OCR Audit Protocol Readiness Assessment

Is Your Compliance Program Defensible — Or Just Documented?

Most organizations can point to a risk assessment, a stack of policies, and a training log — but that’s not the standard OCR audits against. OCR audits against its own published protocol. If your program has never been measured against that standard, you don’t know if it’s defensible — you just know it exists.

The Gap Most HIPAA Programs Don’t Know They Have

Most healthcare organizations can point to a Security Risk Assessment, a stack of policies, and a training log. That satisfies the letter of HIPAA’s requirements. But it answers a different question than the one OCR actually asks when it opens an investigation.

OCR doesn’t audit against your policies. It audits against its own published protocol — a provision-by-provision standard covering the Privacy, Security, and Breach Notification Rules, complete with the exact evidence auditors are trained to request and the exact criteria they use to judge it.

If your compliance program has never been measured against that standard, you don’t actually know how it would hold up — you know it exists, not whether it’s defensible.

What We Do

Colington Consulting’s OCR Audit Protocol Readiness Assessment evaluates your organization against OCR’s own HIPAA Audit Program Protocol — the identical framework OCR uses to assess covered entities during a real audit or post-breach investigation.

This isn’t a generic checklist or a self-scored questionnaire. It’s a structured, evidence-based review conducted by a named evaluator, provision by provision, producing a determination and a documented record that mirrors what an actual OCR audit would produce — before OCR ever asks.

What Sets It Apart

  • Built from OCR’s actual protocol — not a third-party interpretation of it, but the same CFR citations, performance criteria, and audit inquiries OCR auditors are trained to apply
  • Evidence-driven, not self-attested — your organization gathers the specific documentation OCR would request; our evaluator reviews it and makes the compliance determination
  • A named evaluator behind every finding — the difference between “we believe we’re compliant” and “an independent reviewer verified it against the federal standard, with the documentation to show it”
  • A defensible record, not a marketing claim — there is no such thing as official “HIPAA certification,” and any vendor claiming to offer one isn’t telling you something OCR recognizes. What we produce instead is documented, evidence-backed proof that your program was measured against the real standard and where it stood then

Who This is For

This assessment is most valuable for organizations where the cost of an OCR finding — financial, reputational, or contractual — is high enough that “probably fine” isn’t good enough:

  • Health systems and larger provider groups with multiple locations, higher breach exposure, and more OCR scrutiny
  • Self-insured health plans, where OCR’s current enforcement priorities specifically target risk analysis rigor and Business Associate oversight
  • Hybrid entities, where the line between covered and non-covered functions is exactly the kind of structural risk OCR’s protocol is built to catch
  • Organizations heading into a renewal cycle, an M&A transaction, or a payer credentialing review where a defensible compliance record carries real weight
  • Any organization that has completed a Security Risk Assessment and wants to know what the next level of readiness actually looks like

How It Works

  1. Evidence request — your organization receives a structured list of the specific documents OCR itself would request, organized to match the protocol
  2. Evaluator review — our evaluator reviews what you provide against OCR’s established performance criteria for each provision and makes the compliance determination
  3. Documented findings — every determination is recorded with supporting narrative, producing a report structured closely enough to OCR’s own protocol to serve as evidence of a good-faith readiness review
  4. A clear picture, not just a score — you leave knowing exactly where your program stands against the federal standard, and exactly what to fix if it doesn’t

OCR Audit Readiness FAQ Section

What is the difference between a standard HIPAA Security Risk Assessment (SRA) and an OCR Audit Protocol Assessment?

Does completing this assessment provide official “HIPAA Certification”?

What documentation or evidence will our organization need to provide?

Who evaluates our evidence, and how are findings delivered?

Why should an organization undergo an OCR Audit Protocol Assessment if it isn’t legally required?

Office tools on a desk

Schedule a Consultation

Contact us to find out where your compliance program stands against the standard that actually matters.