HIPAA audits assess whether covered entities and business associates are complying with the requirements of the Health Insurance Portability and Accountability Act (HIPAA). The audits examine an organization’s policies, procedures, safeguards, and documentation to determine whether it is appropriately protecting protected health information (PHI), including electronic PHI (ePHI). Adhering to these audit requirements helps effectively preserve the PHI of patients, reduce the risks of data breaches, and ensure conformity with the stipulated provisions of HIPAA standards for both parties involved.
Who is audited?
Every covered entity and business associate is eligible to be selected for a HIPAA audit, regardless of whether the organization has received a complaint or experienced a reported privacy or security incident. The selection process may follow one of two directions:
- Random selection: “Under the Health Insurance Portability and Accountability Act (HIPAA), various organizations can be randomly selected to be audited – even if no complaint has been issued against them and even if there has been no privacy incident or breach,” writes Daniel Solove. The Office for Civil Rights (OCR), which enforces HIPAA, may use a random selection process to identify entities for audit.
- Pre-audit questionnaire: Selected entities may receive a pre-audit questionnaire requesting information about their operations, privacy practices, and security measures. OCR can use this information to assess the entity's risk profile and determine the scope and focus of the audit.
What do auditors look at?
During a HIPAA audit, auditors evaluate whether an organization has appropriate safeguards, policies, and procedures in place to protect PHI and ePHI. Areas they may examine include:
Administrative safeguards (Security Rule)
- Security management process: The development and implementation of security policies and procedures.
- Security risk analysis: Entities are expected to conduct a comprehensive risk analysis to identify and mitigate potential risks to the confidentiality, integrity, and availability of electronic protected health information (ePHI).
- Security risk management: Implementation of measures to manage and mitigate identified risks.
- Information security officer: Designation of an individual responsible for overseeing the entity's information security program.
Physical safeguards (Security Rule)
- Facility access controls: Measures that limit physical access to facilities and electronic information systems.
- Workstation security: Policies and physical safeguards to protect electronic information on workstations.
- Device and media controls: Measures safeguarding the movement and disposal of hardware and electronic media containing ePHI.
Technical safeguards (Security Rule)
- Access control: Procedures to limit access to ePHI.
- Audit controls: Mechanisms to record and examine system activity.
- Integrity controls: Measures to ensure the integrity of ePHI.
- Transmission security: Safeguards to protect ePHI during transmission.
Policies and Procedures (Privacy and Security Rules)
- Privacy Rule compliance: Assess adherence to the Privacy Rule, which governs the use and disclosure of PHI.
- Security Rule compliance: Compliance with the Security Rule, which addresses the protection of ePHI.
Breach Response and Reporting
- Incident Response: Assess the entity's ability to respond to and contain security incidents.
- Breach Notification: Ensure that the entity has processes in place to promptly notify affected individuals and the appropriate authorities in the event of a data breach.
Read also: What are the HIPAA breach notification requirements
Documentation and Record-Keeping
- Documentation of policies and procedures: Auditors check whether the entity has documented policies and procedures in place.
- Training records: Verification of staff training records related to HIPAA compliance.
Go deeper:
- What is the HIPAA Security Rule?
- What is the HIPAA Privacy Rule?
- What are administrative, physical and technical safeguards?
Audit requirements
Learn the HIPAA compliance rules
In 1996, the HIPAA legislation was passed by the US Congress with two main objectives: streamlining medical operations and ensuring continuity of healthcare insurance when changing jobs. The Department of Health and Human Services (HHS) has since incorporated a set of compliance regulations to enforce PHI security measures and protect privacy.
- Privacy Rule: The HIPAA privacy rule ensures that healthcare providers safeguard the privacy of patient data. The rule outlines what healthcare providers can disclose about the patients’ data and how they can use it. It also guarantees the patients the right to access their PHI and medical records. The rule requires healthcare organizations to formulate and implement written privacy rules, notify such regulations to their patients in writing, and train their staff regularly.
- Security Rule: This rule requires healthcare providers to secure their patients’ PHI. More specifically, it outlines the standards required to protect ePHI, specifying how the covered entities and business associates should handle, manage, and transmit it.
- Omnibus Rule: The Omnibus Rule outlines the role of business associates in HIPAA. HHS enacted these regulations in 2013 to address policy gaps that existed in earlier HIPAA rules. The omnibus rule also provides new provisions required by the Health Information Technology for Economic and Clinical Health (HITECH) Act.
- Breach Notification Rule: The breach notification rule stipulates actions that healthcare providers must take in the event their systems are breached. The rule specifies the timelines for reporting breaches to the Office for Civil Rights (OCR) and individuals whose PHI has been breached and what measures the healthcare provider is undertaking to restore normalcy.
- Enforcement Rule: This rule empowers HHS to enforce security and privacy rules. It authorizes the OCR to probe HIPAA complaints, undertake compliance reviews, levy fines on non-compliant providers, and carry out education and outreach activities. The OCR also refers to possible criminal violations of HIPAA to the Department of Justice (DOJ) for further action.
See also: HIPAA Compliant Email: The Definitive Guide
Prepare for the HIPAA audit
There are six fundamental elements that you must consider to prepare for a HIPAA audit:
- Implement robust policies, standards, and procedures: Develop administrative systems and processes that meet the HIPAA compliance rules. Additionally, you need to ensure that your staff is trained routinely in all aspects of the HIPAA compliance processes.
- Implement strong technical and physical measures: Ensure that all the data relating to PHI is foolproof. Implementing robust technical standards such as limiting access to ePHI to authorized personnel, monitoring access logs for irregular activities, or using strong encryption can help you remain compliant. Besides technical standards, you also need to implement physical safeguards, such as restricting users who have physical access to certain offices and facilities.
- Undertake HIPAA risk assessment regularly: Risk assessment should be an ongoing process where you review your healthcare records periodically. This can help you track which entities have accessed ePHI and detect security breaches while evaluating the effectiveness of your measures.
- Report security breaches: Always notify the OCR and customers about any data breach whenever it occurs. You must also develop procedures that outline measures the organization will undertake if the systems get attacked.
- Investigate any violations and execute corrective measures: Investigate any identified violations thoroughly and take corrective actions.
- Document everything: Document measures that your organization has undertaken to address data breaches, contacts of all business associates, and HIPAA violations that have occurred within your systems.
Go deeper: How to prepare for a HIPAA audit
FAQS
How often do HIPAA audits occur?
There is no set frequency for HIPAA audits; they can occur at any time. However, the OCR may focus on entities that have reported breaches, have been the subject of complaints, or have been randomly selected as part of the OCR’s audit program.
Can entities be fined even if there was no data breach?
Yes, entities can be fined for failing to comply with HIPAA regulations, even if no data breach has occurred. Non-compliance with HIPAA standards, such as failure to conduct risk assessments or inadequate policies and procedures, can result in penalties.
How should entities handle third-party vendors in relation to HIPAA audits?
Entities must ensure that any third-party vendors handling PHI are HIPAA compliant. This involves entering into business associate agreements (BAAs) that outline the vendor’s responsibilities regarding PHI. During an audit, entities may need to provide evidence of these agreements and demonstrate that their vendors adhere to HIPAA standards.
