Are you ready for the HIPAA audits? Or are you still feeling a bit lost? Patterson Dental recently shared an important audit update on their blog Off The Cusp, HIPAA Compliance: Next Round of Audits Postponed — but Beware! The HITECH Act of 2009 mandates the Office of Civil Rights (OCR) to perform compliance audits. The pilot audit phase was conducted during 2011-2012 included 115 covered entities. Plans for the Phase 2 mandatory HIPAA audits were announced earlier this year.
Findings from the pilot audits serve as the basis for developing the permanent audit protocols. The Phase 2 Audits target HIPAA Standards that showed the highest incidents of non-compliance in the pilot audits; including areas such as risk analysis and risk management, notice of privacy practices, training and policies and procedures.
Initially, the Phase 2 pre-audit surveys were supposed to be sent to 1,200 randomly selected covered entities and business associates. Subsequently, 300 covered entities and 50 business associates would be selected for a remote audit. Due to delays with the government’s web portal technology, the Phase 2 HIPAA audits have been postponed until 2015.
These audits will be a little trickier. Phase 2 Audits will be “desk audits” or remote audits conducted by OCR staff. If selected for an audit, you will upload the requested information to the OCR website. You won’t be given the opportunity to provide clarification or additional information. This phase will include fines for noncompliance.
Compliance Audits
Previously, the OCR announced the audit findings for the 300 covered entities. It is expected that 100 of those entities will be audited for compliance with the Privacy Rule (Notices of Privacy Practices and patient access to PHI); 100 will be audited on the Breach Notification Rule; and 150 will be audited on the risk analysis and management standards of the Security Rule. Business associate audits will only encompass risk analysis, risk management, and breach reporting to covered entities.
What if you are one of the “lucky” 350 covered entities selected for an audit? If that happens, act quickly, yet carefully. Here are two important tips if you are selected for an audit: 1.Pay close attention to the 2-week response deadline. The clock starts ticking based upon the postmark date, not the date you received the letter. 2.Understand the gravity of Phase 2 Audits. The pilot audits were performed onsite by subcontractors with no penalties levied.
Be Proactive, Self-Audit
However, before you are ever selected, be proactive. Conduct a self-audit and immediately correct any errors you find. Enlist the services of a qualified attorney or HIPAA expert if you are unsure how to self-audit. As Benjamin Franklin said, “Don’t put off until tomorrow what you can do today.” Maintaining compliance readiness is the best strategy.
For More Information
Ready to see how you would fare? Take this complimentary HIPAA assessment. Ready to become empowered with indepth knowledge of the requirements? Read about our HIPAA course and credentials.