Businessolver
Businessolver Blog

H&W: HIPAA Privacy and Security Audit Program

Get the Businessolver Blog in your inbox
Compliance Dashboard profile photo
By Compliance Dashboard
 on November 22, 2011
Share:

HIPAA Privacy and Security Audit ProgramHIPAA Privacy and Security Audit Program:ย The Office of Civil Rights (โ€œOCRโ€), which is the division of the Department of Health and Human Services (โ€œHHSโ€) that is responsible for enforcement of the HIPAA Privacy and Security Rules and the Breach Notification standards, recently announced the โ€œpilot phaseโ€ of a HIPAA audit initiative beginning immediately and extending through December of 2012.

According to the OCRโ€™s website, over the next year this initiative will include a broad range of HIPAA covered entities, including group health plans, health care providers, and health care clearinghouses.ย  Although HIPAA business associates are not the target of the initial pilot program, OCR indicates that business associates will be included in future audits.

The beginning of this OCRโ€™s formal audit program serves to highlight the importance of periodic review of group health plan HIPAA compliance by plan sponsors.ย  This HIPAA compliance review should include, at a minimum, the following steps:

  • Review of plan documentation to ensure that appropriate provisions addressing HIPAA obligations are included;
  • Implementation and periodic review of written HIPAA privacy policies and procedures;
  • Implementation and periodic review of required administrative, technical and physical safeguards related to electronic protected health information;
  • Implementation and documentation of a risk assessment and breach notification procedures;
  • Review of business associate agreements, as well as periodic audit of HIPAA compliance procedures adopted by business associates; and
  • Periodic workforce training regarding HIPAAโ€™s privacy and security requirements for those workforce members with access to group health plan information.

Conducting this compliance review in the near future will ensure that your companyโ€™s group health plan is not caught off guard by a HIPAA audit, and avoid the potential imposition of noncompliance penalties by OCR.