If you wait until after close to test HIPAA privacy risk, you give up price leverage and add avoidable EBITDA drag. I would treat this review as a pre-close workstream that ends with 3 outputs: a scoped PHI map, a ranked gap list, and a costed 100-day fix plan.
For a PE buyer or portfolio operator, the point is simple: turn privacy risk into deal terms. In this article, I focus on the parts that change value fast:
- Scope first - confirm whether the target is a covered entity, business associate, or hybrid entity, then map where PHI moves
- Test proof, not paper - review notices, request logs, training records, BAAs, incident files, and policy dates
- Rank findings by deal impact - separate items that can affect OCR exposure, insurance, or integration from lower-risk admin gaps
- Put a dollar figure on fixes - missed compliance work can run $300,000 to $2,000,000 post-close, and HIPAA penalties can reach $2,177,880 per year for the same violation
- Assign owners before Day 1 - each issue should have a deadline, budget, and owner across legal, IT, compliance, and leadership
I also flag a few repeat problem areas that buyers should not gloss over: missing BAAs, weak Right of Access workflows, stale policy sets, poor training records, and no proof that controls work in practice. For multi-state targets, I would also check state privacy rules that go past HIPAA and can change scope and fix cost.
The short version: if the diligence file does not end with a priced remediation plan and a first-100-day action list, it is not done.
HIPAA Diligence for PE Buyers: 4-Step Pre-Close Process
Master HIPAA Compliance: The Ultimate 2025 Checklist for Healthcare Organizations
sbb-itb-97f6a47
1. Scope the target's HIPAA privacy exposure
Start with the boundary. Before the team reviews policies, it needs a clear answer to 1 question: what does HIPAA cover at this target? If you get that wrong, you either waste cycles on areas that do not belong in scope or miss risk that should affect price and deal terms.
Entity type, PHI flows, and business model boundaries
The first step is to define the target's HIPAA status.
A covered entity (CE) is a health plan, healthcare clearinghouse, or provider that transmits health information electronically for standard transactions such as claims or eligibility checks. A business associate (BA) handles PHI for a covered entity. That group can include cloud storage providers, billing companies, EHR vendors, and consultants. A hybrid entity has both covered and non-covered functions, so only the named health care components fall under HIPAA. Check that this designation is documented and that PHI is kept separate from non-covered business units.
Next, map how PHI moves across systems, vendors, and business units. Do not accept management statements at face value. Test the map against cloud tenant inventories, IAM access lists, and network diagrams. Shadow IT matters here. Unsanctioned cloud apps and AI tools can create PHI flows that never made it into the official record. Flag any subscription that does not line up with the approved vendor registry.
Also check whether the PHI map separates patient, member, employee, and consumer data. When teams lump those categories together, they either pull too much into scope or miss areas that carry exposure.
State law and adjacent requirements that widen scope
HIPAA sets the floor. It is not the ceiling. If the target operates across multiple states or handles consumer health data, widen the review beyond HIPAA. Some state laws push the scope further than OCR does.
| State Law | Key Expansion Beyond HIPAA |
|---|---|
| Texas HB 300 | Broadly defines "covered entity" to include any entity handling PHI in Texas; requires state-specific employee training; penalties can reach $1.5 million per year for patterns of noncompliance [3] |
| California CMIA/CPRA | Includes a private right of action and stricter consent requirements than HIPAA [3] |
| Washington My Health My Data Act | Covers health-adjacent data from wellness apps and similar sources that fall outside the traditional HIPAA PHI definition [3] |
For multistate targets, these overlays increase both scope and remediation cost. Patient-portal pixels and marketing tags should also sit inside scope because they can expose PHI-adjacent data.
With scope fixed, move to the controls that govern those PHI paths.
2. Review core privacy controls and collect evidence
Test controls in practice. Once PHI flows and entity boundaries are mapped, the next step is simple: verify that the target does what its policies say it does.
Policies, notices, and patient-rights procedures
Start with the Notice of Privacy Practices (NPP). Pull the target's website and confirm the NPP is posted, current, and matches how the business uses PHI and communicates patient rights. Then review the policy library. Every document should include an effective date, review date, and version history. If the library is stale or the policies are unsigned, treat that as paper compliance, not operating compliance.
Next, request logs for Right of Access requests, amendment requests, and disclosure accounting logs. Each log should show the request date, response date, and denial rationale. OCR's Right of Access initiative has generated more than 50 financial penalties since 2019, with fines ranging from $3,500 to $240,000 [3]. If the target cannot produce these logs, assume the workflow exists on paper only.
Governance, training, and vendor documentation
Ask for the privacy officer designation and proof of authority. You want to see that the named person is not just listed in a policy, but is actively approving policies, training, and breach assessments. If that approval trail is missing, governance is weak no matter what the org chart says.
Training records should show dates, topics, and acknowledgments. Role-based training matters. A front-desk employee and an IT administrator should not be completing the same course. Missing completions, partial attendance, or no follow-up records usually point to weak execution.
For vendor oversight, reconcile the BAA inventory against cloud spend, finance records, and corporate card data. This is where gaps show up. Shredding vendors, cloud storage providers, email encryption services, and data analytics firms are often absent from BAA registries. Don't stop at the inventory. Ask for proof of active oversight, such as completed security questionnaires or audit reports.
Diligence document request list
These records help a buyer price remediation and set the first-100-day plan. The point is to separate written policy from day-to-day behavior.
| Document Category | What to Request | Evidence of Actual Practice |
|---|---|---|
| Policies & Procedures | Full policy library with version history | Signed approval pages, annual review dates, and evidence of updates |
| Notice of Privacy Practices | Current NPP | Website posting and patient acknowledgment records |
| Workforce Training | Training logs for all staff, last 3 years | Dates, topics covered, and attendee signatures or e-acknowledgments |
| Business Associate Agreements | Full BAA inventory, including subcontractors | Security questionnaires and audit reports for key vendors |
| Patient Rights Logs | Access, amendment, and disclosure accounting logs | Response dates vs. request dates and denial rationales |
| Incident & Breach Records | All reported and non-reported incidents | Four-factor risk assessments for each incident |
| Sanctions Log | Records of workforce sanctions for privacy violations | Documented disciplinary actions; a blank log in a large organization is a warning sign |
| Risk Analysis & Remediation | Most recent Security Risk Analysis and Risk Management Plan | Findings prioritized and remediated |
Request the full package in one pass. Slow delivery, partial delivery, or repeated back-and-forth is a finding on its own.
Then convert the output into a gap table and rank each issue by deal impact.
3. Build a HIPAA gap analysis and risk ranking from findings
Build the gap register as soon as document review, interviews, and sampling are done. The goal is simple: compare the target’s current state against HIPAA and the buyer’s standards, then rank each gap by deal impact. Use the evidence package from Section 2 as the source file for this work.
Gap analysis table for target comparison
Use a standard table so teams can scan findings fast and compare targets on the same basis. Each row should show the requirement, current state, the exact gap, risk level, evidence source, fix cost, and timing.
| Requirement | Current State | Gap | Risk Level | Evidence Source | Est. Fix Cost | Timing |
|---|---|---|---|---|---|---|
| Security Risk Analysis (SRA) | Generic, outdated template | Not tailored or refreshed after system changes | Material | Policy library, IT interviews | High | Pre-close |
| Business Associate Agreements | BAA inventory does not match active vendors | Vendors handling PHI lack a BAA | Material | Finance records, vendor registry | Moderate | Day 1-30 |
| MFA for PHI systems | MFA on some systems only | Not deployed universally | Material | IT configuration screenshots | High | Day 1-60 |
| Patient access requests | No request-tracking log | No documented response log | Moderate | Interviews, records requests | Low to Moderate | First 100 days |
| Workforce training records | Generic annual training for all staff | No role-based training records | Moderate | Training logs, HR records | Low to Moderate | First 100 days |
| Policy review cycle | Policies last reviewed years ago | No annual review or version history | Minor | Policy library | Low | Post-100 days |
How to rank findings by deal impact
Start with the gaps that can change the deal. Material findings create direct regulatory exposure, can block cyber insurance, or suggest an active or undisclosed breach. A missing Security Risk Analysis sits at the top of that group. OCR cites risk-assessment failures in over 70% of enforcement actions [4]. Premera Blue Cross agreed to a $6.85 million settlement with the OCR for failing to conduct an adequate risk assessment, which contributed to a breach affecting 10.4 million individuals [4].
Moderate findings usually do not break the deal, but they do create scrutiny risk and slow integration. Most can be fixed in the first 100 days if ownership is clear. Incomplete BAA coverage is a good example. A $1.55 million OCR settlement against North Memorial Health Care stemmed from a contractor accessing records of 289,904 patients without a BAA in place [3]. Missing BAAs are not a paperwork issue. They create direct liability exposure.
Minor findings tend to be documentation issues or isolated training gaps. They carry lower financial risk and can usually wait until after close. Still, keep them on the register so they do not disappear during valuation and integration planning.
Rank each finding against 4 factors:
- Regulatory exposure
- Scrutiny likelihood
- Remediation effort
- Deal dependency
The 2026 Security Rule update makes MFA and encryption mandatory for covered entities and business associates [3].
The clearest red flag is paper compliance: policies are on file, but there is no technical proof, no log review, and no staff validation.
Push all material findings into the remediation cost estimate and the first-100-day plan.
4. Estimate remediation cost and build the first-100-day plan
Build the budget and the first-100-day plan off the gap register. Each finding should turn into 3 things right away - a cost, an owner, and a deadline. That keeps remediation tied to execution instead of turning into a loose punch list.
Cost the fixes by workstream
Use the $300,000 to $2,000,000 post-close remediation range as your planning guardrail [2]. Start with the workstreams that carry the most regulatory risk and the longest dependency chains. In practice, that means grouping findings into workstreams, pricing the work, and assigning one accountable owner for each lane.
| Remediation Workstream | Priority | Ranking Factor | Dependency |
|---|---|---|---|
| Security Risk Analysis | Critical | Highest Regulatory Exposure | Foundation for all other fixes |
| BAA Inventory | High | High Regulatory Exposure | Requires vendor cooperation |
| Access Controls | High | High Deal Value Impact | Depends on Identity/IAM setup |
| Patient Rights | Medium | Operational Disruption | Depends on workflow redesign |
| Policy Refresh | Medium | Governance Requirement | Precedes workforce training |
| Retraining | Medium | Compliance Evidence | Depends on policy finalization |
Material remediation costs should flow into deal terms where they belong - purchase price, escrows, or holdbacks. A HIPAA mock audit by an outside firm usually costs $15,000 to $50,000, and teams that run annual mock audits using the OCR protocol reduce the risk of negative findings by over 60% [4].
Set first-100-day owners, milestones, and dependencies
Use the same workstreams to map the first 100 days. The point is simple: sequence the work so you fix the highest-risk gaps first without tripping up day-to-day operations.
- Days 1-30: appoint the Privacy Officer, complete the BAA inventory, deploy MFA, and confirm cyber insurance
- Days 31-60: finalize the SRA, refresh policies, and complete tracked HIPAA training for all staff with completion records
- Days 61-100: redesign patient-rights workflows, close vendor gaps, and assemble the audit-ready binder
Centralizing documentation into a single audit-ready binder can cut OCR data request response time from 200+ hours to about 8-16 hours [4].
Each workstream needs a named owner across compliance, legal, IT, operations, and portfolio leadership. If no one owns the milestone, it slips. By Day 90, retest completed fixes and move to quarterly reporting. If you find an active breach, an unresolved OCR deficiency letter, or a gap that blocks insurance, escalate at once.
When to bring in outside diligence or operating support
Outside support is often worth the spend when the target is complex, spread across many sites, or thin on internal bandwidth. Cybersecurity diligence alone usually runs $30,000 to $100,000+, depending on company size and scope [1]. For healthcare platforms with layered vendor ecosystems, multiple locations, or known control gaps, that support can help the deal team move faster and keep post-close work on track.
Conclusion: From privacy uncertainty to a costed remediation roadmap
A HIPAA Privacy Rule assessment has value only if it ends with a priced remediation plan. That is what turns privacy uncertainty into a number the deal team can use.
The financial exposure is direct. OCR's Tier 4 willful neglect penalties can reach $2,177,880 per calendar year for identical violations [3]. Post-close remediation for missed compliance gaps also often moves into the 7-figure range [2].
For PE buyers, the goal is not to document risk. The goal is to price it and assign it before close. Buyer-side HIPAA diligence should end with a priced remediation plan, named owners, and Day 1 priorities that protect value.
FAQs
When should HIPAA privacy diligence start in a PE deal?
HIPAA privacy diligence should start before signing, during pre-signing negotiations.
That timing matters because it gives PE teams a clean view of risk before price, terms, and post-close plans are locked in. Early diligence can surface hidden issues like compliance gaps, weak vendor controls, or prior data breaches that may affect deal value, purchase terms, or indemnity discussions.
It also gives the deal team a better handle on remediation cost and timing. That makes it easier to scope first-100-day workstreams, assign owners, and avoid surprises after close.
What HIPAA gaps matter most before close?
Before close, fix the gaps that create near-term regulatory or operating risk. The top priorities are a missing or stale documented Security Risk Analysis and missing or stale Business Associate Agreements (BAAs). Those 2 items sit squarely in the Office for Civil Rights enforcement path.
Other deal-critical gaps include:
- No universal multi-factor authentication
- Unencrypted devices
- Shadow IT with protected health information
- Unresolved past breaches
How can HIPAA findings affect deal value?
HIPAA findings affect deal value because they point to regulatory exposure and operating debt. PE teams use assessments to spot compliance gaps, then turn those gaps into remediation costs, post-close work, or negotiating leverage on price.
Major deficiencies - such as undisclosed breaches or severe control failures - can trigger civil penalties, force a retrade, or kill the deal. On the other side, strong, auditable HIPAA protocols can support a higher premium because they lower inherited legal risk.