Dental practices can be chosen for a formal HIPAA compliance audit by OCR's periodic audit program, regardless of whether or not they've suffered a breach or been the subject of a complaint. According to the HHS audit program page, the HITECH Act, “Requires HHS to periodically audit covered entities and business associates” for compliance with the HIPAA Rules.
Patient complaints, reported breaches, ransomware attacks, and other tips of potential noncompliance may trigger an investigation or compliance review, but not a formal audit. The HHS’s summation of how they enforce the Privacy & Security Rules, notes it "investigate[s] complaints filed with it" as well as "may also conduct compliance reviews" to confirm covered entities are following HIPAA rules. The American Dental Association (ADA) also notes OCR "can require a covered dental practice to produce documentation of HIPAA compliance" during such investigations or compliance reviews.
Does an audit always have to be conducted by the HHS?
Healthcare providers can perform self-assessments or hire a third-party compliance consultant to evaluate their safeguards and documentation. But HIPAA audits in the context of federal regulatory enforcement are performed by the OCR as part of the HIPAA Audit Program.
The HHS states, “OCR uses the audit program to assess the HIPAA compliance efforts of a range of entities covered by HIPAA regulations.” The audits will employ a detailed protocol to evaluate covered entities’ and business associates’ compliance with the Privacy Rule, Security Rule, and Breach Notification Rule requirements.
HIPAA audits are also different from complaint investigations and compliance reviews. OCR might launch an investigation due to a complaint filed or start a compliance review because of a breach notice, media story, agency referral or another potential compliance issue. These are enforcement actions, not part of OCR’s periodic audits.
The HHS agency is not the only government entity with the authority to investigate HIPAA. Under the HITECH Act, state attorneys general can file civil lawsuits on behalf of state residents for certain violations of the HIPAA Privacy and Security Rules, but a state-led inquiry or civil suit would be an enforcement action, not an OCR HIPAA Audit Program audit.
Understanding what a HIPAA audit evaluates
Healthcare organizations can be better prepared if they know what auditors will be looking at. According to the OCR, HIPAA audits will focus on the policies and procedures and technical safeguards that dental practices have implemented to comply with the HIPAA rules. The audits aren’t necessarily looking for one specific form of paperwork; instead, they will be checking to see if HIPPA compliance is part of the practice's daily routine.
Here are some common areas that dental offices will be audited on:
- Patient privacy policies
- Risk assessments
- Workforce training documentation
- Business associate agreements
- Access controls
- Email encryption
- Incident response plans
- Audit logs
Build compliance into daily workflows
Dental practices often think of HIPAA as an annual checklist but compliance is an operational process. A review published in Dental Clinics of North America states, "Under the Health Insurance Portability and Accountability Act (HIPAA) of 1996, all dental offices are required to formulate policies and procedures to ensure and secure patient privacy of health information."
Staff members should consistently follow those policies during patient scheduling, treatment coordination, billing, referrals, and follow-up communication. HIPAA compliant email makes these policies easier to implement by providing a secure communication channel that staff can use instead of personal email accounts or consumer messaging platforms. As such, practices reduce unnecessary variation while improving documentation.
Completing a comprehensive security risk assessment is likely one of the most beneficial audit prep activities dental practices can do. The ADA advisory on email use provides that a practice's written security risk analysis should assess where electronic patient information is stored, how the information is transmitted, what risks exist with those systems, and how identified risks will be addressed.
Invest in workforce training
Training can help create a more aware workforce. However, in a study published in JAMA Network Open, researchers concluded that healthcare employees are still vulnerable to phishing emails. Across over 2.9 million simulated phishing emails sent to healthcare employees, researchers discovered a median click rate of 16.7%. What's more, researchers also discovered that "repeated phishing campaigns were associated with decreased odds of clicking on a subsequent phishing email" showing that repeated training can help promote better security habits over time.
However, good training has to be accompanied by solid security tools. The Healthcare Email Security Maturity Index Report revealed that 58% of healthcare organizations reported an email-related breach in the last 24 months. Among organizations that experienced a breach, 47% said that improving or strengthening encryption was their number one priority after the breach. It was higher than the percentage that said they wanted additional training for staff or new security tools.
Education can and should help dental practice staff identify protected health information (PHI), confirm the recipient is who they say they are before sending sensitive data, identify phishing emails, report suspicious emails that might be phishing attempts, and understand the organization's communication policy.
Evaluate patient communication practices
Email is a central communication channel for dental practices. Providers send appointment reminders, treatment estimates, post-op instructions, insurance communications, referral letters, and billing alerts via email because it’s fast, easy, and most patients expect it. As email continues to play a bigger role in patient care, it’s necessary to keep those messages secure.
It’s why the American Dental Association now suggests dental practices assess how patient information is sent via email during their HIPAA security risk analysis. Email is now used to send PHI, which means that email communications should be considered clinical coordination.
One thing dental teams should remember is that email remains a common attack vector. The 2025 Paubox Healthcare Email Security Report found that 180 healthcare organizations suffered email-based breaches in 2024, and only 5% of phishing attacks are submitted to security teams by employees. It can also be harder to spot trends before they impact more employees or patients, so make sure dental practices have the secure tools and training to spot phishing emails.
FAQs
Are HIPAA audits the same as complaint investigations?
An audit is a proactive assessment of a selected organization’s compliance. An investigation may begin after a complaint, breach report, or other evidence of possible noncompliance.
What happens if OCR identifies compliance gaps?
The outcome depends on the type and seriousness of the findings. During an enforcement investigation, OCR generally seeks voluntary compliance, corrective action, or a resolution agreement. If the organization does not resolve the matter satisfactorily, OCR may impose civil monetary penalties under the HIPAA Enforcement Rule.
Are state dental boards responsible for HIPAA audits?
OCR oversees federal HIPAA audits, not the ADA or state dental boards. However, state attorneys general can bring civil actions for certain HIPAA violations, and dental boards may separately address state privacy laws or professional standards.
