Findings tied to the citation
Every finding is written against the implementation specification it fails — the exact subsection, and whether that specification is Required or Addressable under the rule. No generic "improve access control" filler.
45 CFR Part 164 · Security Rule audits · Philadelphia, PA
Independent HIPAA Security Rule audits for healthcare organizations and the vendors who hold their data — administrative, physical and technical safeguards assessed control by control, by a working enterprise security engineer rather than a checklist vendor.
CEHSecurity+Splunk Core Seven years of enterprise security engineering across asset management, energy and enterprise software.
What you actually receive
Every finding is written against the implementation specification it fails — the exact subsection, and whether that specification is Required or Addressable under the rule. No generic "improve access control" filler.
Controls are tested where they can be tested — configuration, logging, authentication, transmission — and the evidence is recorded. A control nobody verified is reported as unverified, because that is what it is.
The plan is ordered by what an attacker reaches first and what an investigator would ask for first — not by the order the regulation happens to be printed in. Addressable specifications include the documented rationale you are required to keep.
Audit scope
The scope below is the standard engagement for a covered entity or business associate. Depth and system count are set during scoping, so every engagement is quoted individually rather than sold as a package.
Extended scope
Most auditors have no test for this yet. It is the work I do in my day job.
Retrieval-augmented assistants, agent frameworks and copilots are reaching into clinical and claims data faster than anyone is writing controls for them. In enterprise security environments I have built and secured RAG-based AI agents in Python, and tested them for indirect prompt injection, poisoned knowledge-base retrieval, sensitive-data exposure, unauthorized mailbox access and excessive agency.
Findings arrive the same way the rest of the audit does: structured telemetry, a detection that proves the control works, and a written control gap where it does not.
Method
Where PHI actually lives, who touches it, which systems and vendors are in the boundary, and which safeguards apply to you as a covered entity or business associate.
Policy and procedure review, configuration and identity review, log and telemetry review, and interviews with the people who operate the controls day to day.
Technical validation of the controls that can be validated — authentication, logging coverage, encryption, access boundaries — instead of taking a policy document's word for it.
A findings report written against the citations, a documented rationale for every addressable specification, and a remediation plan ordered by real risk. Then a walkthrough with your team.
Who audits
I am a senior security engineer working in enterprise detection engineering, threat hunting and insider-threat programs — currently on contract with Invesco, previously with Exelon and Serrala. Day to day that means building the detections and running the hunts that catch the behavior a compliance checklist only describes in the abstract.
Before security I served three and a half years in the US Army as an 11B infantryman, stationed in Vilseck, Germany, and read Criminology at Penn State. The through-line is the same one an audit needs: go and look, write down what is actually there, and say so plainly.
Healthcare audits get the same treatment. You get an engineer who has worked inside regulated enterprise environments, not a template with your logo on it.
Credentials
Working knowledge
Track record
Next step
Tell me what you run, where PHI sits and what deadline you are working against. You will get a straight answer on scope and whether an audit is even the right next move for you.