Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Compliance  ·  15 Apr 2026  ·  6 min

The evidence file

What it is, what is in it, and why the security program and the compliance evidence are the same work.

Most IT companies can protect a practice. Very few can prove it. The evidence file is our answer to the second half.

It is a maintained, audit-ready package with a date on every artifact, reviewed quarterly, formatted for an OCR data request. Twelve documents:

  • The current risk analysis, and the risk management plan behind it
  • The asset inventory and the ePHI data-flow map
  • An encryption status attestation, with equivalent-alternative documentation where applicable
  • An MFA coverage report, by system and by user
  • Workforce training completion records, role-based, retained six years
  • The business associate register, with executed agreements and renewal dates
  • Access review and termination records
  • Backup restore test results, timed
  • The incident response plan, tabletop minutes, and after-action items
  • Vulnerability scan history with remediation evidence
  • A Recognized Security Practices attestation covering twelve rolling months

Why these twelve

Because they are what gets asked for. Not by us — by an OCR data request, a cyber insurance underwriter, a health-system security questionnaire, and a private-equity diligence team. Those four audiences ask for remarkably similar things, which means one well-maintained package answers all four.

That is the actual efficiency argument. A practice that assembles a questionnaire response from scratch every time is doing the same work four times a year and doing it badly under time pressure.

Why it is the same work as security

Consider the MFA coverage report. To produce it you have to enumerate every system that touches ePHI, determine the authentication path into each, and verify enforcement rather than configuration. That is not a documentation exercise that happens after the security work. It is the security work, and the report is a byproduct.

The same is true of the asset inventory, the restore test results, and the access review records. Every one of them is the natural output of doing the underlying job properly and writing down what you found.

Which is why separating the two — an IT company over here, a compliance consultant over there — produces such poor results. The consultant documents what the IT company says is true. Nobody verifies it. The practice pays for both and, when the request arrives, finds it has neither.

The part that is worth real money

The Recognized Security Practices attestation. Under the HITECH amendment signed January 5, 2021, if you can demonstrate Recognized Security Practices were in place enterprise-wide for at least the previous twelve months, OCR must consider that as a mitigating factor: reduced penalties, narrower investigation scope, shorter corrective action plan terms.

It is a statutory discount that costs nothing but disciplined recordkeeping. Almost no organization this size has the twelve months of documentation required to claim it, because claiming it requires having been documenting for twelve months before you needed to.

Making it claimable is a design goal of the evidence file, not a happy accident.

Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.