Diligence · when someone buys your clinic

The day you sell,
they will ask for this.

A broker calls. A regional group makes an approach. And HIPAA stops being a rule you were meaning to get to, and becomes a number on your term sheet. Their counsel opens with one request, and what you can hand them in the first week moves your price.

The request

It is not a special document.
It is your program, read by a stranger.

The HIPAA diligence request is remarkably consistent across deals, and it is short enough to print. Every line exists because a provision of the rules creates it. Every line is either in your hands on day one, or it is not.

What their counsel asks for
Ten lines. Six years back.
The risk analysis
Opens with this
The risk management plan, with dates and owners
Did you act on it
Policies for all three rules, with approval dates
Implemented, not purchased
Incident and breach log, with the four-factor assessments
Inherited liability
Every vendor touching PHI, every BAA executed
The register
Training records: who, when, on what
Evidence, not assertion
Named privacy officer and security officer
In writing
Sanctions applied, if any
Is the policy real
NPP, access logs, individual rights handled on time
The 30-day clock
Encryption, authentication, audit logs, backups, retention
Technical evidence
Six years of documentation is the retention rule at 45 CFR 164.316(b)(2)(i). It is also, in practice, the lookback a careful buyer applies.
The auditor's file and the buyer's file are the same file. Pointed at a different reader. Which means you are building it either way, and the only question is whether you build it over years, quietly, or in six weeks under a deadline while the buyer watches. The full request, line by line, with the rule behind each one →
What a red answer costs

It rarely kills the deal.
It reprices it.

Diligence already scores targets red, yellow, and green to drive exactly these adjustments. Their counsel was going to build that scored picture anyway, by hand, out of whatever box of documents you send. The only question is whether it matches the one you would have built yourself.

Outcome one

They walk

A messy compliance picture reads as hidden liability. Some buyers simply pass rather than take on what they cannot measure.

Outcome two

They discount

Gaps become leverage. Unquantifiable risk gets quantified conservatively, by the party who benefits from the conservative number.

Outcome three

They hold it back

Cash you earned sits in escrow for years against violations that might surface later, because HIPAA liability can follow the entity or the assets.

And the insurance does not save you. Representation and warranty insurance generally excludes known issues. A problem surfaced in diligence is, by definition, known. It cannot be insured around. It comes out of the price, or it goes into escrow.
Why the binder fails here

A buyer validates documents
against operational reality.

Which is the one test a purchased policy set cannot pass. And you do not have to take our word for what that looks like to a regulator, because OCR published its own grading scale.

OCR, 2016-2017 HIPAA Audits Industry Report

A rating of 4 means negligible effort. The example OCR chose: policies copied directly from an association template.

In the same audits, zero percent of covered entities earned the top rating on risk analysis. 94% failed risk management. 89% failed the individual right of access. Most of them had binders. The binder was not what OCR was measuring.

Their counsel knows this record. So when they ask for your risk analysis and you cannot produce one, the inference is not that you have a gap. It is read as proof the program was never real, and that colors every other compliance representation you make in the deal. The policy binder problem →

What we actually do about it

The file exists because it was being built all along.

Not assembled in a panic when the LOI lands. WiseUpHIPAA computes your posture from what is really happening in your clinic, and the evidence behind every control is dated and kept as you operate. When someone finally asks, the answer is already there.

What the platform does
  • Twenty-five controls, computed from your real operations, not from what you typed into a checkbox.
  • Policies written from your clinic's actual facts: your systems, your staffing model, your physical realities.
  • Every control carries dated evidence, retained on the six-year clock the rule requires.
  • The vendor register, the training record, the incident log, the access picture: kept current, not reconstructed.
  • Red where red is true. We will not seed you to green, because a buyer's counsel can tell.

You will build this file either way.

Over years, quietly, as a by-product of running the clinic properly. Or in six weeks, under a deadline, with a counterparty whose financial interest is served by finding it thin. The price difference between those two is the largest number nobody writes down.