OCR HIPAA Audit Advisory Services

HIPAA Audit Advisory

Prepare your practice for Office for Civil Rights/Health and Human Services HIPAA/HITECH audits by leveraging our HIPAA consulting expertise.

The HITECH Act authorizes Health and Human Services (HHS) to conduct periodic audits to ensure that covered entities and business associates are complying with the HIPAA/HITECH Privacy, Security, and Breach rules.  As a result Office for Civil Rights (OCR), has begun to phase 2 audit of Covered Entities and Business Associates.  Our HIPAA audit advisory service will guide with this process and help phase audit with confidence.

As a first step, OCR is in the process of verifying your organizations’ primary email address.  Be on the lookout for an email from OCR; OSOCRAudit@hhs.gov. and follow the instructions in the email.  Verify to ensure  your primary contact information is correct with OCR.

Audits will give OCR an ability to assess privacy and security protections and compliance issues on a systemic level and to identify potential vulnerabilities to help entities prevent problems before they occur. This will complement the incident-based work that HHS currently conducts with respect to investigations. . Read more about Phase 1 of the HIPAA Audit Program.


Our HIPAA audit advisory Approach:

EHR 2.0’s OCR HIPAA/HITECH  audit advisory services help healthcare organizations prepare for the audit by:

HIPAA Audit advisory

  1. Assessing the current policies and procedures
  2. Identifying key gaps and risk areas based on ePHI created, transmitted, received and stored
  3. Training
  4. Risk analysis
  5. Plans to mitigate risks identified
  6. Audit support in case of OCR audit


Looking for HIPAA audit advisory service?

Let our security consultants help you …

 Call now at 866-276 8309 or


Frequently Asked Questions on Phase 2 HHS/OCR HIPAA audit

Who is responsible for paying the on-site HIPAA auditors?

The Department of Health and Human Services is responsible for the on-site auditors. Neither covered entities nor their business associates are responsible for the costs of the audit program.

Will Phase 2 HIPAA audit cover state-specific Privacy and Security Rules in addition to HIPAA’s Privacy, Security, and Breach Notification rules?

No, the scope of the audit program does not extend beyond the Privacy, Security, and Breach Notification Rules.

Will Phase 2 HIPAA audit differ depending on the size and type of participants?

The audit protocols are designed to work with a broad range of covered entities and business associates, but their application may vary depending on the size and complexity of the entity being audited.

How will consumers be affected with Phase 2 HIPAA audit?

The audit program is an important tool to help assure compliance with HIPAA protections, for the benefit of individuals. For example, the audit program may uncover promising practices or reasons health information breaches are occurring and will help OCR create tools for covered entities and business associates to better protect individually identifiable health information. Concerns about compliance identified and corrected through an audit will serve to improve the privacy and security of health records. The technical assistance and promising practices that OCR generates will also assist covered entities and business associates in improving their efforts to keep health records safe and secure. During the audit process, OCR will continue to accept complaints from individuals and to launch compliance reviews where warranted;   covered entities and business associates’ compliance obligations remain in full effect.

What happens after Phase 2 HIPAA audit?

Audits are primarily a compliance improvement activity. OCR will review and analyze information from the final reports. The aggregated results of the audits will enable OCR to better understand compliance efforts with particular aspects of the HIPAA Rules. Generally, OCR will use the audit reports to determine what types of technical assistance should be developed and what types of corrective action would be most helpful. Through the information gleaned from the audits, OCR will develop tools and guidance to assist the industry in compliance self-evaluation and in preventing breaches.

Should an audit report indicate a serious compliance issue, OCR may initiate a compliance review to further investigate. OCR will not post a listing of audited entities or the findings of an individual audit which clearly identifies the audited entity. However, under the Freedom of Information Act (FOIA), OCR may be required to release audit notification letters and other information about these audits upon request by the public. In the event OCR receives such a request, we will abide by the FOIA regulations.

What is the general timeline for Phase 2 HIPAA audit ?

In the coming months, OCR will notify the selected covered entities in writing through email about their selection for a desk audit. The OCR notification letter will introduce the audit team, explain the audit process and discuss OCR’s expectations in more detail. In addition, the letter will include initial requests for documentation. OCR expects covered entities that are the subject of an audit to submit requested information via OCR’s secure portal within 10 business days of the date on the information request.  All documents are to be in digital form and submitted electronically via the secure online portal.

After these documents are received, the auditor will review the information submitted and provide the auditee with draft findings.  Auditees will have 10 business days to review and return written comments, if any, to the auditor. The auditor will complete a final audit report for each entity within 30 business days after the auditee’s response.  OCR will share a copy of the final report with the audited entity. While conducting desk audits of covered entities, OCR will replicate the notification and document request process for initiating desk audits of selected business associates. OCR will share a copy of the final report with the audited business associate. Similarly, entities will be notified via email of their selection for an onsite audit. The auditors will schedule an entrance conference and provide more information about the onsite audit process and expectations for the audit. Each onsite audit will be conducted over three to five days onsite, depending on the size of the entity. Onsite audits will be more comprehensive than desk audits and cover a wider range of requirements from the HIPAA Rules. Like the desk audit, entities will have 10 business days to review the draft findings and provide written comments to the auditor. The auditor will complete a final audit report for each entity within 30 business days after the auditee’s response. OCR will share a copy of the final report with the audited entity.

What if an entity doesn’t respond to OCR’s requests for HIPAA audit ?

If an entity does not respond to requests for information from OCR, including address verification, the pre-screening audit questionnaire and the document request of those selected entities, OCR will use publically available information about the entity to create its audit pool.  An entity that does not respond to OCR may still be selected for an audit or subject to a compliance review.

How will the Phase 2 HIPAA audit program work?

OCR plans to conduct desk and onsite audits for both Covered Entities and their Business Associates. The first set of audits will be desk audits of covered entities followed by a second round of desk audits of business associates. These audits will examine compliance with specific requirements of the Privacy, Security, or Breach Notification Rules and auditees will be notified of the subject(s) of their audit in a document request letter.  All desk audits in this phase will be completed by the end of December 2016.

The third set of audits will be onsite and will examine a broader scope of requirements from the HIPAA Rules than desk audits. Some desk auditees may be subject to a subsequent onsite audit. The audit process will employ common audit techniques. Entities selected for an audit will be sent an email notification of their selection and will be asked to provide documents and other data in response to a document request letter. Audited entities will submit documents on-line via a new secure audit portal on OCR’s website. There will be fewer in-person visits during these Phase Two audits than in Phase One, but auditees should be prepared for a site visit when OCR deems it appropriate.  Auditors will review documentation and then develop and share draft findings with the entity.  Auditees will have the opportunity to respond to these draft findings; their written responses will be included in the final audit report.  Audit reports generally describe how the audit was conducted, discuss any findings, and contain entity responses to the draft findings.

How will the selection process work for Phase 2 HIPAA audit?

Once entity contact information is obtained, a questionnaire designed to gather data about the size, type, and operations of potential auditees will be sent to Covered Entities and Business Associates. As a part of the pre-audit screening questionnaire, OCR is asking that entities identify their business associates. We encourage covered entities to prepare a list of each business associate with contact information so that they are able to respond to this request. OCR will conduct a random sample of entities in the audit pool. Selected auditees will then be notified of their participation.

If a Covered Entity or Business Associate fails to respond to information requests, OCR will use publically available information about the entity to create its audit pool.  An entity that does not respond to OCR may still be selected for an audit or subject to a compliance review.

What is the basis for being selected in the Phase 2 HIPAA audit ?

For this phase of the audit program, OCR is identifying pools of Covered Entities and Business Associates that represent a wide range of health care providers, health plans, health care clearinghouses and business associates.  By looking at a broad spectrum of audit candidates, OCR can better assess HIPAA compliance across the industry – factoring in size, types and operations of potential auditees. Sampling criteria for auditee selection will include size of the entity, affiliation with other healthcare organizations, the type of entity and its relationship to individuals, whether an organization is public or private, geographic factors, and present enforcement activity with OCR. OCR will not audit entities with an open complaint investigation or that are currently undergoing a compliance review.

Who will be audited in HIPAA phase 2 audit ?

Every Covered Entity and Business Associate are eligible for an audit. These include covered individual and organizational providers of health services; health plans of all sizes and functions; health care clearinghouses; and a range of business associates of these entities. OCR expectx Covered Entities and Business Associates to provide the auditors their full cooperation and support.

When will HIPAA phase 2 audits in 2016 will commence?

Phase Two of OCR’s HIPAA audit program is currently underway. OCR has begun to obtain and verify contact information to identify covered entities and business associates of various types and determine which are appropriate to be included in potential auditee pools.  Communications from OCR will be sent via email and may be incorrectly classified as spam. If your entity’s spam filtering and virus protection are automatically enabled, we expect you to check your junk or spam email folder for emails from OCR; OSOCRAudit@hhs.gov. Click here to view sample e-mail >>

How can we help? – Call 866-276-8309, or e-mail us at info@ehr20.com