HIPAA internal audit checklist
A policy-facing checklist for internal HIPAA audits on bldrAgent projects, including governance, technical controls, and evidence collection guidance.
HIPAA internal audit checklist for bldrAgent projects
This document is designed for compliance officers, security teams, and internal auditors who need a repeatable way to review HIPAA controls for apps built on bldrAgent.
If you are configuring a new healthcare project, first read HIPAA compliance mode for healthcare apps.
Scope and audit objective
Use this checklist to verify that:
- HIPAA mode is properly enabled for regulated projects
- policy and operational safeguards are in place
- technical controls are configured and functioning
- evidence is captured for internal governance and external reviews
This checklist supports internal review workflows and is not legal advice. Your organization remains responsible for final compliance determinations.
Pre-audit preparation
Before running the audit, collect:
- Project inventory of apps that process PHI
- Applicable policy set (security, access control, incident response, retention)
- Assigned control owners (engineering, security, compliance, legal)
- Most recent risk assessment and remediation status
- BAA status and legal approvals
Reference documents:
Internal audit checklist
A) Governance and policy controls
- HIPAA-scoped projects are formally identified and documented
- Responsible owner is assigned for each HIPAA-scoped project
- Security policies for PHI handling are approved and current
- Workforce training records for PHI handling are maintained
- Risk assessment cadence is defined and current cycle completed
- Vendor and subprocessors used by the project are reviewed by legal/compliance
Evidence examples:
- Policy documents with approval dates
- Training completion report
- Current risk register and mitigation plan
B) Project setup and entitlement controls
- Project is created with HIPAA Compliance Mode enabled
- BAA acknowledgement is recorded for HIPAA mode usage
- Project is confirmed private by default
- HIPAA audit logging is enabled for the project
- Plan entitlement supports HIPAA mode and is documented
Evidence examples:
- Project configuration screenshots or exported settings
- BAA acceptance records and timestamps
- Subscription/plan record showing HIPAA entitlement
C) Access management controls
- Role-based access model is documented (least privilege)
- Access approvals are required for privileged roles
- Access recertification is performed on a defined cadence
- Offboarding process removes access within policy SLA
- Shared accounts are prohibited or tightly controlled
Evidence examples:
- Access matrix and role definitions
- Access review reports
- Joiner/mover/leaver workflow records
D) Data protection and technical safeguards
- Encryption in transit is enforced for application access
- Encryption at rest controls are documented and active
- Secrets and credentials are managed through approved secure mechanisms
- Audit logging retention and access controls are documented
- Backup and restore process is tested and results recorded
- Data retention and deletion policy is defined for PHI data classes
Evidence examples:
- Security architecture diagrams
- Log retention policy and storage controls
- Backup test reports and restore validation logs
E) Change management and release controls
- Compliance-impacting changes are reviewed before release
- Release validation includes HIPAA-related control checks
- Critical findings are tracked to closure with owners and deadlines
- Rollback or recovery plan exists for production regressions
Evidence examples:
- Change tickets and approval records
- Release checklists with HIPAA control sign-off
- Post-release validation reports
F) Incident response and breach readiness
- Incident response plan includes PHI-impact scenarios
- Escalation paths and on-call ownership are documented
- Breach assessment criteria and notification workflow are defined
- Tabletop exercise conducted within required period
- Corrective action tracking exists for incident findings
Evidence examples:
- Incident response runbooks
- Tabletop exercise notes and action items
- Corrective action register
Audit scoring and outcomes
Recommended rating model:
- Pass: all critical controls satisfied; medium/low gaps have dated remediation plans
- Conditional pass: one or more non-critical controls incomplete; compensating controls documented
- Fail: any critical control missing, ineffective, or without remediation owner
Critical controls typically include: HIPAA mode enablement, BAA acknowledgement, private project posture, access control enforcement, audit logging, and incident readiness.
Ongoing cadence and reporting
Set a recurring audit rhythm for HIPAA-scoped projects:
- Monthly: control drift checks and access recertification deltas
- Quarterly: full control review and evidence refresh
- Annually: policy and risk framework review with executive sign-off
Track all gaps in a remediation register with:
- severity
- owner
- target completion date
- verification method
- closure evidence
Recommended companion documents
- HIPAA compliance mode for healthcare apps
- Privacy and security
- Deleting user data
- Using the Workflow Board
Use this checklist as your baseline internal standard, then extend it with organization-specific legal, contractual, and regulatory obligations.
