Skip to main content
Category: OCR Enforcement and Penalties

On-Site Audit

Also known as: Onsite Audit, On-Site Auditing, On-Site Review
Simply put

An on-site audit is an audit in which the auditor performs review activities at the physical location of the organization being audited, rather than reviewing materials remotely. During an on-site audit, the audit team typically gathers necessary documents, interviews key staff, and observes how processes actually work in practice. This in-person approach can reveal things that documentation alone may miss, such as how physical processes and controls are actually implemented.

Formal definition

An on-site audit is an audit engagement in which the auditor conducts verification activities, such as inspection, examination, document collection, staff interviews, and observation of operational processes, at the physical location of the auditee. It is generally distinguished from a remote audit by the auditor's physical presence at the site, which enables direct verification of physical process control implementation and other factors that documentation review may not surface. In a compliance context, on-site work typically includes copying relevant documents or information, conducting interviews with key personnel, and reviewing operational processes to assess conformance against applicable requirements or standards. Note: The scope, procedures, and criteria of any on-site audit depend on the governing framework or agreement, which readers should confirm against the applicable authority; the evidence provided here does not address HIPAA- or HITRUST-specific audit requirements.

Why it matters

On-site audits matter because some aspects of an organization's operations simply cannot be verified through documents alone. Written policies may describe how a process is supposed to work, but an auditor physically present at a location can observe how procedures are actually carried out, how staff behave in practice, and how physical controls are implemented day to day. This direct observation can surface gaps between documented intent and operational reality that a remote, document-only review may not reveal.

In a compliance context, the value of on-site work lies in the auditor's ability to gather primary evidence firsthand, collecting relevant documents, interviewing key personnel, and reviewing operational processes as they occur. These activities allow the audit team to assess conformance against applicable requirements or standards with a fuller picture of the organization's actual practices, rather than relying solely on self-reported materials.

Readers should note that the scope, procedures, and evaluation criteria of any on-site audit depend entirely on the governing framework or contractual agreement under which it is conducted. The general definition here does not address HIPAA- or HITRUST-specific audit requirements; where such frameworks apply, on-site audit expectations should be confirmed against the applicable authority or the current version of the relevant standard.

Who it's relevant to

Compliance and Privacy/Security Officers
Officers preparing their organization for an on-site audit should ensure that documented policies align with actual operational practice, since auditors physically present can observe discrepancies that paper alone would not reveal. They typically coordinate document collection, staff availability for interviews, and access to areas where processes are performed.
Auditors and Assessors
Audit professionals conducting on-site work rely on direct inspection, examination, staff interviews, and observation of operational processes to gather primary evidence. They should confirm the scope, procedures, and criteria against the governing framework or agreement before the engagement.
Operational and Front-Line Staff
Key personnel are often interviewed during on-site audits and may have their day-to-day handling of processes observed directly. Their descriptions of how work actually happens contribute to the auditor's assessment of conformance.
Legal and Contract Managers
Because an on-site audit's scope and criteria are frequently defined by contract or a governing framework, those responsible for agreements should understand what an on-site review entails and verify obligations against the applicable authority, particularly where framework-specific requirements may apply.

Inside On-Site Audit

Purpose and Scope
An on-site audit is an in-person examination conducted at a covered entity's or business associate's physical location to assess compliance with applicable HIPAA requirements. In the HIPAA context, such reviews are generally associated with HHS Office for Civil Rights (OCR) oversight activities, though internal audits and third-party assessments may also occur on-site. The specific scope depends on the authority conducting the review and the objectives established for the engagement.
Documentation Review
On-site auditors typically examine written policies and procedures, risk analyses, business associate agreements, workforce training records, and other documentation required under the Privacy Rule, Security Rule, and Breach Notification Rule. Because the Security Rule requires documentation of certain safeguards and decisions, the availability and completeness of these records is commonly a focus.
Physical Safeguard Observation
A distinguishing feature of an on-site audit relative to a remote review is the ability to directly observe physical safeguards under the Security Rule, such as facility access controls, workstation security, and device and media controls protecting electronic protected health information (ePHI). The Privacy Rule's protections for PHI in all forms, including paper and oral, may also be observed on-site.
Personnel Interviews
Auditors may interview workforce members, privacy and security officers, and other staff to evaluate awareness of policies and the extent to which documented procedures are followed in practice. This helps assess operational compliance beyond what documentation alone reveals.
Technical and Administrative Safeguard Assessment
For ePHI, an on-site audit may evaluate technical safeguards (such as access controls and audit controls) and administrative safeguards (such as the risk management process and workforce security), including whether required implementation specifications are met and whether addressable specifications have been implemented or the decision not to implement has been reasonably documented.
Findings and Follow-up
An on-site audit generally concludes with findings that identify gaps or areas of concern. Depending on the conducting authority, this may lead to corrective action, further review, or, in the case of OCR enforcement activity, other regulatory outcomes. Readers should confirm specific processes against current OCR guidance or the terms of the particular engagement.

Common questions

Answers to the questions practitioners most commonly ask about On-Site Audit.

Does an on-site audit only apply to covered entities, or can business associates be audited too?
The scope is not limited to covered entities. Business associates, and in many arrangements their subcontractors, can also be subject to on-site audits depending on the auditing authority and the relationship structure. Obligations generally flow through business associate agreements, so an on-site review may examine how a business associate meets the responsibilities it has taken on contractually and under HIPAA. Readers should confirm the specific scope with the entity conducting the audit, since who may be audited and under what authority can vary.
Does passing an on-site audit mean an organization is fully HIPAA compliant?
No. An on-site audit is generally a point-in-time assessment of specific practices, documentation, and controls within a defined scope. It does not by itself guarantee ongoing HIPAA compliance or ensure that all future breaches are prevented. Compliance is a continuing obligation, and matters outside the audit's scope, as well as additional requirements under state law or the HITECH Act, may still apply. A favorable audit result should be treated as evidence about the reviewed areas, not as a blanket certification.
What kinds of materials are typically requested during an on-site audit?
In most cases, auditors request documentation such as policies and procedures, risk analyses, training records, business associate agreements, and evidence that administrative, physical, and technical safeguards are implemented. Depending on scope, they may review both Privacy Rule materials (covering PHI in all forms) and Security Rule materials (covering ePHI). The exact document list varies by the auditing authority and the focus of the review, so organizations should clarify requested items in advance and verify expectations against current guidance.
How should an organization prepare its staff for an on-site audit?
Preparation typically includes ensuring relevant personnel understand their roles, confirming that policies and procedures are current and accessible, and verifying that documentation supporting safeguards can be produced. It is generally advisable to identify points of contact who can respond to auditor questions and to review how required and addressable implementation specifications have been handled, since addressable does not mean optional. Because audit approaches differ, staff should be briefed on the specific scope and expectations communicated by the auditing authority.
How does an on-site audit differ from a HITRUST CSF assessment?
An on-site HIPAA audit is generally connected to compliance with the HIPAA Rules, which are enforced for covered entities and business associates by HHS OCR. A HITRUST CSF assessment is conducted under a private, certifiable control framework maintained by HITRUST. HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. An organization may use a HITRUST assessment to support its control posture, but it should not treat that assessment as a substitute for meeting HIPAA obligations directly.
What should an organization do with findings from an on-site audit?
Findings are typically reviewed to identify gaps in policies, documentation, or safeguards, followed by developing and tracking a remediation or corrective action plan. Because an audit reflects a point in time, organizations generally treat findings as inputs to ongoing risk management rather than a one-time fix. Where findings touch areas subject to state law or the HITECH Act, additional requirements may apply. Organizations should confirm any remediation timelines and expectations with the auditing authority and against current regulatory guidance.

Common misconceptions

An on-site audit only reviews computer systems and electronic data.
While the Security Rule governs only ePHI, the Privacy Rule covers PHI in all forms, including paper and oral. An on-site audit may therefore examine physical records, verbal disclosure practices, and physical safeguards in addition to electronic systems.
Holding a HITRUST CSF certification means an on-site HIPAA audit will confirm compliance or can be skipped.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification does not by itself establish HIPAA compliance and does not exempt an organization from an OCR on-site audit or enforcement activity. HIPAA is enforced by HHS OCR independently of any HITRUST assessment.
Addressable implementation specifications will not be examined during an on-site audit because they are optional.
Addressable does not mean optional. During an on-site review, an auditor may evaluate whether an addressable specification was implemented or, alternatively, whether the entity documented a reasonable basis for not implementing it and adopted an equivalent measure where appropriate.

Best practices

Maintain current, complete documentation of policies, procedures, risk analyses, and business associate agreements so that materials can be produced promptly during an on-site review.
Verify that decisions regarding addressable implementation specifications are documented, including the rationale where a specification was not implemented and any alternative measures adopted.
Confirm that observable physical safeguards, such as facility access controls and workstation and device security, are consistent with written policies before an auditor arrives.
Prepare workforce members and designated privacy and security officers to accurately describe actual practices, since interviews may reveal gaps between documentation and operations.
Do not rely on HITRUST CSF certification or any single control framework as evidence of HIPAA compliance; treat them as complementary and confirm requirements against the current regulation.
Consult current HHS OCR guidance to confirm the specific scope, process, and follow-up expectations for any audit, and account for state law or HITECH Act provisions that may impose additional requirements beyond HIPAA.