IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Frameworks & Controls

HICP 2023 — Medium Organizations

41 published sub-practices across ten healthcare security practices

All available frameworks

What the app checks

Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.

Explicit requirement-to-test mappings

RequirementCollector / testWhat it checks or supports
1.M.BENTRA / ENTRA-MFA-REG-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
2.M.AWINDOWS / WIN-AV-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
3.M.AENTRA / ENTRA-GUEST-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
3.M.BADSEC / AD-LIFECYCLE-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
3.M.DENTRA / ENTRA-MFA-REG-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
4.M.CSTORAGE / STOR-AT-REST-ENCRYPTION-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
4.M.DBACKUP / VEEAM-REPO-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
5.M.AWINDOWS / WIN-INVENTORY-COVERAGE-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
6.M.AWINDOWS / WIN-FW-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
7.M.AVULN / VULN-IMPORT-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.
7.M.DWINDOWS / WIN-PATCH-FRESHNESS-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, clinical workflows, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. No medical-device, clinical-safety or HIPAA conclusion from a general scan.

What requires manual review

Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.

Voluntary healthcare practice preparation; not certification or a HIPAA compliance determination. Medical-device and clinical-safety conclusions require clinical engineering and manufacturer evidence. Source: U.S. Department of Health and Human Services, 405(d) program and HPH sector publications. Text reformatted; ITAF evidence actions and supporting scan mappings added. No HHS endorsement. Voluntary guidance does not establish HIPAA compliance, certification or clinical safety.

Where it is available

This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.

Coverage shown here comes from the application’s C32 requirement and mapping catalogs.