decisionhealth Newsletters, Part B News - 2022 Issue 7 (July)
Expert Q&A: HIPAA audits, cybersecurity, patient record access and more
Subscribe or sign in to view the full article.
Article Overview
This article reviews practical HIPAA compliance topics for health care organizations and their business associates, with an emphasis on preparing for Office for Civil Rights (OCR) audits, managing patient record access requests, strengthening cybersecurity practices, handling family member information requests, and evaluating privacy officer qualifications. It is aimed at compliance, privacy, security, operations, and legal teams that support HIPAA programs and document retention, training, and risk management activities.
Why This Topic Matters
The piece helps organizations understand the broad areas OCR may examine and the operational controls that support compliance across privacy, security, access, and documentation processes. It is useful for teams improving readiness, documenting workflows, and aligning staff training and oversight with HIPAA obligations.
Article Sections
-
HIPAA audit preparation for OCR
Discusses readiness for an OCR audit, including documentation, notices, recordkeeping, and staff interviews. Emphasizes what organizations should have organized and available for review.
-
Improving patient records access request turnaround times
Covers operational steps for managing patient records access requests more efficiently. Focuses on inventorying records, coordinating with business associates, and documenting procedures and training.
-
Cybersecurity risks and safeguards
Reviews common cybersecurity threats affecting health care organizations and their business associates. Addresses broad safeguard categories such as training, authentication, encryption, backups, and risk assessment.
-
Handling family member requests for medical information
Explains general planning considerations for sharing information with family members or others involved in care or payment. Describes the need for documented procedures, staff consistency, and careful documentation.
-
Qualities to look for when hiring a privacy officer
Summarizes the knowledge and skills valued in a privacy officer role. Includes broad expectations related to HIPAA knowledge, privacy and security awareness, communication, and organization.
What You Will Learn
- How organizations can organize their HIPAA compliance materials for audit readiness
- What operational areas are commonly reviewed in OCR-related compliance discussions
- Ways to streamline patient record access request handling
- Which cybersecurity topics are emphasized for health care organizations and business associates
- What planning considerations support information-sharing requests involving family members
- What skills and experience are relevant when evaluating a privacy officer candidate
Who Should Read This
- HIPAA compliance officers
- Privacy officers
- Security officers
- Health care operations teams
- Medical practice administrators
- Revenue cycle and records staff
- Health care legal and risk teams
- Business associate compliance teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com