OCR HIPAA Audit Program and Audit Protocol Update

Yesterday, OCR posted on its website the protocol used to conduct the audits required by the HITECH Act. The OCR HIPAA Audit program analyzes key processes, controls, and policies of selected covered entities pursuant to the HITECH Act audit requirement. OCR established a comprehensive audit protocol that contains the requirements to be assessed through these performance audits. The entire audit protocol is organized around modules, representing separate elements of privacy, security, and breach notification. The combination of these multiple requirements may vary based on the type of covered entity selected for review.

The audit protocol covers Privacy Rule requirements for
(1) notice of privacy practices for PHI
(2) rights to request privacy protection for PHI
(3) access of individuals to PHI
(4) administrative requirements
(5) uses and disclosures of PHI
(6) amendment of PHI
(7) accounting of disclosures.

The protocol covers Security Rule requirements for administrative, physical, and technical safeguards.
The protocol covers requirements for the Breach Notification Rule.
Learn more by visiting the website at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/audit/index.html

Share this in :
The following two tabs change content below.
Our mission is to assist healthcare organizations and business associates in the development, design, and implementation of practices to secure IT systems and comply with HIPAA/HITECH privacy, security, breach and enforcement rules by protecting patient health information.

Latest posts by EHR 2.0 (see all)