Jun 25 / Alex Lipovtsev & Dianne Pledgie

When a Cyber Audit Comes Back Clean: What a Small Hospital Got Right

The HHS Office of Inspector General (OIG) recently published an audit that stands out for what it did not contain. In OAS-25-18-033 (issued June 12, 2026), OIG examined whether a small hospital in the southeastern United States had cybersecurity controls in place to prevent, detect, and respond to cyberattacks. The OIG concluded the small hospital had sufficient cybersecurity controls in place and OIG made no recommendations.

What makes this really stand out is that this audit is the third in a series that included two larger hospitals. The OIG told both of the larger facilities (A-18-22-08019 and A-18-22-08021) they had room to improve. When it comes to cybersecurity, vigilance matters more than size.

What OIG Examined
OIG's objective was straightforward: determine whether the hospital could prevent, detect, and respond to a cyberattack. Rather than reviewing policies on paper alone, OIG contracted with a cybersecurity firm to run external penetration testing, web application testing, and vulnerability scanning against four of the hospital's public-facing websites. OIG also reviewed the hospital's incident response and contingency planning policies and interviewed its officials. The penetration testing took place in June 2025, with broader audit work running from January 2025 through April 2026.

What OIG Found
OIG found that the hospital's controls held. The hospital had adopted the NIST Cybersecurity Framework (CSF) 2.0 as its primary framework, and OIG evaluated its controls against the HIPAA Security Rule. Specifically, OIG observed:

  • A defense-in-depth architecture layering multiple safeguards, including a custom system built to block unusual or suspicious activity. The hospital detected OIG's penetration testing and flagged it as suspicious in real time.

  • Mature incident response practices aligned with NIST SP 800-53, including annual cybersecurity training, routine vulnerability scanning, continuous monitoring, regular tabletop exercises, and annual third-party penetration testing.

  • Disciplined contingency planning with a plan tested twice a year and updated annually based on risk assessments, role-based contingency training, nightly backups replicated to an off-site location and tested at least monthly, quarterly disaster recovery exercises, backup workstations to keep clinical data accessible during outages, and data encrypted at rest and in transit.

  • Engaged leadership that met regularly to focus on emerging threats and ongoing improvements to the security program.


The testing identified only one low-risk issue: certain systems did not enforce a secure transport setting. Tellingly, the hospital had already identified that issue itself, formally documented its acceptance of the associated risk, and was working with a vendor on a long-term fix. Even the single weakness OIG found was already under active management.

Key Takeaways for Health Centers

  • Start by knowing your vulnerabilities. Ensure you have a good understanding of where you may need to focus your attention and resources by conducting a thorough Security Risk Analysis (SRA), which is required under HIPAA (45 CFR §164.308(a)(1)(ii)(A)). Identifying and managing your own gaps matters more than implementing any particular framework.


  • Test what you've written down. Policies only count if they work. This hospital confirmed its controls through regular monitoring and tabletop exercises. Health centers can do this at any scale; even an annual tabletop walkthrough beats an untested binder. A tabletop exercise with a cybersecurity scenario can also satisfy the additional (off-year) exercise requirement for FQHCs under the CMS Emergency Preparedness Rule (42 CFR 491.12(d)(2)(ii)(C)), letting one activity serve both your HIPAA and EP obligations.


  • Make backups and recovery routine. Off-site, regularly tested backups with encrypted data are what would allow this hospital to keep delivering care through a disruption. The Security Rule's contingency planning standard (45 CFR § 164.308(a)(7)) expects this.


  • Small can be mighty. A hospital with fewer than 50 beds passed where larger ones were told to improve. A focused, well-run program is what made the difference.

  • Make security a leadership priority, not just an IT problem. OIG credited the hospital's leadership for meeting regularly on emerging threats and security strategy, a sign the program had buy-in from the top. Any compliance program is only as effective as the leadership behind it: without genuine support, adequate resources, and real buy-in, even the best-designed controls fall short.

For more information, please contact:

DIANNE PLEDGIE
Principal
dianne.pledgie@powerslaw.com
ALEX LIPOVTSEV
Manager, Compliance and Risk Management Services
alex.lipovtsev@powerslaw.com

Want to know more?

Below are upcoming trainings you may find helpful. Visit our Catalogue page for a full list.