Audits Are More Than a Check-the-Box Exercise

October 05, 2026

By Paul Rothermel

Is Your Compliance Program Working?

Medical products and life sciences companies operate in an increasingly complex compliance environment. Healthcare compliance requirements, privacy obligations, cybersecurity expectations, and regulatory oversight continue to evolve at the federal, state, and international levels. Against this backdrop, audits can serve as an important tool for evaluating alignment with legal and regulatory requirements.

While no audit can completely eliminate compliance or privacy risks, a well-designed assessment process helps organizations identify potential gaps, prioritize remediation efforts, and demonstrate ongoing attention to compliance obligations.

An audit is an important step in assessing whether your compliance or privacy program is designed to adequately address risk and is functioning effectively. Gaps in health care or privacy compliance programs that go unaddressed can be damaging to the organization, other stakeholders, and ultimately lead to more costly fixes. The Office of Inspector General for the U.S. Department of Health and Human Services identifies risk assessment, auditing, and monitoring as key elements of an effective compliance program. OIG recommends that organizations develop risk-based audit schedules and periodically assess the effectiveness of their compliance programs. This same principle is addressed in various other domains, including privacy and cybersecurity, as evidenced by recent rulemaking in California under its Consumer Privacy and Privacy Rights Acts, and HIPAA’s inclusion of periodic audit and assessment requirements within the HIPAA Security Rule.

“A compliance audit should do more than confirm that policies exist on paper. Its real value is in understanding how those policies and controls work in practice, identifying where gaps exist, and helping the organization prioritize what needs attention.”

Paul Rothermel, Managing Attorney

What Should an Audit Focus On?

Every organization has a different risk profile shaped by its business model and industry. An organization planning to enhance patient and consumer data collection programs, such as through a new patient-facing mobile app, should consider auditing its privacy program against state, federal, and international privacy laws. An organization with an established HIPAA compliance program should consider whether a HIPAA compliance audit is timely. Any company with an active sales force may prioritize a risk-based audit of sales and marketing practices, including promotional compliance, healthcare fraud and abuse, and transparency controls. 

Companies anticipating diligence inquiries, whether from prospective strategic partners, customers, or investors, would benefit from conducting their own audits prior to these discussions.

In many cases, organizations should consider auditing more than one area to develop a comprehensive picture of their compliance risk.

What Does the Audit Process Look Like?

Although methodologies differ, compliance and privacy audits frequently involve several common phases:

  1. First, organizations should define the audit's scope and objectives, often focusing on areas presenting elevated legal, operational, or business risk. Organizations should also consider at the outset whether the audit should be conducted under attorney-client privilege. 
  2. Second, auditors typically request and then review relevant documentation, such as policies, procedures, agreements, training materials, incident logs, risk assessments, and governance records.
  3. Third, interviews and operational walkthroughs are often conducted to better understand how compliance obligations are implemented in practice.
  4. Finally, observations, potential gaps, and improvement opportunities are documented and prioritized. Organizations will then typically develop remediation plans designed to address identified opportunities for improvement in a risk-based manner.

The ultimate value of an audit often depends not only on the findings themselves but also on an organization's willingness to evaluate and improve its compliance controls as business processes evolve.

Effective assessments generally focus on the organization's actual operations and risk profile rather than reviewing policies in isolation. When audit activities are aligned with operational realities, organizations are often better able to identify risks that could affect business objectives, regulatory compliance, or reputation.

Practical Considerations for Organizations

Organizations considering a compliance or privacy audit may wish to:

  • Evaluate whether current policies and procedures reflect existing operations;
  • Confirm that compliance controls are documented and consistently implemented;
  • Review how regulatory changes have affected compliance obligations;
  • Assess whether vendor oversight processes remain appropriate;
  • Identify areas where training or increased monitoring may be beneficial; and
  • Develop a mechanism for tracking remediation efforts and continuous improvement.

Periodic reviews can help organizations understand where resources should be directed and where additional attention may be warranted.

How Gardner Law Can Help

Gardner Law regularly assists organizations with compliance and privacy assessments across a broad range of regulatory frameworks. Our team works with medical device manufacturers, pharmaceutical companies, digital health organizations, and technology companies to evaluate compliance programs, identify potential gaps, and develop practical remediation strategies.

We assist clients with matters involving:

  • Healthcare fraud and abuse compliance programs;
  • HIPAA privacy, security, and breach notification requirements;
  • U.S. state privacy law compliance;
  • Global privacy and data governance obligations;
  • FDA-related compliance and regulatory matters;
  • Information security and cybersecurity governance; and
  • Internal compliance investigations and risk assessments.

Whether your organization is conducting its first compliance review or evaluating a mature compliance program, Gardner Law can help assess risks, prioritize improvements, and develop practical solutions tailored to your business.

If you have questions about compliance audits, privacy assessments, healthcare regulatory compliance, or related risk management initiatives, contact Gardner Law to learn how we can help.