25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

OCR Confirms HIPAA Compliance Audit Surveys Sent

There has been much speculation over the past week since the sending of the letters was first reported, about whether the OCR pre-screening surveys have actually been dispatched. Now the Department of Health and Human Services’ Office for Civil Rights has confirmed – to Fierce Health IT – that its preliminary HIPAA surveys have now been dispatched, marking the start of the 2015 HIPAA compliance audits.

In an article in the National Law Review on Monday, McDermott Will & Emery announced that phase 2 of the HIPAA compliance audits was no longer being delayed, after the firm had been notified by some of its clients that an OCR HIPAA audit screening survey had been received.

The purpose of the screening surveys is to ensure that all contact and organization information is correct. The OCR auditors can then select the organizations most appropriate for audit. From the responses, the OCR is expected to select 350 covered entities and 50 Business Associates for an audit on the Security Rule, Privacy Rule, Breach Notification Rule or a combination audit comprising 2 or 3 audit modules.

The OCR is expected to audit healthcare providers, health plans and healthcare clearinghouses first, with Business Associate HIPAA audits to follow.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

It is not clear at this stage whether the surveys have been sent out to all 1,200 entities that formed the initial sample or if Business Associates have been contacted yet. According to McDermott Will & Emery, the OCR is working with a pool of 550 and 800 CEs. If this is the case, any covered entity receiving a survey may have a 50% chance or higher of being audited.

Start Date of Second Round HIPAA Audits not yet Announced

The OCR statement, issued by e-mail, confirmed that the pre-audit surveys had been sent, but no information was provided as to when the second round of compliance audits will be taking place. According to the original schedule for the audits that were supposed to commence in the fall of 2014, the surveys were scheduled to be sent around this time of year indicating that the audits will only have been delayed a year and will take place this fall.

The statement said “Additional information about the audit program is forthcoming,” with covered entities instructed to “Check our website for updates.”

Once the notice is placed on the OCR website, the audits are expected to commence approximately 90 days later, giving covered entities three more months to ensure they are fully HIPAA-compliant before it is put to the test.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist