General Surgery Coding Alert - 2016 Issue 16
Patient Privacy: HIPAA Audits to Scrutinize the Fundamentals of Your Privacy Plans
Subscribe or sign in to view the full article.
Article Overview
This article explains how healthcare organizations can use the OCR HIPAA Audit Protocol to assess their privacy and security compliance posture before an audit. It focuses on the kinds of policies, procedures, and documentation auditors are expected to review, with special attention to privacy, security, breach notification, and related preparedness areas. The discussion is aimed at covered entities and business associates that want to understand the scope of the audit process and identify potential gaps in their HIPAA compliance programs.
Why This Topic Matters
HIPAA audits can expose weaknesses in an organization’s privacy and security program, so understanding the audit protocol helps practices prepare in advance and reduce compliance risk. The article is relevant for organizations that need to confirm whether their policies, procedures, and supporting documents align with OCR expectations.
What You Will Learn
- How the OCR HIPAA Audit Protocol is used during privacy and security audits
- What types of policies, procedures, and documentation may be reviewed
- Why self-audits can help identify gaps before an external audit
- How audit focus areas relate to broader HIPAA compliance readiness
- What general preparedness issues practices should consider for data loss and disaster recovery
Who Should Read This
- Covered entities
- Business associates
- Small medical practices
- HIPAA compliance staff
- Practice administrators
- Healthcare attorneys
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com