HIPAA Audit Protocols Now Public; Plus, Preliminary Insights From OCR

As promised by the Department of Health and Human Services' Office of Civil Rights (OCR) and as reported here on June 11th, OCR has released its HIPAA privacy and security audit protocols. The audit protocols are intended to cover the three main areas of HIPAA privacy and security enforcement:

Privacy Rule requirements, specifically: notice of privacy practices for Protected Health Information (PHI); rights to request privacy protection for PHI; access of individuals to PHI; administrative requirements; uses and disclosures of PHI; amendment of PHI; and accounting of disclosures. Security Rule requirements for administrative, physical, and technical safeguards. Breach Notification Rule requirements. The protocol addresses 165 performance criteria, 77 of which focus exclusively on compliance with the Security Rule, and 88 in combination that deal with Breach Notification and Privacy Rule requirements.

Senior Advisor David Mayer of OCR, during his presentation at the 2012 American Health Lawyers Association Annual meeting in Chicago, Illinois, stated that the protocol presently on the website is actually an updated version of the protocol used to audit the first 20 covered entities who were selected for examination during the HITECH audit pilot program period. He also stated that there are ninety-five more covered entities that will be audited to meet the OCR's goal of auditing 115 entities and that OCR did not open any additional reviews related to the 20 audits it has completed so far. Last, he noted that once the HIPAA Omnibus Rule is published, OCR will likely audit business associates thereafter.

Mr. Mayer also provided some of his preliminary observations...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT