45 CFR Part 164 · Security Rule audits · Philadelphia, PA

Compliance that would
survive an actual attacker.

Independent HIPAA Security Rule audits for healthcare organizations and the vendors who hold their data — administrative, physical and technical safeguards assessed control by control, by a working enterprise security engineer rather than a checklist vendor.

CEHSecurity+Splunk Core Seven years of enterprise security engineering across asset management, energy and enterprise software.

What you actually receive

An audit you can hand to counsel, a plan you can hand to engineering.

Findings tied to the citation

Every finding is written against the implementation specification it fails — the exact subsection, and whether that specification is Required or Addressable under the rule. No generic "improve access control" filler.

Evidence and severity, not attestation

Controls are tested where they can be tested — configuration, logging, authentication, transmission — and the evidence is recorded. A control nobody verified is reported as unverified, because that is what it is.

Remediation sequenced by risk

The plan is ordered by what an attacker reaches first and what an investigator would ask for first — not by the order the regulation happens to be printed in. Addressable specifications include the documented rationale you are required to keep.

Audit scope

The Security Rule, taken one specification at a time.

The scope below is the standard engagement for a covered entity or business associate. Depth and system count are set during scoping, so every engagement is quoted individually rather than sold as a package.

§164.308

Administrative safeguards

Scoped per engagement
  • Risk analysisRequired
  • Risk managementRequired
  • Sanction policyRequired
  • Information system activity reviewRequired
  • Assigned security responsibilityRequired
  • Workforce clearance & termination proceduresAddressable
  • Access authorization, establishment & modificationAddressable
  • Security awareness & training, log-in monitoringAddressable
  • Security incident response & reportingRequired
  • Contingency plan, backup & disaster recoveryRequired
  • Business associate contractsRequired
§164.310

Physical safeguards

Scoped per engagement
  • Facility access controls & contingency operationsAddressable
  • Facility security plan, access control & validationAddressable
  • Workstation useRequired
  • Workstation securityRequired
  • Device & media disposalRequired
  • Media re-useRequired
  • Accountability & data backup before movementAddressable
§164.312

Technical safeguards

Scoped per engagement
  • Unique user identificationRequired
  • Emergency access procedureRequired
  • Automatic logoffAddressable
  • Encryption & decryption at restAddressable
  • Audit controlsRequired
  • Integrity & ePHI authentication mechanismAddressable
  • Person or entity authenticationRequired
  • Transmission security & encryption in transitAddressable
§164.314 / .316

Organizational requirements & documentation

Scoped per engagement
  • Business associate contract contentRequired
  • Group health plan requirementsRequired
  • Written policies & proceduresRequired
  • Six-year documentation retentionRequired
  • Periodic review & update of documentationRequired

Extended scope

AI and LLM systems that touch PHI

Most auditors have no test for this yet. It is the work I do in my day job.

Retrieval-augmented assistants, agent frameworks and copilots are reaching into clinical and claims data faster than anyone is writing controls for them. In enterprise security environments I have built and secured RAG-based AI agents in Python, and tested them for indirect prompt injection, poisoned knowledge-base retrieval, sensitive-data exposure, unauthorized mailbox access and excessive agency.

  • 01Indirect prompt injection & untrusted-content labeling
  • 02Poisoned retrieval & knowledge-base integrity
  • 03Sensitive-data exposure in model responses
  • 04Excessive agency & least-privilege tool access
  • 05Canary detection & session attack-chain correlation
  • 06OWASP LLM Top 10 risk classification

Findings arrive the same way the rest of the audit does: structured telemetry, a detection that proves the control works, and a written control gap where it does not.

Scope my audit

Method

How the engagement runs.

  1. I

    Scope

    Where PHI actually lives, who touches it, which systems and vendors are in the boundary, and which safeguards apply to you as a covered entity or business associate.

  2. II

    Collect

    Policy and procedure review, configuration and identity review, log and telemetry review, and interviews with the people who operate the controls day to day.

  3. III

    Test

    Technical validation of the controls that can be validated — authentication, logging coverage, encryption, access boundaries — instead of taking a policy document's word for it.

  4. IV

    Report

    A findings report written against the citations, a documented rationale for every addressable specification, and a remediation plan ordered by real risk. Then a walkthrough with your team.

Navkaran Randhawa
Navkaran Randhawa · Philadelphia, PA

Who audits

The person who scopes it is the person who tests it.

I am a senior security engineer working in enterprise detection engineering, threat hunting and insider-threat programs — currently on contract with Invesco, previously with Exelon and Serrala. Day to day that means building the detections and running the hunts that catch the behavior a compliance checklist only describes in the abstract.

Before security I served three and a half years in the US Army as an 11B infantryman, stationed in Vilseck, Germany, and read Criminology at Penn State. The through-line is the same one an audit needs: go and look, write down what is actually there, and say so plainly.

Healthcare audits get the same treatment. You get an engineer who has worked inside regulated enterprise environments, not a template with your logo on it.

  • 7years in enterprise security
  • 4industry certifications
  • 3regulated enterprise environments
  • 11BUS Army infantry veteran

Credentials

Verifiable, and dated.

CredentialIssuerIssued
Certified Ethical Hacker (CEH)EC-CouncilNov 2022
CompTIA Security+CompTIAOct 2022 Verify
Splunk Core Certified UserSplunkDec 2022
Google IT Support Professional CertificateGoogleAug 2022
BA, CriminologyPenn State University2015–2019

Working knowledge

  • GRC
  • Regulatory compliance
  • NIST CSF
  • NIST 800-53
  • ISO 27001
  • Risk & vulnerability assessment
  • Security controls
  • Incident response
  • Insider threat detection
  • DLP
  • Cloud security
  • Microsoft Azure
  • Microsoft Sentinel
  • Splunk
  • SIEM
  • SOAR
  • KQL
  • Detection engineering
  • Threat hunting
  • MITRE ATT&CK
  • Malware analysis
  • Web application security
  • Network security
  • Log analysis
  • Agentic AI
  • AI/ML security
  • LLM security
  • OWASP LLM Top 10

Track record

Where the practice comes from.

  1. Oct 2024 — Present1 yr 11 mos

    Security Analyst · Invesco

    Security monitoring · AI/ML security · Detection engineering · Insider threat detection

  2. Oct 2023 — Sep 20241 yr

    Cyber Security Engineer · Exelon

    Vulnerability assessment · Endpoint security · SIEM · Security policies · Security controls

  3. Mar 2020 — Sep 20233 yrs 7 mos

    Security Analyst · Serrala

    Web application security · Endpoint security · Intrusion detection & prevention · Security monitoring · SIEM

  4. Feb 2019 — Feb 20201 yr 1 mo

    Security Analyst, contract · Elevate Cyber

    Independent security engagements

  5. Apr 2012 — Aug 20153 yrs 5 mos

    11B Infantryman · US Army

    Vilseck, Germany · Team leadership · Inventory & project management

Next step

Find out what an auditor would actually find.

Tell me what you run, where PHI sits and what deadline you are working against. You will get a straight answer on scope and whether an audit is even the right next move for you.