
The Gap Most HIPAA Programs Don’t Know They Have
Most healthcare organizations can point to a Security Risk Assessment, a stack of policies, and a training log. That satisfies the letter of HIPAA’s requirements. But it answers a different question than the one OCR actually asks when it opens an investigation.
OCR doesn’t audit against your policies. It audits against its own published protocol — a provision-by-provision standard covering the Privacy, Security, and Breach Notification Rules, complete with the exact evidence auditors are trained to request and the exact criteria they use to judge it.
If your compliance program has never been measured against that standard, you don’t actually know how it would hold up — you know it exists, not whether it’s defensible.

What We Do
Colington Consulting’s OCR Audit Protocol Readiness Assessment evaluates your organization against OCR’s own HIPAA Audit Program Protocol — the identical framework OCR uses to assess covered entities during a real audit or post-breach investigation.
This isn’t a generic checklist or a self-scored questionnaire. It’s a structured, evidence-based review conducted by a named evaluator, provision by provision, producing a determination and a documented record that mirrors what an actual OCR audit would produce — before OCR ever asks.

What Sets It Apart
- Built from OCR’s actual protocol — not a third-party interpretation of it, but the same CFR citations, performance criteria, and audit inquiries OCR auditors are trained to apply
- Evidence-driven, not self-attested — your organization gathers the specific documentation OCR would request; our evaluator reviews it and makes the compliance determination
- A named evaluator behind every finding — the difference between “we believe we’re compliant” and “an independent reviewer verified it against the federal standard, with the documentation to show it”
- A defensible record, not a marketing claim — there is no such thing as official “HIPAA certification,” and any vendor claiming to offer one isn’t telling you something OCR recognizes. What we produce instead is documented, evidence-backed proof that your program was measured against the real standard and where it stood then

Who This is For
This assessment is most valuable for organizations where the cost of an OCR finding — financial, reputational, or contractual — is high enough that “probably fine” isn’t good enough:
- Health systems and larger provider groups with multiple locations, higher breach exposure, and more OCR scrutiny
- Self-insured health plans, where OCR’s current enforcement priorities specifically target risk analysis rigor and Business Associate oversight
- Hybrid entities, where the line between covered and non-covered functions is exactly the kind of structural risk OCR’s protocol is built to catch
- Organizations heading into a renewal cycle, an M&A transaction, or a payer credentialing review where a defensible compliance record carries real weight
- Any organization that has completed a Security Risk Assessment and wants to know what the next level of readiness actually looks like

How It Works
- Evidence request — your organization receives a structured list of the specific documents OCR itself would request, organized to match the protocol
- Evaluator review — our evaluator reviews what you provide against OCR’s established performance criteria for each provision and makes the compliance determination
- Documented findings — every determination is recorded with supporting narrative, producing a report structured closely enough to OCR’s own protocol to serve as evidence of a good-faith readiness review
- A clear picture, not just a score — you leave knowing exactly where your program stands against the federal standard, and exactly what to fix if it doesn’t
OCR Audit Readiness FAQ Section
What is the difference between a standard HIPAA Security Risk Assessment (SRA) and an OCR Audit Protocol Assessment?
A standard Security Risk Assessment satisfies basic administrative requirements by identifying potential risks to Electronic Protected Health Information (ePHI). An OCR Audit Protocol Assessment measures your organization against the provision-by-provision standards, performance criteria, and documentation inquiries OCR auditors use during an official audit or investigation across the Privacy, Security, and Breach Notification Rules.
Does completing this assessment provide official “HIPAA Certification”?
No. The U.S. Department of Health and Human Services (HHS) and OCR do not recognize or offer official “HIPAA certification.” Instead, this service provides an evidence-based review with a named evaluator, creating documented proof that your compliance program was independently evaluated against federal standards.
What documentation or evidence will our organization need to provide?
You will receive a structured list of documents aligned with OCR’s audit framework. This typically includes written policies and procedures, risk management plans, Business Associate Agreements (BAAs), employee training logs, incident response logs, and technical safeguard configurations.
Who evaluates our evidence, and how are findings delivered?
An experienced evaluator at Colington Consulting reviews your submitted documentation against OCR performance criteria. We record every finding with a detailed supporting narrative and categorize the determinations, delivering a structured report that serves as evidence of a good-faith compliance review.
Why should an organization undergo an OCR Audit Protocol Assessment if it isn’t legally required?
While HIPAA mandates a Security Risk Assessment, evaluating your program against the OCR Audit Protocol is optional. Organizations choose this assessment to make their compliance programs truly defensible. Instead of relying on basic compliance logs, measure your controls against actual OCR auditor inquiry criteria to uncover hidden gaps, show good-faith compliance efforts, and prepare for potential audits, post-breach investigations, or M&A due diligence.

Schedule a Consultation
Contact us to find out where your compliance program stands against the standard that actually matters.
