The OCR has not performed required audits of corporations that handle protected patient information, has not sufficiently documented decisions made regarding potential privacy violations and has failed to properly safeguard its own records, according to the report.
The report recommends the OCR conduct periodic audits as outlined in the HITECH Act to ensure compliance at all HIPAA-covered entities, as well as readjust the auditing program to comply with federal regulations.
More Articles on HIPAA:
The 10 Biggest Hospital Stories of 2013
7 Best Practices for HIPAA Mobile Device Security
GAO Calls for Updated Consumer Privacy Framework
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.