis process now will be ahead of the change if it's finalized.
During an analysis, each of HIPAA’s standards is measured carefully against the controls and evidence documented to determine whether they meet current compliance expectations.
It is good practice to evaluate each of the safeguard groups separately and to individually identify what each control needs to do to meet HIPAA’s standards.
Gaps found during an analysis should comprehensively record what departments require to bring standards up to code, what processes are affected, and to what extent ePHI is exposed to threats. The direct causes of threats must also be clearly identified for efficient remediation.
Before a HIPAA gap analysis is completed, control owners should be contacted to validate and confirm findings.
Using a gap analysis template ensures that the process is not only streamlined and efficient but also predictable and repeatable for continuous compliance.
Key areas a gap analysis must address.
OCR auditors have the power to take enforcement action across a wide range of non-compliance factors. However, there are several key compliance failure triggers that companies may trip up on.
A HIPAA gap analysis must prioritize focus on the following areas, among others:
When to bring in legal and outside experts.
While HIPAA gap analyses can be carried out completely in-house, outside support can help to validate findings with an expert lens. Doing so can reduce guesswork, build more defensible analyses, and limit the chances of regulatory exposure.
Working with legal counsel can, for example, help companies review analysis findings and advise on potential enforcement implications. This ensures that teams can remedy gaps by order of legal priority.
What’s more, many companies hire external auditors and HIPAA consultants ahead of OCR auditing. These experts offer unbiased, independent assessments of whether existing controls are accurate and what teams must do to meet current HIPAA standards. It is an additional line of defense against enforcement.
Outside experts can be engaged at any time during the gap analysis process, but typically before auditing, bringing on new vendors, or making major changes to systems, processes, and policies. They can also help to provide insight in the event of mergers, where companies blend their controls.
Reporting findings and acting on them.
All gap analyses end with a report—which takes lessons learned from an assessment and makes recommendations for remediation. A report informs teams on how to bring individual, specific controls up to HIPAA’s current standards.
A HIPAA gap analysis report should clearly identify:
- All gaps and what systems are affected.
- How severe are gaps and threats to ePHI.
- Which HIPAA standards are directly affected.
- Who is responsible for remedying individual gaps and closing the incidents.
The report is, effectively, a bridge between the analysis and any future remediation. With data and insights from the report, Privacy and Security Officers design remediation plans around each gap found.
They set deadlines, outline resources, and declare verification steps needed for each gap found—and establish clear governance reviews and checkpoints to ensure measures are followed up on.
Analysis reviews also make recommendations regarding cycles, and how often analyses should recur to confirm issue closure. What’s more, analyses should be repeated after each major change (e.g., when new systems and vendors are introduced, or when regulations shift).
Conclusion
A HIPAA gap analysis, while not a required part of compliance, is a useful control check. However, it’s important to treat it as a recurring process, not a one-time exercise. Staying compliant with HIPAA is a continuous effort, as threats evolve and data storage needs change.
If you are running a HIPAA gap analysis for the first time, hiring outside expertise can help ensure you find all potential threats (and advise you on what to do next). Learn more about VikingCloud’s HIPAA compliance services and explore our range of support options for your business.
FAQs
Is a HIPAA gap analysis required by law?
No, a HIPAA gap analysis isn’t required by law, but it is a recommended control check to help keep safeguards operating to HIPAA’s standards. HIPAA risk analyses, however, are mandatory for all covered entities, business associates, and subcontractors handling ePHI.
How is a gap analysis different from a HIPAA risk analysis?
A HIPAA gap analysis is an optional evaluation of how a company’s security controls compare to HIPAA’s ideal standards and the steps that should be taken to meet them. A HIPAA risk analysis, meanwhile, is a mandatory, enterprise-wide assessment of specific ePHI threats and vulnerabilities. The former should never be a replacement for the latter.
How often should a HIPAA gap analysis be conducted?
There's no mandated frequency for a HIPAA gap analysis. HIPAA doesn't require one. As a best practice, most organizations run one annually, and again after any major change to systems, policies, vendor relationships, or regulations.
Who should perform the gap analysis, internal staff or external consultants?
A HIPAA gap analysis can be completed by either internal staff or external experts. Internal teams have a close, deep understanding of control contexts, and in-house checks can be cost-effective. However, hiring external consultants can reduce bias, relieve resource strain, and provide detailed, specialized expertise.
What happens if a gap analysis identifies a serious compliance failure?
A serious compliance failure must be addressed immediately, with action taken to contain the threat, document any relevant findings, and build on remediation. Proactive discovery doesn't guarantee immunity from enforcement, but documented, good-faith remediation significantly reduces risk. OCR weighs an organization's response heavily when deciding whether and how to penalize. A serious gap that's found, fixed, and documented internally is a far better position than one OCR finds first.
Related Blogs
Stay up-to-date on the latest happenings in Cybersecurity and PCI Compliance.
Supersized Confidence, Underprepared Frontlines: Closing the Restaurant Cybersecurity Gap



.png)