Medicare Compliance & Reimbursement - 2013 Issue 26
Patient Privacy: HIPAA Audits Begin in Two Months--Are You Ready?
Subscribe or sign in to view the full article.
Article Overview
This article is aimed at medical practices and compliance staff preparing for HIPAA audits. It covers the transition to OCR’s permanent audit program, why ongoing privacy and security readiness matters, how risk assessments fit into compliance planning, how business associate responsibilities are discussed under HIPAA/HITECH, and where to find HHS/OCR audit protocol guidance. The focus is on broad audit readiness and documentation awareness rather than detailed coding or claim-submission issues.
Why This Topic Matters
HIPAA audits can affect practice compliance programs, privacy and security processes, and vendor oversight. Understanding the broad audit landscape helps organizations prepare documentation and review internal safeguards before an audit notice arrives.
Article Sections
-
You Can’t Wait Until 2014
Introduces the planned timing of OCR’s broader HIPAA audit program and explains the shift from a pilot phase to ongoing audits. It also frames the article’s emphasis on readiness and compliance review.
-
Consider Risk Assessment
Discusses risk assessment as a core part of HIPAA privacy and security preparation. It references general update considerations, federal funding context, and a federal standards resource for assessing threats and vulnerabilities.
-
Who Counts As ‘Business Associates?’
Reviews the broad topic of business associate oversight under HIPAA and HITECH. It addresses the types of outside entities commonly discussed in compliance planning and the distinction between business associate and confidentiality arrangements.
-
Use HHS Guidance to Prepare
Points readers to HHS/OCR audit protocol guidance as a resource for understanding the kinds of documentation and review areas that may be involved in an audit.
What You Will Learn
- How OCR’s HIPAA audit program affects medical practice compliance planning
- Why risk assessments are part of privacy and security readiness
- How business associate responsibilities are discussed in HIPAA compliance
- What general HHS/OCR audit guidance can help practices review
- How audit preparation ties to documentation and internal process review
Who Should Read This
- Medical practices
- Practice administrators
- Compliance officers
- Privacy and security staff
- Healthcare billing and operations teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com