People imagine an audit as a technical penetration test. Many reviews start with policies, training records, and a request for activity logs on a specific date range. If your email and forms cannot produce that, the rest of the conversation is uphill.
Have these ready
- Current user list with roles and last access.
- BAA for every vendor that touches PHI, including fax and forms.
- Sample exports of email, fax, and form activity.
- The incident log, even if it is short.
Build the habit before the letter
HIPAA Companion keeps email, fax, and form activity in one compliance model so a privacy officer can export without opening three vendor portals. Pair the product with a quarterly "pull a sample log" task. That task is the control. The software is the evidence source.
If you still have consumer channels in parallel, say so in the risk analysis and set a retirement date. Hidden channels are what turn a routine review into a findings letter.
