25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

HIPAA Audits to Recommence in 2015

Following on from a series of pilot HIPAA audits, the HHS Office for Civil Rights (OCR) is planning a second round of random audits to ensure healthcare organizations are fully compliant with current HIPAA regulations. The next round of audits will also carry severe financial penalties for any violations uncovered.

The next round of HIPAA audits was planned to start in October 2014, although the date has now been pushed back until 2015. It was announced at the San Diego American Health Information Management Association (AHIMA) annual convention that a round of 350 audits would be conducted on healthcare organizations, with a further 50 audits to be conducted on business associates to ensure compliance. Insurers and clearinghouses will also be subjected to audits in 2015.

The healthcare organizations due to be audited have already been selected, although entities have also been selected to ensure better coverage across the whole of the United States and to ensure that a good diversity of entities are assessed for HIPAA compliance.  This only gives healthcare organisations a few more months to find pager replacements that are HIPAA compliant.

The delay to the audits is believed to be largely due to issues with the OCR website which is currently being updated to be more user friendly. Subjects selected for audit will be required to use the system to download and print out documents.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Since the OCR started its audit program it has collected $26 million from the financial penalties it imposed on organizations which breached HIPAA rules, and during the past 6 years has issued 23 settlement agreements ranging from $125,000 to $4.5 million, depending on the nature of the violation and damage caused.

While large organizations, hospitals and healthcare centers are to be included in the audits, small healthcare companies will not escape scrutiny on procedures and policies covering data security and privacy. Even individuals are not exempt from the new audits.

The message given by the OCR is clear. Every organization and individual covered by HIPAA regulations must ensure full compliance with the legislation and recent amendments. Risk assessments must be conducted and emergency response procedures defined and implemented.

While the audits will assess the procedures and technology used to prevent unauthorized access to patient data, organizations will also be assessed on how patient access to PHI is handled and whether any blocks to patient access rights still exist.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist