If it is like SOC2 I would expect respected auditors to reject that
But there are no auditors required for HIPAA. Only the government (HHS OCR) itself can enforce the standards.
No? Like, wildly no? This is a big part of why you pay for the most respected auditors.
But there are no auditors required for HIPAA. Only the government (HHS OCR) itself can enforce the standards.