E/M Coding Alert - 2016 Issue 12
Patient Privacy: It's Official: HIPAA Audits Are in Full Swing
Subscribe or sign in to view the full article.
Article Overview
This article explains the rollout of phase two HIPAA audits by the Office for Civil Rights and discusses what covered entities and business associates should generally have ready if selected for review. It covers the overall audit process, document-readiness expectations, privacy and security policy review, risk assessment preparation, business associate oversight, and related HIPAA compliance planning. The piece is aimed at healthcare providers, practice administrators, compliance staff, and business associates who want to understand the scope of the audits and the kinds of compliance areas being examined.
Why This Topic Matters
HIPAA audits can require organizations to quickly produce evidence of compliance, so understanding the broad areas under review helps practices reduce exposure and improve readiness.
Article Sections
-
Overview of phase two HIPAA audits
Introduces the shift from the earlier audit phase to the current one and explains the general scope of entities involved. It also describes the mix of desk and on-site audits discussed in the article.
-
How phase two builds on phase one
Summarizes the relationship between the earlier pilot audits and the current audit protocol. This section focuses on the program structure and how the audit approach was refined.
-
Business associate considerations
Discusses the role of business associates in the audit process and the general compliance relationship between covered entities and their vendors. It addresses the need for oversight and awareness of privacy-related issues.
-
Preparing for audits
Covers the kinds of documentation and policy readiness organizations should consider before an audit request arrives. It includes broad preparation areas such as written policies, agreements, and response readiness.
-
Demonstrating an ongoing compliance program
Describes the importance of maintaining an active compliance effort and being able to show that it exists. The section also references ongoing review, updates, and related administrative preparation.
What You Will Learn
- What phase two HIPAA audits are generally about
- Which types of organizations may be reviewed
- What broad compliance areas are commonly examined
- Why business associate oversight matters in audit readiness
- What kinds of records and policies organizations should have available
- How ongoing HIPAA compliance programs fit into audit preparation
Who Should Read This
- Covered entities
- Business associates
- Healthcare compliance staff
- Practice managers
- Privacy and security officers
- Healthcare attorneys
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com