Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

HIPAA Audit Activities Increase in 2016

Kelly Tyrrell  |  August 17, 2016

In the coming months, rheumatologists may want to pay particular attention to their email inboxes. By the end of the year, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) will complete stage I, phase II of a series of desk and on-site audits designed to assess providers and their business partners for compliance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996. Those randomly selected for audit will be notified by email, the HHS says.

What to Do If You’re Chosen
Physicians who are notified should ask what materials are being audited so the practice can pull together the requested information to review.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Rachel Yaffe, a Chicago-based healthcare attorney with McDonald Hopkins LLC, says “contact [your] healthcare attorney immediately—ideally someone who specializes in HIPAA compliance. They can assist with timelines, documentation and complying with the request, [and they can] also help you know what’s within your rights.”

OCR Under Review
Phase II of the OCR’s audits is a continuation of a process that began in 2011–2012 following a review of the OCR’s audit activity. The review was conducted by the HHS Office of the Inspector General (OIG), and the findings, which were presented in a report published last year, determined that the OCR had been less than thorough in its assessment and enforcement of penalties associated with HIPAA breaches or breach risk.1

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

“OCR should strengthen its oversight of covered entities’ compliance with the Privacy Rule,” the report said. “OCR’s oversight is primarily reactive; it investigates possible noncompliance primarily in response to complaints. OCR has not fully implemented the required audit program to proactively assess possible noncompliance from covered entities.”

The Health Information Technology for Economic and Clinical Health Act (HITECH), part of the 2009 American Recovery and Reinvestment Act, requires the OCR to conduct such audits of covered entities, which include hospitals, doctors, pharmacies, health insurance companies and more. It also gave equal legal liability to businesses that handle patient data.

“If you’re going to be a vendor in the healthcare space, you have to play by healthcare rules,” Ms. Yaffe says.

One such rule: Under HIPAA, every practice or healthcare organization must designate a privacy officer to oversee all activities related to the development, implementation and maintenance of the practice’s or organization’s privacy policies in accordance with applicable federal and state laws.

Focus on Smaller Providers
Although previous audits have focused primarily on large providers, the latest round will be directed at smaller providers and their risks for HIPAA breaches. The OIG report found smaller covered entities were less likely to be investigated for small breaches (impacting fewer than 500 patients) than larger entities.

Page: 1 2 | Single Page
Share: 

Filed under:Practice SupportProfessional Topics Tagged with:HIPAA auditHIPAA complianceOffice for Civil Rights

Related Articles

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

    Preparing for Increased HIPAA Audits Among Smaller Rheumatology Providers

    May 13, 2016

    Recent enforcement activities of the Department of Health and Human Services’ Office for Civil Rights (OCR) have shown an increase in fines and penalties assessed against smaller providers for failing to comply with the privacy, security and breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA). Historically, OCR has focused on larger…

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties

    April 1, 2013

    Physicians’ business associates can now face civil and criminal penalties for violating HIPAA laws guarding the confidentiality of protected health information

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences