By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: OCR Just Finalized its Audit Protocols – Are You Feeling Confident About Your HIPAA Compliance?
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Business > OCR Just Finalized its Audit Protocols – Are You Feeling Confident About Your HIPAA Compliance?
BusinessPolicy & Law

OCR Just Finalized its Audit Protocols – Are You Feeling Confident About Your HIPAA Compliance?

Dan Stempel
Dan Stempel
Share
5 Min Read
HIPAA-Compliance.png
SHARE

HIPAA-Compliance.png

Contents
  • There’s No Reason for Panic — Just Preparation
  • Possibility for Consequences?

A friendly reminder that, with the recent HHS Office of Civil Rights announcement, covered entities may soon be facing some unwelcome audits. Now’s the time to review compliance.

HIPAA-Compliance.png

A friendly reminder that, with the recent HHS Office of Civil Rights announcement, covered entities may soon be facing some unwelcome audits. Now’s the time to review compliance.

More Read

health insurance disability
Job Seekers with Disabilities Should at Health Insurance Benefits
Measuring Physician Quality – Bully or Just Plain Bull
Planning an Enterprise Archive (VNA) to Accommodate Collaboration in Precision Medicine
Giving Power to the States, But at Whose Expense?
Lessons on Building a Great Ortho Team from The Avengers

HIPAA compliance can sometimes feel like changing the oil in your car: inarguably necessary, a serious problem when left unchecked, yet tedious enough that some are willing to let the task slide. The difference, of course, is that one is bad for your engine while the other is a federally mandated and legally enforceable standard.

Friendly reminder: the HHS Office of Civil Rights (OCR) recently announced the Phase II launch of its HIPAA audit program, part of the 2009 HITECH Act. And with their finalized Audit Protocol published on April 8th, all signs point to the OCR soon getting down to brass tacks.

This needn’t be cause for alarm. But if covered entities or their business associates haven’t recently ensured that their compliance is watertight — especially regarding the measurement of referral and appointment activity — there’s definitely no time like the present.

There’s No Reason for Panic — Just Preparation

Files.jpg

Audits are tentatively set to begin sometime in May, according to OCR official Devin McGraw via Politico, at which point randomly selected covered entities will receive an email announcing their fates (they recommend checking spam folders).

Business associates, who are also subject to individual audits, will be subject to audits in June or July. The agency plans to conduct roughly 200 remote desk audits, to be completed by December 2016, and anywhere from 10-25 “full scale” field audits thereafter, according to Healthcare Info Security. If you’re uncomfortable with the vagueness of this plan, you’re not alone.

The good news is that the majority of organizations will not be audited. However, if selected, entities will have a mere ten business days to prepare and submit all relevant documents via a secure online portal. Desk audits may (or may not) entail just a review of policies, or pertain to only one of the three HIPAA Rules: Privacy, Security, or Breach Notification. However, certain charmed organizations may, in fact, get to experience the unique joy of both desk and on-site audits.

Possibility for Consequences?

Officially, Phase II OCR audits are relatively benign, designed to “develop tools and guidance to assist the industry in compliance self-evaluation and in preventing breaches.” Nevertheless, they will open a formal investigation, should they find a “serious compliance issue,” however defined. And while OCR won’t publish the audit results (or even list which companies are audited), the whole process is subject to the Freedom of Information Act (FOIA), which means that journalists or other public agents can legally publish results. 

You may recall that 115 covered entities were audited in 2011 during Phase 1 of program, unearthing major compliance breaches; 89% were found to have compliance issues, and smaller organizations tended to struggle in multiple areas. 

Given the involvement of business associates — many of whom are not primarily dedicated to healthcare — one of the most difficult compliance aspects to cover will be Protected Health Information (PHI) and ePHI (electronic PHI). For instance, if your marketing agency measures referral and appointment activity, they’re likely in the domain of PHI and will need to be in solid compliance.

The bottom line is that if you haven’t implemented HIPAA privacy and security policies and procedures, recently conducted an inventory of relevant assets, or regularly completed risk assessments, then now is probably your last chance to do so before the audit process begins.

In the end, however, integrating a comprehensive HIPAA compliance program will keep you from running afoul of any regulatory standards that may come down the pipeline. The HHS is only conducting these audits in order to better enforce compliance standards in the future. So while you may or may not be audited this year, you and your digital marketing vendors must be prepared to stand up to scrutiny at any time.

Targeted Medical Marketing, Digital Marketing

(Image credit: Medill DC/flickr)

TAGGED:HIPAAHIPAA compliance
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

nurse checking her schedule
Managing On-Call Lists for Healthcare Open Shifts
Health
March 26, 2026
outdoor yoga class in sunny park setting
Resveratrol Capsules VS Resveratrol Powder: Are There Differences?
Health
March 26, 2026
Clinical Trials Demystified: Yousuf A. Gaffar, M.D’s Guide to Research and Patient Impact
Clinical Trials Demystified: Yousuf A. Gaffar, M.D’s Guide to Research and Patient Impact
Health
March 25, 2026
woman wearing white long sleeved shirt
Common Mistakes When Trying to Treat Hair Fall at Home
Fitness
March 20, 2026

You Might also Like

Encouraging the Parent-Child Dialogue About Cancer

October 19, 2015

Back to Basics… The (lost) Art of The Patient-Physician Interaction

October 26, 2011
IVF and insurance
BusinessFinance

Paying for IVF

September 5, 2014

What If The Supreme Court Strikes Down the Individual Mandate?

November 3, 2011
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?