HIPAA compliance and internal audit
HIPAA compliance and internal audit covers the administrative, technical, and process safeguards required to handle protected health information as a business associate, plus periodic internal review of billing accuracy and process.
Follows reporting and analytics. The final step in the cycle.
Where practices lose money here
Compliance gaps go unnoticed until an external audit
Access controls, transmission security, and staff training are easy to let drift when there is no internal check, and the first sign of a gap is often an external audit finding it.
Billing process and compliance get treated separately
Coding accuracy and compliance risk are related. An internal audit that only checks security controls and ignores billing accuracy misses half the actual exposure.
How we handle it
Maintain a signed Business Associate Agreement and operate under its terms as a matter of course, not just at onboarding.
Apply access controls limiting PHI visibility to staff who need it for their specific role.
Use secure transmission for all PHI, including claims data, statements, and reporting.
Run staff training on HIPAA requirements on a recurring schedule, not a one-time onboarding event.
Maintain audit logging on systems that touch PHI.
Follow a documented breach protocol, defined in advance rather than improvised if something happens.
Run internal chart and process audits periodically to catch both compliance and billing accuracy issues before an external party does.
What you receive
Concrete output for this step, delivered on a set schedule rather than on request.
- A signed BAA on file.
- An internal audit summary on the schedule agreed with the practice.
- Documentation of staff training completion.
Where this sits in the cycle
This runs alongside every other step in the cycle rather than sitting at one point in it. Every service on this site touches PHI at some point, which is why compliance is treated as infrastructure, not an add-on.
Questions about this step
Do you sign a BAA?
Yes, as a standard part of onboarding, before any PHI is shared or handled.
How often is staff trained?
On a recurring schedule, not a single onboarding session.
What does an internal audit actually check?
Both security controls, access, transmission, logging, and billing accuracy, coding, documentation support, and process adherence. The two are reviewed together because they are related.
Want us to review how this is handled in your practice right now?
The free billing audit looks at hipaa compliance and internal audit alongside the rest of the cycle, and comes back with specific findings.