Check and double-check your HIPAA policies and procedures.
The HHS Office for Civil Rights’ new phase of HIPAA audits are in full swing, so you should make sure you’ll pass them with flying colors should OCR auditors knock on your door.
During the OCR’s desk audits, the agency will be reviewing privacy policies relating to the Privacy, Security, and Breach Notification Rules, says San Francisco-based privacy attorney Diana Maier. “OCR has also said that they expect audited entities to respond to their initial request for documentation within ten business days by submitting documents electronically via their secure, online portal.
To prepare for a potential audit, I always recommend that covered entities and business associates ensure that they have written privacy policies consistent with their requirements under HIPAA.”
In addition, she recommends that her clients run the Security Risk Assessment Tool, which is available online. “This isn’t required by the HIPAA Security Rule, but it is meant to assist with a risk assessment and can be a great resource for identifying areas of vulnerability,” she advises. Maier also suggests the following steps during your audit preparation:
Attorney Neil Eggeson of Eggeson Appellate Services in Indianapolis offers this advice:
Although it’s never too late to tighten up your HIPAA program, chances are that if you get an audit notification today and you haven’t yet launched a privacy program, you could get zinged by an auditor, Eggeson warns.