May 8, 2026
Cheri Hotman, Managing Partner of Hotman Group, joins Hotman Group practitioners Brittany Schroeder, Ja'Kayla Lovelace, and Tanya Wade to examine an anonymized HIPAA compliance audit report and show why a report that says “100% compliant” may still leave important questions unanswered about scope, evidence, risk, testing, and whether controls are actually working in practice.
Watch the Hotman Group team walk through a real, fully anonymized HIPAA audit report and explain what experienced cybersecurity and GRC practitioners look for before deciding whether an audit report can actually be relied upon.
A clean audit report does not automatically mean an organization is secure, mature, or even operating its controls consistently. Before relying on a compliance report, organizations should understand what was actually in scope, what evidence was reviewed, how controls were tested, whether operating effectiveness was evaluated, and whether the report provides enough information to support a meaningful risk decision.
A report filled with green checkmarks can create confidence without providing assurance. That is especially dangerous in third-party risk management, where the entire purpose of reviewing an external audit is to help determine whether using a supplier, SaaS platform, or service introduces acceptable risk.
Compliance evidence should reduce uncertainty. If the report cannot tell you what was tested, where the relevant data lives, what systems were included, and whether the controls actually work, additional due diligence may still be necessary.
A clean audit is not inherently suspicious. Organizations can absolutely perform well, maintain strong controls, and complete an audit without material exceptions.
But an experienced practitioner may still pause when every control is marked conforming, there are no findings, there are no opportunities for improvement, and the report offers little explanation about what was tested.
“If everything is fine, where do you focus your time and budget?”
— Brittany Schroeder
Real cybersecurity programs involve change, exceptions, imperfect processes, competing priorities, new technologies, employee turnover, evolving threats, and controls that need continual improvement. A useful assessment should help an organization understand that reality rather than simply declaring everything green.
A report that creates the impression that nothing needs attention can even make it harder for security and GRC leaders to secure budget for improvements because executives may reasonably ask why additional investment is necessary if the audit says everything is already fine.
One of the first things Brittany identifies in the report is a lack of meaningful scope.
Listing portions of HIPAA or naming the regulatory requirements used during an assessment describes the criteria or methodology. It does not explain what the auditor actually examined.
A useful scope should make it possible to understand questions such as:
Without that information, a reader cannot confidently determine what the audit results actually apply to.
HIPAA places significant emphasis on understanding risk to protected health information. That begins with knowing where the relevant information exists, where it moves, which systems process it, and who can access it.
A statement that an organization performed a risk analysis is therefore only the beginning. A reader should be able to understand whether the assessment actually addressed the organization's environment and risks.
That same principle applies well beyond HIPAA. A meaningful cybersecurity risk assessment requires organizations to understand what they are protecting, how the environment works, what could go wrong, and which risks deserve priority.
One recurring concern in the session is vague evidence language.
A phrase such as “evidence reviewed and deemed sufficient” may tell the reader that an auditor looked at something, but it does not explain what the auditor actually examined or how the evidence supported the conclusion.
For physical access controls, for example, relevant evidence might involve badge records, visitor logs, access reviews, facility procedures, or direct observation. Those are very different from simply pulling automated evidence through an API.
The evidence should make sense for the control being tested.
Sometimes API-based evidence is exactly what an auditor needs. Automation can efficiently retrieve configuration information, vulnerability data, logs, training completion records, and other technical evidence.
The problem is assuming that because evidence can be collected automatically, the entire control can also be validated automatically.
Consider security awareness training. An integration with a training platform may confirm that certain users completed a course. It may not prove that the population was complete.
An auditor may still need to ask:
Technology can make evidence collection more efficient. It should not eliminate professional judgment. The same principle applies when organizations select and use GRC technology: the tool should enable the program, not substitute for the program.
A well-designed control describes what should happen. Operating effectiveness asks whether it actually happens consistently in the real environment.
Ja'Kayla uses contingency planning as an example. A policy may say that the organization periodically tests and revises its contingency plan. That demonstrates intent and may help establish that a control has been designed.
But to evaluate whether the control operates effectively, an auditor would want evidence such as:
“It's like passing a test before you check all the answers.”
— Brittany Schroeder
Policies matter. Documentation matters. But neither proves that the organization can perform the activity when it counts.
Organizations frequently request external compliance reports because they do not have the time, resources, or access necessary to personally audit every supplier they use.
A strong independent audit can reduce that burden. Instead of reproducing the auditor's work, the customer can evaluate the report and use it as part of the third-party risk decision.
But that system only works when the report itself is reliable.
Third-party risk management is not third-party checkbox management. The purpose of reviewing an audit report is to understand and manage risk.
If the report does not provide sufficient assurance, the customer may still need questionnaires, interviews, additional documentation, technical validation, contractual protections, compensating controls, or its own deeper due diligence.
An audit report is not only something customers and regulators may use. It can influence internal decisions as well.
If leadership sees a report showing every control as conforming with no meaningful findings, the organization may struggle to justify investments that practitioners already know are necessary.
A useful audit should help leadership understand the current state of the program, remaining risks, and where additional investment can strengthen the organization. Declaring everything perfect can unintentionally block that progress.
No.
An audit provides information about a defined scope, criteria, timeframe, testing approach, and set of controls. Its value depends heavily on how those elements were defined and evaluated.
That is why organizations can pass a cybersecurity or compliance audit and still have meaningful security vulnerabilities.
The goal of cybersecurity is not simply to produce a clean report. It is to protect people, data, systems, operations, and the organization from risk.
A good audit report should make it possible to answer questions like these:
It can be, but a clean report should still be evaluated in context. Organizations should understand the audit scope, evidence, testing procedures, and depth of review before relying on the conclusion.
The scope should make clear which systems, data, workflows, assets, environments, and relevant business processes were evaluated, including where protected health information exists and how it moves through the environment.
GRC platforms can automate important parts of evidence collection, control mapping, workflow, and reporting. They do not eliminate the need for professional judgment, validation, contextual analysis, or testing processes that cannot be demonstrated through automated evidence alone.
Control design describes how a control is intended to work. Operating effectiveness evaluates whether the control actually performs as designed over time in the real environment.
Yes. An audit evaluates specific criteria within a defined scope and period. Risks can exist outside that scope, arise after the audit period, or remain even when the assessed controls technically conform.
Vendor audit reports can provide independent assurance about a supplier's control environment and reduce the need for customers to conduct a full audit themselves. The report is useful only when it contains enough information and reliable testing to support the customer's risk decision.
This article is based on a live Hotman Group practitioner discussion featuring Cheri Hotman, Managing Partner of Hotman Group, Brittany Schroeder, Ja'Kayla Lovelace, and Tanya Wade.
Using a real but fully anonymized HIPAA compliance audit report, the team examines how experienced practitioners evaluate scope, risk analysis, audit evidence, automation, control testing, operating effectiveness, third-party risk, and whether an external audit actually provides enough assurance to be relied upon.
Brittany brings healthcare and HIPAA experience to the discussion, while the team collectively draws on practical cybersecurity, GRC, audit, and client-program experience to demonstrate the critical thinking required beyond a compliance checklist.
Organizations may need additional support when an audit result looks clean on paper but does not provide enough clarity about what was actually tested, what risk remains, or whether controls are operating effectively. Hotman Group can help when:
Hotman Group does not replace the independent auditor. HG helps organizations evaluate what assurance evidence actually demonstrates, identify remaining risk, strengthen controls, remediate weaknesses and improve readiness and operating effectiveness.
Talk with Hotman Group about strengthening audit readiness, evidence or control effectiveness
Hotman Group is a cybersecurity and Cyber GRC professional-services firm that helps organizations diagnose, design, build, remediate, implement, operate and mature cybersecurity programs. HG provides hands-on vCISO and vGRC leadership, supports multi-framework environments, and helps organizations select and implement GRC technology while connecting cybersecurity decisions to business risk and strategy.
Rather than treating an audit result as the end goal, Hotman Group helps organizations understand what the evidence actually shows, identify meaningful risk, strengthen controls, and operate cybersecurity and compliance programs that work in practice.
The objective is not simply to pass the next audit. It is to build a program that protects the organization before, during, and after the audit is complete.