HIPAA Handbooks

  • Privacy and security training for new and seasoned staff
  • 11 staff/setting focus areas
  • Education on protecting PHI
  • HITECH Act updates
  • Discounts on bulk purchases

More»

E-learning

  • Role-based training using real-life case scenarios
  • Test-your-knowledge exercises with remediation
  • Post-course test to document staff participation

More»

Other HIPAA Resources

  • Hot-topic audio conferences
  • CD-Rom, books on privacy and security
  • Business associate training
  • Videos with real-life HIPAA scenarios

More»

Sep
27

OCR official answers audit questions

Email This Post Print This Post

Editor’s note: The following excerpt from the September Briefings on HIPAA is the third in a series of questions answered by Susan McAndrew, JD, deputy director of health information privacy for the Office for Civil Rights (OCR).

What is the anticipated scope of these OCR HIPAA audits?

"OCR will look at overall compliance efforts as a way to ensure that effective protocols are in place for the audits of both the Privacy and Security Rules," says Susan McAndrew, JD, deputy director of health information privacy for HHS' OCR. Thus, rather than focusing its audits on a specific set of issues, OCR will be taking a general look at an entity's compliance.

Organizations selected for an audit will receive notification beforehand.

"The audit process will include standard components associated with most audits," says McAndrew.

For example, preliminary steps, such as document requests, will occur, she says. After on-site visits, auditors will send audited organizations reports and will communicate with CEs to ensure that everyone understands these reports, says McAndrew. "Audit reports generally describe how the audit was ­conducted, what the findings were, and what actions the covered entity is taking in response to those findings," she says.
 

Categories : HHS

Comments are closed.