The US Department of Health and Human Services Office for Civil Rights (OCR) will soon begin a second phase of audits for compliance with HIPAA privacy, security and breach notification standards as required by the HITECH Act. In this second phase, OCR will audit both covered entities and their business associates, unlike the pilot audits of 2011 and 2012, which focused on covered entities alone. This On the Subject details practical steps that covered entities, including employer-sponsored group health plans, and their business associates can take to prepare for a potential audit.
Phase 2 HIPAA Audits Are Underway
By Anthony A. Bongiorno on May 5, 2016
Tags: covered entities, Department of Health and Human Services Office for Civil Rights, group health plan, Health Information Technology for Economic and Clinical Health, Health Insurance Portability and Accountability Act of 1996, HIPAA, HITECH Act, OCR, Phase 2 Audit, protected health information, risk assessment, Security and Breach Notification Standards

Anthony (Tony) A. Bongiorno has extensive jury trial experience in a variety of commercial matters and serves as the partner-in-charge of the Firm’s Boston office. Tony has successfully tried cases in various federal and state courts around the country. In addition to his significant jury trial experience, Tony has also tried matters under the auspices of the American Arbitration Association, the International Centre for Dispute Resolution and the International Chamber of Commerce. Tony has represented clients in many industries, including energy, health care, biotech and construction. Read Anthony A. Bongiorno's full bio.
Related Posts
- OCR Launches Phase 2 HIPAA Audit Program with Pre-Audit Screening Surveys
- OCR to Begin Phase 2 of HIPAA Audit Program
- HIPAA Privacy and Security Compliance for Group Health Plan Sponsors
- HHS Issues Guidance on Requirements Under HIPAA for Online Tracking Technologies, Addressing Privacy and Security Concerns Related to Health Information
- HIPAA Boss Sees ‘Low-Hanging Fruit’ Ripe For Enforcement
BLOG EDITORS
STAY CONNECTED
TOPICS
ARCHIVES
RECENT POSTS
- GOP Calls Biden’s Medicare Plans a Tax Hike on Small Businesses
- The Bosses May Be Back in Charge (but Not as Much as They Think)
- Coverage of COVID-19 Vaccines and the End of the COVID-19 Emergency
- NLRB Attacks Non-Disparagement and Confidentiality Clauses in Employee Releases, Severance Agreements
- District Court Vacates Provisions of No Surprises Act Final Rule

