The day you sell your clinic, they will ask for this
A buyer's counsel opens HIPAA diligence with one request, and the answer moves your price. What the request actually contains, item by item, why the six-year window is not a coincidence, and what a red answer does to a deal.
Last verified: 2026-07-12
Most ABA clinic owners meet HIPAA as a grudge purchase: a rule to satisfy, a binder to buy, a box to tick. Then one day a broker calls, or a regional group makes an approach, or a private equity roll-up sends a letter, and HIPAA stops being a rule and becomes a number.
Because the buyer’s counsel is going to ask, and what you can hand them in the first week of diligence will move your price.
What they actually ask for
The HIPAA diligence request is remarkably consistent across deals, and it is short enough to print. Every item on it exists because a specific provision of the rules creates it, and every item is either in your hands on day one or it is not.
| What the buyer asks for | What it has to show | The rule behind it |
|---|---|---|
| The risk analysis | An accurate and thorough assessment covering all ePHI, across every system, device, cloud service, and vendor flow, current rather than historical | 164.308(a)(1)(ii)(A) |
| The risk management plan | That you acted on what the analysis found, with owners, dates, and evidence of closure | 164.308(a)(1)(ii)(B) |
| Policies for all three rules | That they were implemented, not merely purchased, with approval dates and a review cadence | 164.316, 164.530(i) |
| Incident and breach log | What happened, when it was discovered, the four-factor assessments, and that notification met the 60-day requirement | 164.402, 164.404, 164.408 |
| Business associate agreements | A complete vendor register, every PHI-touching vendor executed and current | 164.502(e), 164.504(e), 164.308(b) |
| Training records | Who was trained, on what, and when, by role, with evidence rather than assertion | 164.308(a)(5), 164.530(b) |
| Named officers | A named privacy official and a named security official, in writing | 164.308(a)(2), 164.530(a) |
| Sanctions applied | That the sanction policy is real, and has been used | 164.308(a)(1)(ii)(C), 164.530(e) |
| Notice of Privacy Practices and access logs | Current NPP, and evidence that individual rights requests were handled on time | 164.520, 164.524, 164.528 |
| Technical evidence | Encryption, authentication, audit logs, backups, retention and destruction | 164.312, 164.310(d) |
Notice what that list is. It is not a special acquisition artifact. It is the HIPAA program, reorganized into a buyer’s mental model instead of a regulator’s. Which is the entire point of this page.
The six-year window is not a coincidence
HIPAA requires that required documentation be retained for six years from the date of its creation or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)). Six years is also, in practice, the lookback a careful acquirer applies.
So the evidence file you would hand an OCR investigator and the evidence file you would hand a buyer’s counsel are substantially the same file, pointed at a different reader. The operator who has been maintaining it all along walks into diligence with the work already done. The operator who has not spends the diligence window building a compliance record under a deadline, while the buyer watches, which is the worst possible condition under which to construct one.
Why they open with the risk analysis
They open with it for the same reason OCR does: it is the least fakeable document in the program, and its absence is diagnostic.
OCR has run a dedicated Risk Analysis Initiative since late 2024, and the pattern in its own announcements is relentless. In April 2026 it settled four ransomware investigations at once, totaling 1,165,000 dollars across breaches affecting more than 427,000 people, and the finding in all four was the same: no accurate and thorough risk analysis before the breach.
And for anyone in this field who still believes enforcement is a hospital problem, there is one settlement that should end the argument. In July 2025, OCR settled with Deer Oaks, a behavioral health provider, for 225,000 dollars and a two-year corrective action plan, after breaches affecting over 171,000 individuals. OCR’s finding: the organization failed to conduct an accurate and thorough risk analysis.
A buyer’s counsel reads that record too. So when they ask for your risk analysis and you cannot produce one, the inference is not that you have a gap. The absence of the risk analysis is not read as a gap in a program. It is read as proof the program was never real, and that inference then colors every other compliance representation you make in the deal.
What a red answer actually does
It rarely kills the deal outright. It reprices it, and the mechanics are worth knowing before you are inside them.
“The absence of the risk analysis is not read as a gap in a program. It is read as proof the program was never real”
The multiple comes down. Unquantifiable risk gets quantified conservatively, by the party who benefits from the conservative number.
The escrow goes up. Cash you earned sits in a holdback for years against violations that might surface later, because HIPAA liability can follow the entity or the assets depending on how the deal is structured.
Indemnities survive closing. A carve-out that outlives the general survival period is a tail you carry personally.
A restructuring condition delays the close. Months, sometimes, while you rebuild a compliance record, and every month of delay is a month in which something else in the deal can break.
And the insurance does not save you. Representation and warranty insurance generally excludes known issues. A problem surfaced in diligence is, by definition, known. It cannot be insured around; it comes out of the price or it goes into escrow.
Diligence already scores targets red, yellow, and green to drive exactly these adjustments. The buyer’s counsel was going to build that scored picture anyway, by hand, out of whatever box of documents you send them. The only question is whether the picture they build matches the one you would have built yourself.
The trap: a binder that is worse than nothing
There is a temptation, once the term sheet is in sight, to paper over the gap quickly. Buy a policy set. Backdate nothing, but produce a great deal of documentation in a hurry.
Do not. Documentation that does not describe what your clinic actually does is worse than no documentation, and it is worse for a precise reason: it converts an evidentiary hole into an admission. It demonstrates that the organization knew the requirement and represented a compliance program it did not have. An empty file is a gap. A false file is a finding, and in a transaction it is a representation you signed.
This is why the honest posture is not just ethically better. It is commercially better. A seller who hands over a program with two amber items, a dated remediation plan, and evidence of the work is more credible, and more valuable, than a seller who hands over an implausibly perfect binder assembled last month.
What to do, if a sale is anywhere on your horizon
Not on the eve of the deal. Now, while it is quiet, which is the only time this is cheap.
Do the risk analysis properly, on a real inventory of where your ePHI actually lives. It is the page they open with, and it is the one that colors everything else.
Close the vendor register. Every vendor touching PHI, every BAA executed and current. The walkthrough is here, and this is the second item their counsel checks, because it is the easiest to falsify by omission.
Keep the incident log, even for the small ones. A clinic with a log showing three minor incidents, assessed and closed, reads as a functioning program. A clinic with an empty log reads as a clinic that never looked.
Make the training record a record, not a memory: who, when, on what.
Fix the amber items and keep the receipts. Remediation with dates is an asset in diligence. It shows a program that finds and closes things, which is exactly what a buyer wants to inherit.
Everything on that list is required of you anyway. The only thing the sale changes is who reads it, and what it costs you if it is not there.
The honest summary
The file that satisfies an auditor is the file that satisfies a buyer. Both of them are asking the same question, and it is not “did you mean well.” It is: show me.
You will build that file eventually. You will either build it over years, quietly, as a by-product of running the clinic properly, or you will build it in six weeks, under a deadline, with a counterparty whose financial interest is served by finding it thin.
Those are the two options, and the price difference between them is the largest number in this article that nobody ever writes down.
The short version
- HIPAA diligence opens with the risk analysis, and its absence is read as evidence the whole program was theater.
- The six-year documentation rule and the buyer's six-year lookback are the same window; the auditor's file and the buyer's file are substantially the same file.
- A red answer does not usually kill a deal. It reprices it: a lower multiple, a bigger escrow, an indemnity that survives closing, or a restructuring condition that delays the close.
- Representation and warranty insurance generally excludes known issues, so a gap found in diligence cannot be insured around; it comes out of the price.
- Documentation that does not match what the clinic actually does is worse than none: it proves you knew the requirement and represented compliance you did not have.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Policies and procedures and documentation requirements, including the six-year rule45 CFR 164.316(b)(2)(i)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316
- Administrative safeguards, including risk analysis and risk management45 CFR 164.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Business associate contracts and other arrangements45 CFR 164.502(e) and 164.504(e)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
- Breach notification to individuals and the Secretary45 CFR 164.404 and 164.408https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
- Administrative requirements, including training, sanctions, and documentation45 CFR 164.530https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- HHS Office for Civil Rights settles HIPAA investigation with a behavioral health providerHHS press release, July 7, 2025https://www.hhs.gov/press-room/ocr-hipaa-racap-deer-oaks.html
- HHS Office for Civil Rights settles four HIPAA Security Rule ransomware investigationsHHS press release, April 23, 2026https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html
- HHS Office for Civil Rights, resolution agreements and civil money penaltiesHHS.govhttps://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
The file is the same file. Keep it, and the day comes easy.
WiseUpHIPAA computes your posture from live operational data and holds the dated, frozen evidence behind every control, honestly, including the parts that are not done. The evidence package is available the same day it is asked for, because it was being built all along.