The evidence file
What it is, what is in it, and why the security program and the compliance evidence are the same work.
Most IT companies can protect a practice. Very few can prove it. The evidence file is our answer to the second half.
It is a maintained, audit-ready package with a date on every artifact, reviewed quarterly, formatted for an OCR data request. Twelve documents:
- The current risk analysis, and the risk management plan behind it
- The asset inventory and the ePHI data-flow map
- An encryption status attestation, with equivalent-alternative documentation where applicable
- An MFA coverage report, by system and by user
- Workforce training completion records, role-based, retained six years
- The business associate register, with executed agreements and renewal dates
- Access review and termination records
- Backup restore test results, timed
- The incident response plan, tabletop minutes, and after-action items
- Vulnerability scan history with remediation evidence
- A Recognized Security Practices attestation covering twelve rolling months
Why these twelve
Because they are what gets asked for. Not by us — by an OCR data request, a cyber insurance underwriter, a health-system security questionnaire, and a private-equity diligence team. Those four audiences ask for remarkably similar things, which means one well-maintained package answers all four.
That is the actual efficiency argument. A practice that assembles a questionnaire response from scratch every time is doing the same work four times a year and doing it badly under time pressure.
Why it is the same work as security
Consider the MFA coverage report. To produce it you have to enumerate every system that touches ePHI, determine the authentication path into each, and verify enforcement rather than configuration. That is not a documentation exercise that happens after the security work. It is the security work, and the report is a byproduct.
The same is true of the asset inventory, the restore test results, and the access review records. Every one of them is the natural output of doing the underlying job properly and writing down what you found.
Which is why separating the two — an IT company over here, a compliance consultant over there — produces such poor results. The consultant documents what the IT company says is true. Nobody verifies it. The practice pays for both and, when the request arrives, finds it has neither.
The part that is worth real money
The Recognized Security Practices attestation. Under the HITECH amendment signed January 5, 2021, if you can demonstrate Recognized Security Practices were in place enterprise-wide for at least the previous twelve months, OCR must consider that as a mitigating factor: reduced penalties, narrower investigation scope, shorter corrective action plan terms.
It is a statutory discount that costs nothing but disciplined recordkeeping. Almost no organization this size has the twelve months of documentation required to claim it, because claiming it requires having been documenting for twelve months before you needed to.
Making it claimable is a design goal of the evidence file, not a happy accident.
IT diligence for practice acquisitions: what to look for
What a buyer should check, what a seller should clean up first, and what post-close integration actually costs.
Read it Imaging · 25 Mar 2026Your imaging server is probably on the internet
A late-2025 scan found 3,627 internet-accessible DICOM servers. CVE-2025-0896 is why the free ones are over-represented.
Read it