HIPAA is not a certification. There is no auditor who hands you a HIPAA report the way a CPA hands you a SOC 2. That is precisely why a gap analysis matters more, not less: the moment you discover your HIPAA gaps is usually a bad one — an Office for Civil Rights (OCR) investigation after a complaint, an enterprise partner's diligence that gates a contract, or a breach that turns your safeguards into evidence. A gap analysis lets you find them on your own terms first.
The anchor requirement: the HIPAA Security Rule at 45 CFR § 164.308(a)(1)(ii)(A) requires a risk analysis — an accurate, thorough assessment of the risks to electronic protected health information (ePHI). This is not optional and it is the single most-cited failure in OCR enforcement actions. A gap analysis and a risk analysis are related but not the same thing.
Gap analysis vs. risk analysis
The distinction is worth getting right because HIPAA names one of them explicitly:
- A risk analysis (required) identifies where ePHI lives, the threats and vulnerabilities to it, the likelihood and impact of each, and the resulting risk level. It is threat-centric.
- A gap analysis measures your current safeguards against the Security Rule's requirements and tells you which are missing or weak. It is control-centric.
You need both, and they feed each other: the gap analysis tells you which safeguards are absent, the risk analysis tells you which absences actually matter given your threats. Firms that do only a checklist gap analysis without a real risk analysis are missing the requirement OCR most wants to see.
The safeguards a HIPAA gap analysis covers
The Security Rule organizes safeguards into three families, each with required and addressable implementation specifications. "Addressable" does not mean optional — it means you must implement it or document why an alternative is reasonable.
Administrative safeguards
Security management (including the risk analysis), assigned security responsibility, workforce security, information-access management, security awareness training, incident procedures, contingency planning, and — easy to forget — business associate agreements (BAAs) with every vendor that touches ePHI.
Physical safeguards
Facility access controls, workstation use and security, and device and media controls including disposal and re-use.
Technical safeguards
Access control (unique user IDs, automatic logoff, encryption/decryption), audit controls (logging of ePHI access), integrity controls, authentication, and transmission security. This is the family a penetration test directly validates.
Common HIPAA gaps we find: a risk analysis that is either missing or was done once years ago, ePHI that is not encrypted at rest, audit logging that records access but is never reviewed, missing or stale BAAs, over-broad access that violates minimum-necessary, and no documented decision trail for addressable specifications that were skipped.
Where penetration testing fits
HIPAA does not name "penetration test" as a requirement, but the technical safeguards — access control, authentication, transmission security — are exactly what a pentest validates, and the required risk analysis is far more credible when it is informed by real technical testing rather than a questionnaire. A penetration test of the systems that store or transmit ePHI turns "we believe access is controlled" into "we tested it." When OCR or an enterprise partner asks how you validate your technical safeguards, a recent independent pentest is the answer that ends the conversation.
Why doing it first is not optional in practice
HIPAA's enforcement model is retrospective and expensive. Penalties scale with culpability, and "we did not know" is the most costly posture because it signals no risk analysis. A gap analysis — and the remediation it drives — is the documented, good-faith effort that both reduces your actual risk and demonstrates diligence if you are ever investigated. Doing it before an incident is compliance; doing it after is mitigation.
How Lorikeet runs a HIPAA gap analysis
We assess your safeguards against the Security Rule family by family, help you produce (or refresh) the required risk analysis grounded in your real environment, and validate the technical safeguards with an independent penetration test of the systems that touch ePHI — run on our PTaaS platform with Lory's autonomous testing countersigned by a human pentester. You get one prioritized remediation plan, the documented decision trail for addressable specifications, and the technical evidence that makes your risk analysis credible.
Close Your HIPAA Gaps Before Someone Else Finds Them
Lorikeet Security runs HIPAA Security Rule gap analyses across the administrative, physical, and technical safeguards, paired with independent penetration testing of the systems that touch ePHI.