Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HIPAA Audits – Phase 2: On-Site Audits Scheduled for First Quarter of 2017

By Steven Grigas & Elizabeth F. Hodge on November 14, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

Covered Entities and Business Associates may be ringing in the New Year with the prospect of responding to on-site HIPAA audits by federal regulators. The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has announced that a certain number of comprehensive on-site HIPAA compliance reviews will be done over the first quarter of next year. Details of these audits are currently being finalized and will be posted on the OCR website in the coming months.

In a departure from the OCR’s Phase I HIPAA Audit Program, OCR staff will conduct the majority of such reviews with limited support from outside contractors. The stated purpose of such audits is to examine existing compliance measures, identify best practices, and discover problem areas likely to surface at a later date in time. OCR will use the audit reports to determine what types of technical assistance should be developed and what types of corrective action would be most helpful. The information gleaned from such audits may result in follow up investigations, fines and sanctions depending upon the severity of violations found. These onsite audits follow the desk audits of 167 Covered Entities that OCR began in July 2016. According to reports, OCR is still reviewing the voluminous documentation submitted in response to that audit. OCR is currently slated to begin desk audits of Business Associates this month. As with the covered entity desk audits, business associates will receive notice by email that they have been selected for a desk audit and will have ten (10) business days to respond to the request for documentation.  OCR expects to complete all desk audits for Phase II by December 31, 2016. Entities selected for a desk audit may also be chosen for an onsite audit.

To prepare for either a Phase 2 business associate desk audit or a covered entity onsite audit by OCR, we suggest that immediate consideration should be given to the following:

  • Perform a self-assessment and risk analysis of existing security and privacy measures.
  • Review existing risk management plans and protocols. Ensure that they are up to date and fully documented. If it is not documented – it never happened.
  • Organize all current and past HIPAA related documentation.
  • Review, update, and document personnel records to ensure that staff has completed necessary HIPAA training. If it is not documented – it never happened.
  • Review the published audit protocols of OCR to ensure readiness for the audit.
  • Review prior OCR alerts and advisories to ensure your current and prior practices are compliant.
  • Update and organize your listing of Business Associates (BA) and Business Associate Agreements (BAA). If you are a Business Associate ensure that existing protocols under your BAA are documented and compliant with HIPAA standards.
  •  Institute a plan and structure for the on-site audit, including:
    • Select which of your employees will participate in the audit;
    • Select site/work area for auditors to use;
    • Review and discuss operational aspects with participants and leadership;
    • Drill down on specific areas of weakness and discuss ways to respond if raised by audit staff

Should you have any questions regarding HIPAA compliance or the terms of this article, please contact the authors of this post to discuss further.

 

Photo of Steven Grigas Steven Grigas

A former interim Medicaid Director, Assistant Deputy Secretary, Deputy General Counsel, and Chief Medicaid Counsel for the State of Florida, Steven Grigas has presided over the State of Florida’s $15 billion Medicaid program with particular focus in managed care, disease management, pharmacy services…

A former interim Medicaid Director, Assistant Deputy Secretary, Deputy General Counsel, and Chief Medicaid Counsel for the State of Florida, Steven Grigas has presided over the State of Florida’s $15 billion Medicaid program with particular focus in managed care, disease management, pharmacy services, long term care, and hospital services.

Read more about Steven GrigasEmail
Show more Show less
Photo of Elizabeth F. Hodge Elizabeth F. Hodge

A former president of the Florida Academy of Healthcare Attorneys, Betsy Hodge concentrates her practice on compliance and regulatory issues affecting health care providers and payers and employer-sponsored health plans. Betsy has significant experience with HIPAA and the HITECH Act and assists covered…

A former president of the Florida Academy of Healthcare Attorneys, Betsy Hodge concentrates her practice on compliance and regulatory issues affecting health care providers and payers and employer-sponsored health plans. Betsy has significant experience with HIPAA and the HITECH Act and assists covered entities and business associates in complying with these laws through the development of policies and procedures, workforce training, analysis and notification of breaches, and assisting with government audits and investigations.  In addition, she counsels her clients on regulatory issues, including state and federal fraud and abuse laws.

Read more about Elizabeth F. HodgeEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Health Law Rx
  • Organization:
    Akerman LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo