Traditionally, OCR would audit covered entities when such entities submitted reports of breaches. Now, the OCR plans to conduct periodic audits to ensure continued compliance with HIPAA’s security rule, as opposed to retroactive auditing.
According to the report, initial audits will consist of “desk audits” in which OCR will ask entities to submit security policies and procedures for review. Some in-person audits may occur.
More articles on HIPAA:
Vermont physician office burglarized, 2,000 records compromised
Why are healthcare data breaches so common?
Fitbit adds HIPAA compliance features to its Wellness division
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.