Skip to content
CyberSmithSECURE
Under Attack

HIPAA

HIPAA Assessment

The Security Rule separates its requirements into administrative, physical and technical safeguards, and an organisation can be strong in one and absent in another — so each is assessed against its own control set and reported separately. The assessment does not stop at checking whether a policy or document exists. Controls are assessed across five stages — from design intent through to demonstrated effectiveness — so the outcome distinguishes “we have a policy” from “we have an operating control that can be demonstrated”.

Methodology

  1. 01

    Scope

    Establish what is subject to the requirements — which systems, workforce members and business processes create, receive, maintain or transmit protected health information.

  2. 02

    Risk Assessment

    Assess the risk across that scope, to the confidentiality, integrity and availability of electronic protected health information.

  3. 03

    Safeguard Assessment

    Assess the administrative, physical and technical safeguards, each against its own control set rather than as one combined score.

  4. 04

    Evidence Validation

    Validate the evidence that the safeguards operate, not only that they are documented.

  5. 05

    Gap Identification

    Identify the gaps the assessment surfaces, grouped so remediation can be assigned to the function that owns it.

  6. 06

    Remediation

    Plan the remediation those gaps call for, sequenced by risk.

Approach to testing

  • Requirement — what does the applicable standard, regulation or framework require?
  • Control — what control has the organisation established?
  • Implementation — how is the control actually implemented?
  • Evidence — what evidence demonstrates that the control operates?
  • Risk — what happens if the control is ineffective or absent?
  • Action — what needs to be changed?
  • Validation — has the corrective action actually addressed the issue?

Types of assessment

Black-Box

Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.

Grey-Box

Selected organisational documentation, process information and evidence are provided for structured assessment.

White-Box

Full documentation, evidence, stakeholder and process access is provided for detailed control validation.

Hybrid

Combines independent assessment techniques with detailed evidence and stakeholder validation.

Frameworks and standards

HIPAA Privacy Rule
Governs permitted uses and disclosures of protected health information, and the rights of the individuals it belongs to. Assessed as part of the privacy governance review.
HIPAA Security Rule
The source of the administrative (§164.308), physical (§164.310) and technical (§164.312) safeguards.
HIPAA Breach Notification
The source of the breach risk assessment criteria and the notification timelines. Assessed as part of incident and breach governance.
CSS HIPAA Assessment Checklist
The checklist the assessment is run from, mapping each assessed control back to the requirement it satisfies.

Tools used

Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.

CSS HIPAA Assessment Checklist

Safeguard assessment across administrative, physical and technical controls.

CSS HIPAA Matrix

Control-to-safeguard mapping, so a gap is traceable to the requirement it fails.

CSS HIPAA Procedure Library

Risk analysis, workforce clearance, emergency access, information systems activity review, data backup, disaster recovery, disposal, asset tracking, password management and access control validation.

CSS HIPAA Standards Library

Encryption and key management, authentication, audit, least privilege, remote access, patch management, antimalware, backup, file integrity monitoring, network and firewall standards.

GRC Assessment Toolkit

Risk assessment, third-party risk, evidence assessment and remediation tracking.

PlyoGRC

Where appropriate, the toolkits are supported through PlyoGRC for control, evidence, risk and compliance management.

Checklist approach

The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.

Administrative safeguards (§164.308)

  • Security management process and risk analysis
  • Assigned security responsibility
  • Workforce security and workforce clearance
  • Information access management
  • Security awareness and training
  • Security incident procedures
  • Contingency planning, data backup and disaster recovery
  • Periodic evaluation
  • Sanction policy

Physical safeguards (§164.310)

  • Facility access controls
  • Access control and validation procedures
  • Workstation use and workstation security
  • Device and media controls
  • Disposal and media re-use
  • Asset tracking and accountability

Technical safeguards (§164.312)

  • Access control and unique user identification
  • Emergency access procedure
  • Automatic logoff and least privilege
  • Audit controls and information systems activity review
  • Integrity and file integrity monitoring
  • Person or entity authentication
  • Transmission security, encryption and key management

Privacy governance

  • Assigned privacy responsibility
  • Privacy policies and notices of privacy practices
  • Permitted uses and disclosures
  • Minimum necessary standard
  • Authorisations where required
  • Data classification and retention

Individual rights

  • Right of access to records
  • Right to request amendment
  • Right to an accounting of disclosures
  • Right to request restrictions
  • Right to confidential communications

Incident and breach governance

  • Incident identification and escalation to privacy
  • Breach risk assessment against the four-factor criteria
  • Notification to affected individuals and to the regulator
  • Media notification where thresholds are met
  • Breach log and documentation retention
  • Post-incident review and corrective action

Business associate and third-party governance

  • Business associate inventory and risk tiering
  • Business associate agreements and required terms
  • Subcontractor and downstream entity flow-down
  • Breach reporting obligations and timelines
  • Return or destruction on termination
  • External connection inventory and third-party access review

Supporting technical standards

  • Patch management and antimalware
  • Network security, compartmentalisation and firewall configuration
  • Remote access
  • Server and workstation hardening
  • Vulnerability scanning

How CSS tests

A unified swarm of agents, for blind spot detection

AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.

  • Framework Mapping Agent — maps requirements and controls across applicable frameworks.

  • Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.

  • Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.

  • Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.

  • Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.

  • Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.

AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.

Why this differs

What CSS does that most vendors do not

Every one of these is checkable. Ask any vendor for the same and compare the answers.

Three safeguard categories, reported separately

Administrative, physical and technical safeguards are assessed against their own control sets and reported on their own. A single combined compliance percentage hides the category an organisation has not started.

Beyond the checklist

Structured checklists and framework mappings establish coverage, but the assessment continues through implementation, evidence, risk, action and validation.

Operating control, not documentation only

Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?

Every gap traces to a requirement

The HIPAA Matrix maps each assessed control back to the safeguard it satisfies, so a finding arrives with the citation attached rather than as a generic recommendation.

Breach readiness is tested, not assumed

A documented notification procedure and a demonstrated ability to notify inside the required timeline are different things. The assessment looks for evidence of the second.

Depth selected per engagement

Black-box, grey-box, white-box or hybrid, chosen on the purpose, scope and risk of the engagement rather than applied uniformly.

Human-in-the-loop AI assistance

AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.

What you receive

A working management system, not a folder of documents

The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.

Executive layer

Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary

GRC layer

Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker

Assurance layer

Internal audit, findings, CAPA, management review, certification-readiness assessment

Operational layer

Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable

Governance cadence established

Monthly
Risk / action review, evidence status, control exceptions, material incidents
Quarterly
Risk trend, supplier / control reviews, KPI/KRI, management action tracking
Annual
Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan

For this engagement specifically

  • Control owners
  • IT teams
  • Security teams
  • Compliance teams
  • Process owners
  • Auditors
  • Key risks
  • Significant gaps
  • Business impact
  • Priority actions
  • Ownership
  • Target timelines

Next

Scope this assessment

Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.