Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

Phase 2 of HIPAA Audit Program Launches

From the College  |  Issue: May 2016  |  May 13, 2016

Understanding the differences between on- and off-site audits and what may be required is key to preparing for inquiries or audit letters. Off-site or desk audits refer to documentation requests by phone or electronic means and are usually limited in scope and pertain to one or two provisions under HIPAA. OCR representatives may also ask all covered entities for a list of their business associates to verify if there are signed agreements on file.

On-site audits are frequently more intensive and include visits by federal investigators to provider practices. It is mainly to look at a larger range of HIPAA requirements and verify that all compliance and permission policies are well documented and all requests were replied to in a timely manner. Bear in mind that all documentation must be current as of the request date and cannot be created after the inquiry. During on-site audits, providers should be prepared to answer questions and allow any other queries or questions directed to their staff. For example, HIPAA investigators may ask employees about their HIPAA privacy officer, whether they can bring work laptops home or email patients, and if so, what privacy safeguards are in place.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

While covered entities adopt new technologies to improve the quality and efficiency of patient care, practices are being held accountable for ensuring the safety and security of patient information. It should be noted that healthcare security is built around compliance, and even though an organization is HIPAA and HITECH compliant, it should not be taken for granted that there are security measures in place. Keep in mind that the main objective of the Security Rule is to protect the privacy of individuals’ health information. The goal of the OCR’s Phase 2 audit program intends to identify best practices and assess controls and processes that are implemented by all covered entities. It is imperative for practices to add a task to their to-do list to pull out their current HIPAA policy and procedure guidelines, spend some time verifying that security measures are in place to respond to and report any security breach of patient information.

Hopefully, organizations are staying abreast of the regulatory updates from OCR on the HIPAA audit process. Key steps include:

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE
  • Ensure emails are being monitored, because OCR messages may be routed to your spam or junk email folder. OCR has stated that it will be sending audit-related emails from [email protected]. All spam and junk email folders should be checked periodically for any correspondence from the agency. Failure to respond to an OCR email will not protect an entity from an audit; the agency plans to use publicly available information about entities that do not respond and include them in the audit pool.
  • Prepare a list of your business associates and have it readily accessible. Covered entities are encouraged to prepare a list in advance for responding to this request during this pre-audit phase in the event the practice is contacted.
  • Assign a security officer, or create an audit response team. As noted above, practices will have only 10 business days to respond to an OCR request for documentation, as well as only 10 business days to review the auditor’s draft findings. Preparation is the key, such as assigning a security officer or an audit team in advance to monitor your electronic systems as well as storage of printed documents, because this will help alleviate the strain on the practice.
  • Review the Phase 1 audit protocol. The Phase 1 audit protocol is available on the OCR website. Even if your organization is not selected for an audit, working through the protocol is a great way to evaluate your compliance and avoid any fines.
  • Keep up to date with the OCR audit information. The OCR has published its objectives for Phase 2, and they are available for review.

HIPAA and the HITECH Act are intricate laws, and compliance is mandatory to prevent significant fines from being imposed. Practices should monitor their current systems and train staff as necessary on how to respond to breaches.

Page: 1 2 3 | Single Page
Share: 

Filed under:From the CollegePractice Support Tagged with:ComplianceGuidelinesHIPAA auditPracticeRegulationrheumatologistSecurity

Related Articles

    Preparing for Increased HIPAA Audits Among Smaller Rheumatology Providers

    May 13, 2016

    Recent enforcement activities of the Department of Health and Human Services’ Office for Civil Rights (OCR) have shown an increase in fines and penalties assessed against smaller providers for failing to comply with the privacy, security and breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA). Historically, OCR has focused on larger…

    HIPAA Audit Activities Increase in 2016

    August 17, 2016

    In the coming months, rheumatologists may want to pay particular attention to their email inboxes. By the end of the year, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) will complete stage I, phase II of a series of desk and on-site audits designed to assess providers and their business…

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties

    April 1, 2013

    Physicians’ business associates can now face civil and criminal penalties for violating HIPAA laws guarding the confidentiality of protected health information

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences