Why IT Risk Is Now Every Healthcare Auditor’s Business

Technology is embedded in virtually every aspect of healthcare operations, from billing and reimbursement to patient information, compliance, pharmacy operations and reporting. As healthcare organizations become increasingly dependent on interconnected systems and data, understanding the controls behind that technology is no longer solely the responsibility of IT auditors. 

In the article “IT Audit for Non-IT Auditors: Understand why IT matters more than ever in healthcare,” published in the Association of Healthcare Internal Auditors (AHIA)’s Journal of the Association of Healthcare Internal Auditors, Jeannie O’Donnell, Director in Healthcare Forensics at BDO, explores how financial, operational and compliance auditors can strengthen their ability to recognize technology-related risks without becoming cybersecurity or engineering specialists. 

The article explores practical considerations across areas including IT governance, access and application controls, change management, cybersecurity, business continuity and disaster recovery, third-party risk, and security risk assessments. It also examines how weaknesses in technology controls can quickly evolve into broader financial, operational, regulatory and reputational risks for healthcare organizations. 


What Healthcare Auditors Should Consider

As technology becomes increasingly intertwined with audit objectives, organizations should consider:

  • How confidently can auditors rely on the data generated by critical systems?
  • Are access controls appropriately designed around employee roles and responsibilities?
  • How could technology changes affect billing, claims, reimbursement or compliance?
  • Are business continuity and disaster recovery plans sufficiently tested?
  • How are third-party technology and data risks being evaluated?
  • When should non-IT auditors bring specialized technology expertise into an engagement? 

Understanding these fundamentals can help healthcare auditors ask better questions, identify potential control weaknesses earlier and recognize when what appears to be a business or compliance issue may actually originate within the technology environment. 

Read the full article to learn how healthcare auditors can build greater fluency in IT risk and strengthen their approach to auditing technology-enabled environments.