How Prepared is Your Organization for a HIPAA Audit?

by Jay Hodes, President – Colington Consulting

Could your organization be prepared for an onsite HIPAA audit in ten days? Before you answer, let me explain what documentation you will need for the auditors, lawyers and investigators the U.S. Health and Human Services (HHS) Office for Civil Rights (OCR) will be sending to your office or business. ย 

One of the first documents OCR will be asking for is a copy of your most recent HIPAA Risk Assessment. ย Conducting a risk assessment is a regulatory requirement to determine the vulnerabilities and threats to any electronic protected health information your organization accesses, stores, creates or transmits. A checklist is not sufficient, and a comprehensive risk assessment needs to be made available to OCR. ย  ย 

OCR will be interested in seeing how your organization has attempted to mitigate those vulnerabilities and threats. Just conducting the assessment is not good enough. A remediation plan must be implemented. I always recommend a systematic approach to remediation by addressing high threats first, then on to moderates, and concluding with the lows if actionable items are needed. ย 

Once the risk assessment is provided, be prepared to hand over any number of HIPAA policies and procedures that an organization must have in place. How do you know what OCR will ask for? That is a tough question to answer. Based on my knowledge from others who have been onsite during an audit or investigation, all bets are off as far as which of those policies and procedures will be requested.ย 

When you look at the HIPAA Implementation Specifications, all of these must be covered with policies and procedures. As former Assistant Inspector General for Investigations in the HHS IGโ€™s office involved with the oversight of complex criminal investigations, my experience tells me OCR will ask for a lot, if not all, of policies and procedures generated by the organization. ย ย 

If I were to pick a handful of policies that OCR would be interested in seeing, I would include the Mobile Device Management Policy; Breach Notification Policy; Facility Security Plan and Policy; Audit Control Policy; and the Sanction Policy. All of these are critical areas that must be addressed with not only policy, but procedures on how to implement the policy. ย ย 

Expect OCR to request documentation regarding the annual HIPAA Security Awareness Training requirement. Your organization will need to show you provided this training to each member of your workforce. This includes all physicians, part-timers, interns and volunteers, along with the rest of the staff. ย 

I can tell you from my expertise in compliance, if you do not have all the HIPAA requirements currently in place, there is no way an organization can be prepared for audit in ten days. OCR will look for specific dates for items, such as when an access audit was conducted or when a HIPAA Risk Assessment was conducted, as well as entry dates on a maintenance record log. Your organization must be prepared as if any day now a letter is going to arrive from HHS indicating you have been identified for an audit. This will make it easier having required compliance requirements in place and minimize any concerns if that letter does come.

This blog was previously posted October 24, 2016