ISACA logo
  • ShopCart
    0
  • Get support
  • Credentialing
  • Membership
  • Enterprise
  • Partnerships
  • Training and Events
  • Resources
Need help?Get support
©2026 ISACA. All rights reserved.
  • Certifications
    • CISA – Certified Information Systems Auditor
    • AAIA – Advanced in AI Audit
    • CISM – Certified Information Security Manager
    • AAISM – Advanced in AI Security Management
    • CRISC – Certified in Risk and Information Systems Control
    • AAIR – Advanced in AI Risk
    • CCOA – Certified Cybersecurity Operations Analyst
    • CGEIT – Certified in the Governance of Enterprise IT
    • CDPSE – Certified Data Privacy Solutions Engineer
    • CCA – CMMC Certified Assessor
    • CCI – CMMC Certified Instructor
    • CCP – CMMC Certified Professional
    • LCCA – Lead CMMC Certified Assessor Designation
    • ITCA
    • CET – Certified in Emerging Technology Certification
    • CSX-P – CSX Cybersecurity Practitioner Certification
  • Certificates
    • AI Fundamentals
    • Blockchain Fundamentals
    • Cloud Fundamentals
    • COBIT 19 Foundation
    • COBIT 2019 Design & Implementation
    • COBIT 5 Certificates
    • Cybersecurity Audit
    • Cybersecurity Fundamentals
    • Data Science Fundamentals
    • Digital Trust Ecosystem Framework Foundation Certificate
    • IoT Fundamentals
    • IT Audit Fundamentals
    • IT Risk Fundamentals
How can we help?
  • Find the right certification
  • Navigate Career Journey
  • Maintain or renew a certification
  • Verify a certification
  • Find the right certification
  • Navigate Career Journey
  • Maintain or renew a certification
  • Verify a certification
Trusted Partner for the DoW's CMMC ProgramISACA now serves as the official CAICO.
  • About Membership
    • Member Benefits
    • Membership Types
    • Browse Chapters
  • Get Involved
    • Advocacy
    • Author an Article
    • Chapter Events Calendar
    • ISACA Awards
    • SheLeadsTech
    • Volunteer
  • Maximize Your Membership
    • Career Center
    • Discounts & Savings
    • Free CPE
    • Free Resources
    • Member Experience Leadership Series
    • Mentorship
  • Engage Online Community
What would you like to do?
  • Join today
  • Earn free CPE
  • Browse chapters
  • Volunteer
  • Join today
  • Earn free CPE
  • Browse chapters
  • Volunteer
Personalize your ExperienceUpdate your ISACA profile today.
  • AI Solution
    • CMMI Artificial Intelligence Maturity (AIM)
  • Performance Improvement Solutions
    • CMMI Performance Solutions
    • CMMI Cybermaturity Assessment Platform
    • Medical Device Program
  • CMMI Appraisal Results
  • Team Training
    • Skills and Credentials
    • CMMI Training and Certification
  • License Enterprise Training
  • Enterprise Support
  • Contact Us
Empower Your Team to Empower Business GrowthCustomize your IT team training with ISACA.
  • Become a Partner
    • Accredited Training Organization
    • CMMI Partner
    • Academic Partner
    • CMMC Approved Training Provider (ATP)
    • Sponsor
    • Global Sponsors
  • Become an Enterprise Practitioner
    • Medical Device Appraiser
    • CMMC Certified Assessor (CCA)
    • CMMC Credentialed Instructor (CCI)
    • CMMI Certified Individual
Need to find a training partner
  • Certification Training Partners
  • COBIT Training Partners
  • Academic & Workforce Partners
  • CMMI Performance Improvement Partners
  • Certification Training Partners
  • COBIT Training Partners
  • Academic & Workforce Partners
  • CMMI Performance Improvement Partners
Over 100,000 People Were Trained By ISACA in 2022Become a Partner to capitalize on this demand.
  • Conferences
    • GRC Conference
    • ISACA Europe Conference
    • ISACA North America Conference
    • ISACA Virtual Conference
    • Student Summit
    • CMMI's Capability Creates
    • Call for Speakers
  • Training Week
  • Virtual Workshops
  • Training by Type
    • Virtual Summits
    • Webinars
    • Online Review Courses
    • Session Recordings
  • Training from an Accredited Partner
  • Training by Topic
    • All Training Topics
    • Artificial Intelligence
    • Cybersecurity
    • IT Audit
    • Certification Exam Preperation
    • Cobit
What would you like to do?
  • Earn CPE
  • Find Team Training
  • Explore Virtual Workshops
  • Find Chapter Events
  • Earn CPE
  • Find Team Training
  • Explore Virtual Workshops
  • Find Chapter Events
Featured Training15% Off AI Fundamentals Online Review Course
  • ISACA Resources
    • Digital Trust
    • ISACA Journal
    • Frameworks, Standards & Models
    • Insights & Expertise
    • ISACA Podcast
    • Videos
    • News & Trends
    • ISACA Now Blog
  • Engage Online Communities
  • COBIT
  • Resources by Topic
    • Artificial Intelligence
    • Cybersecurity
    • Emerging Technology
    • Governance
    • IT Audit
    • IT Risk
    • Privacy
  • Glossary
What can we help you find?
  • ISACA Now Blog
  • White Papers
  • Audit Programs
  • ISACA Now Blog
  • White Papers
  • Audit Programs
ISACA's IT Audit FrameworkThe newest edition is now available.
ISACA logo

1700 E. Golf Road, Suite 400, Schaumburg, Illinois 60173, USA  |  +1-847-660-5505

  • LinkedIn
  • Facebook
  • Instagram
  • YouTube
  • Support
    • Contact Us
    • Fraud Reporting
    • Bug Reporting
  • Careers
    • Career Journey
    • Career Center
    • Careers at ISACA
  • About Us
    • Who We Are
    • Newsroom
    • Participate & Volunteer
    • Leadership & Governance
    • Advocacy
    • ISACA Foundation
    • Code of Professional Ethics
  • Join / Renew
    • Renew
    • Professionals
    • Recent Graduates
    • Students
  • Credentialing
  • Membership
  • Enterprise
  • Partnerships
  • Training & Events
  • Resources
  • Bug Reporting
  • Contact Us
  • Terms
  • Privacy
  • Cookie Notice
  • Fraud Reporting

©2026 ISACA. All rights reserved.

HIPAA Audit Program

HIPAA Audit Program

ENEnglish
Download

HIPAA Audit Program

No image available

About this Tool and Audit Program


After completing check-out, your download will be available under MyISACA > Resources.

The Health Insurance Portability and Accountability Act (HIPAA) was created to provide privacy and security for protected health information (PHI). While HIPAA provides covered entities with standards for safeguarding PHI, the Health Information Technology for Economic and Clinical Health Act (HITECH) also plays a role in the security of PHI through its establishment of breach notification requirements.

Assurance that covered entities comply with HIPAA is through the efforts of the U.S Health and Human Services’ Office for Civil Rights (OCR). In addition to investigating complaints alleging non-compliance with HIPAA, the OCR also conducts audits of covered entities and their business associates. Resolution of complaints can either be the OCR facilitating compliance through corrective action or through issuance of formal findings. On the other hand, the outcome of an audit by the OCR may range from the OCR issuing guidance to the OCR initiating a compliance review, if the compliance deficiencies are significant enough.

Objective—Given the potential for OCR involvement in a covered entity’s HIPAA efforts, the objective of ISACA’s Health Insurance Portability and Accountability Act (HIPAA) Audit program is to provide a means for entities to internally evaluate their processes, controls, and policies.

Scope—Having identified any potential gaps between their practices and HIPAA’s requirements, corrective action can be taken prior to an OCR audit or compliance review. The audit areas include, but are not limited to, the following:

  • Authentication: There are risks associated with having sensitive information available to users as well as the security of the locations from which users request access. Accordingly, the audit program covers authentication associated with users as well as non-user authentication (such as a server that communicates electronically with another server that hosts sensitive information).
  • Access Management: An organization’s access control program must assure that data integrity and data confidentiality are not compromised as a result of unauthorized access. Given HIPAA’s objective of providing privacy for health information, access is an important part of the audit program.
  • Continuous monitoring: This is essential to ensure that access violations are identified, evaluated for risk, and escalated to the appropriate information security professional for investigation or addressed to prevent recurrence. The audit program addresses data integrity from a monitoring perspective and security incident response in the event an incident does occur.

As an IT audit and assurance professional, you are expected to customize this document for your unique assurance process environment. Use it as a review tool or starting point to modify for your purposes, rather than as a checklist or questionnaire. Keep in mind that to use this document for maximum effectiveness, you should hold the Certified Information Systems Auditor (CISA) designation or have the necessary subject matter expertise to conduct your assurance process while under the supervision of a professional who holds the CISA designation. Format: ZIP

Page Count
6
ISBN
9781604207200
Product SKU
WAPHIP
Non-members
US$45
OR
Members
US$25.00
+ membership fees
Save US$20
  • Earn 70+ FREE CPE credits a year
  • Gain exclusive access to job postings
  • Access the online ISACA Journal

You might also like

No image available
Database Audit Program

Database Audit Program

Members
$25
Non-members
$45
No image available
Blockchain Framework Audit Program

Blockchain Framework Audit Program

Members
FREE
Non-members
$45
No image available
Azure Audit Program

Azure Audit Program

Members
FREE
Non-members
$45
No image available
Biometrics Audit Program

Biometrics Audit Program

Members
$25
Non-members
$45
No image available
Blockchain Framework Audit Program

Blockchain Framework Audit Program

Members
FREE
Non-members
$45
No image available
IT Risk Management Audit Program

IT Risk Management Audit Program

Members
FREE
Non-members
$45
No image available
Azure Audit Program

Azure Audit Program

Members
FREE
Non-members
$45
No image available
Change Management Audit Program

Change Management Audit Program

Members
FREE
Non-members
$45
No image available
Information Security Management Audit Program

Information Security Management Audit Program

Members
FREE
Non-members
$45
No image available
VPN Security Audit Program

VPN Security Audit Program

Members
$25
Non-members
$45
No image available
Cloud Computing Management Audit Program

Cloud Computing Management Audit Program

Members
FREE
Non-members
$45
No image available
Blockchain Framework Audit Program

Blockchain Framework Audit Program

Members
FREE
Non-members
$45
No image available
Blockchain Preparation Audit Program

Blockchain Preparation Audit Program

Members
FREE
Non-members
$45
No image available
Mobile Computing Audit Program

Mobile Computing Audit Program

Members
$25
Non-members
$45
No image available
IT Risk Management Audit Program

IT Risk Management Audit Program

Members
FREE
Non-members
$45
No image available
Azure Audit Program

Azure Audit Program

Members
FREE
Non-members
$45
No image available
Azure Audit Program

Azure Audit Program

Members
FREE
Non-members
$45
No image available
European Cybersecurity Audit Program

European Cybersecurity Audit Program

Members
FREE
Non-members
$45
No image available
Shadow IT Audit Program

Shadow IT Audit Program

Members
FREE
Non-members
$45
No image available
IPv6 Security Audit Program

IPv6 Security Audit Program

Members
FREE
Non-members
$45
Resources
Shop AllResourcesHIPAA Audit Program