By Fisher, JD, CHC, CCEP
What Does the HIPAA Phase 2 Audit Program Mean for Providers?
OCR Announces HIPAA Phase 2 Audit Program
The HHS Office for Civil Rights (“OCR”) has officially announced the commencement of its 2016 Phase 2 HIPAA Audit Program. During Phase 2, OCR will review the policies and procedures of covered entities and their business associates to determine whether they have properly implemented and satisfied the standards and implementation specifications of the HIPAA privacy, security, and breach notification rules.
For the most part, Phase 2 audits will involve document review to assess compliance with policy and procedure requirements. In cases of noncompliance, the initial document review may lead to a formal site visit and a more comprehensive HIPAA audit.
What Providers Can Expect
OCR will send an email to covered entities and business associates requesting verification of each organization’s address and contact information. This will be followed by a pre-audit questionnaire asking for information about the size, type, and operations of covered entities and business associates. OCR will use this information, together with other data, to create potential audit subject pools.
Providers should respond to OCR’s requests within the specified timeframes. Failure to respond may increase the likelihood of further audit activity and scrutiny. OCR is expected to release additional details regarding audit protocols in the near future.
Why Phase 2 Matters
A provider’s chance of being audited is greater under the Phase 2 Audit Program than under the prior phase. Although not every provider will be selected, OCR is using the increased possibility of audit to encourage providers to prepare and strengthen their policies, procedures, business associate agreements, compliance documentation, and related practices.
Given the public nature of the program and the amount of time providers have had to prepare, Phase 2 audits are likely to be less forgiving than the previous phase.
Recommended Next Steps for Providers
Providers should use this opportunity to confirm that their HIPAA practices, policies, and procedures comply with applicable legal requirements. They may also consider performing an effectiveness audit of their HIPAA policies and processes to identify gaps in policy or practice that could lead to further investigation under the Phase 2 program. Even though no specific provider is certain to be audited, some providers will be selected. Every provider should be prepared for that possibility.
