HIPAA Privacy and Security Audit Program:ย The Office of Civil Rights (โOCRโ), which is the division of the Department of Health and Human Services (โHHSโ) that is responsible for enforcement of the HIPAA Privacy and Security Rules and the Breach Notification standards, recently announced the โpilot phaseโ of a HIPAA audit initiative beginning immediately and extending through December of 2012.
According to the OCRโs website, over the next year this initiative will include a broad range of HIPAA covered entities, including group health plans, health care providers, and health care clearinghouses.ย Although HIPAA business associates are not the target of the initial pilot program, OCR indicates that business associates will be included in future audits.
The beginning of this OCRโs formal audit program serves to highlight the importance of periodic review of group health plan HIPAA compliance by plan sponsors.ย This HIPAA compliance review should include, at a minimum, the following steps:
Conducting this compliance review in the near future will ensure that your companyโs group health plan is not caught off guard by a HIPAA audit, and avoid the potential imposition of noncompliance penalties by OCR.