Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

HIPAA Audit Activities Increase in 2016

Kelly Tyrrell  |  August 17, 2016

The first series of desk audits will focus on covered entities, and the second will look at business associates. The OCR expects desk audits to be completed by December 2016. A third series of audits will involve on-site visits, which the OCR says will “examine a broader scope of requirements from the HIPAA rules than desk audits.” An entity may be selected for a desk and an on-site audit.

The Penalties
The OCR is considering size and type of covered entity, geography, affiliations and whether an entity is public or private for audit selection criteria. The agency can assess criminal or civil penalties for violations. Civil penalties fit four tiers that range from accidental noncompliance to purposeful violation without correction. Penalties include fees up to $1.5 million annually and/or jail time for up to 10 years.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

“It’s getting continually harder for small physician groups to fully comply with HIPAA when even large institutions often are not doing so,” says Ms. Yaffe.


Kelly April Tyrrell writes about health, science and health policy. She lives in Madison, Wis.

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

Reference

  1. Murrin S. OCR should strengthen its oversight of covered entities’ compliance with the HIPAA Privacy Standards. Department of Health and Human Services Office of the Inspector General. 2016 Jul. https://oig.hhs.gov/oei/reports/oei-09-10-00510.pdf.

Page: 1 2 | Single Page
Share: 

Filed under:Practice SupportProfessional Topics Tagged with:HIPAA auditHIPAA complianceOffice for Civil Rights

Related Articles

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

    Preparing for Increased HIPAA Audits Among Smaller Rheumatology Providers

    May 13, 2016

    Recent enforcement activities of the Department of Health and Human Services’ Office for Civil Rights (OCR) have shown an increase in fines and penalties assessed against smaller providers for failing to comply with the privacy, security and breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA). Historically, OCR has focused on larger…

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties

    April 1, 2013

    Physicians’ business associates can now face civil and criminal penalties for violating HIPAA laws guarding the confidentiality of protected health information

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences