White Paper

HIPAA Audit Program - Is Phase 2 Almost Here?

 
The Office of Civil Rights (OCR) within the U.S. Department of Health and Human Services (HSS) is distributing preliminary HIPAA compliance surveys and preparing for a second round of HIPAA compliance audits. All HIPAA-covered entities and their business associates should take steps now to be prepared to respond.

HIPAA Audits – Phase 1
Under the 2009 Health Information Technology for Economic and Clinical Health Act (HITECH), OCR is required to conduct HIPAA compliance audits of covered entities and their business associates. The OCR HIPAA Audit program was designed to review and analyze the processes, controls and policies of selected covered entities pursuant to the HITECH Act audit mandate.

As part of a pilot phase for the audit program (“Phase 1”), OCR identified a pool of 115 covered entities for audits that broadly represented the wide range of healthcare providers, health plans and healthcare clearinghouses operating today. OCR also established a comprehensive audit protocol identifying the requirements to be assessed.

Download this white paper to continue reading …

Daniel E. Rohner is Of Counsel at Shook, Hardy & Bacon L.L.P.’s Denver office. He has spent 19 years as trial lawyer concentrating practice on complex commercial disputes. Mr. Rohner is a member of Shook’s data privacy team that regularly advises covered entities and business associates regarding compliance issues, employee training, vendor management agreements, and data breach notification requirements and resulting litigation.