HIPAA Gap Analysis: Find the Gaps Before an Auditor (or a Breach) Does | Lorikeet Security Skip to main content
Back to Blog

HIPAA Gap Analysis: Find the Gaps Before an Auditor (or a Breach) Does

Lorikeet Security Team August 19, 2026 11 min read

HIPAA is not a certification. There is no auditor who hands you a HIPAA report the way a CPA hands you a SOC 2. That is precisely why a gap analysis matters more, not less: the moment you discover your HIPAA gaps is usually a bad one — an Office for Civil Rights (OCR) investigation after a complaint, an enterprise partner's diligence that gates a contract, or a breach that turns your safeguards into evidence. A gap analysis lets you find them on your own terms first.

The anchor requirement: the HIPAA Security Rule at 45 CFR § 164.308(a)(1)(ii)(A) requires a risk analysis — an accurate, thorough assessment of the risks to electronic protected health information (ePHI). This is not optional and it is the single most-cited failure in OCR enforcement actions. A gap analysis and a risk analysis are related but not the same thing.

Gap analysis vs. risk analysis

The distinction is worth getting right because HIPAA names one of them explicitly:

You need both, and they feed each other: the gap analysis tells you which safeguards are absent, the risk analysis tells you which absences actually matter given your threats. Firms that do only a checklist gap analysis without a real risk analysis are missing the requirement OCR most wants to see.

The safeguards a HIPAA gap analysis covers

The Security Rule organizes safeguards into three families, each with required and addressable implementation specifications. "Addressable" does not mean optional — it means you must implement it or document why an alternative is reasonable.

Administrative safeguards

Security management (including the risk analysis), assigned security responsibility, workforce security, information-access management, security awareness training, incident procedures, contingency planning, and — easy to forget — business associate agreements (BAAs) with every vendor that touches ePHI.

Physical safeguards

Facility access controls, workstation use and security, and device and media controls including disposal and re-use.

Technical safeguards

Access control (unique user IDs, automatic logoff, encryption/decryption), audit controls (logging of ePHI access), integrity controls, authentication, and transmission security. This is the family a penetration test directly validates.

Common HIPAA gaps we find: a risk analysis that is either missing or was done once years ago, ePHI that is not encrypted at rest, audit logging that records access but is never reviewed, missing or stale BAAs, over-broad access that violates minimum-necessary, and no documented decision trail for addressable specifications that were skipped.

Where penetration testing fits

HIPAA does not name "penetration test" as a requirement, but the technical safeguards — access control, authentication, transmission security — are exactly what a pentest validates, and the required risk analysis is far more credible when it is informed by real technical testing rather than a questionnaire. A penetration test of the systems that store or transmit ePHI turns "we believe access is controlled" into "we tested it." When OCR or an enterprise partner asks how you validate your technical safeguards, a recent independent pentest is the answer that ends the conversation.

Why doing it first is not optional in practice

HIPAA's enforcement model is retrospective and expensive. Penalties scale with culpability, and "we did not know" is the most costly posture because it signals no risk analysis. A gap analysis — and the remediation it drives — is the documented, good-faith effort that both reduces your actual risk and demonstrates diligence if you are ever investigated. Doing it before an incident is compliance; doing it after is mitigation.

How Lorikeet runs a HIPAA gap analysis

We assess your safeguards against the Security Rule family by family, help you produce (or refresh) the required risk analysis grounded in your real environment, and validate the technical safeguards with an independent penetration test of the systems that touch ePHI — run on our PTaaS platform with Lory's autonomous testing countersigned by a human pentester. You get one prioritized remediation plan, the documented decision trail for addressable specifications, and the technical evidence that makes your risk analysis credible.

Close Your HIPAA Gaps Before Someone Else Finds Them

Lorikeet Security runs HIPAA Security Rule gap analyses across the administrative, physical, and technical safeguards, paired with independent penetration testing of the systems that touch ePHI.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!