• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

What Would The Office Of Civil Rights Most Likely Find In a HIPAA/HITECH Audit?

May 28, 2014/in 1st Healthcare Compliance, Blog, HIPAA, HIPAA Zone, HITECH, Security Zone

Looking back at past audits by the Office of Civil Rights (OCR) is the best place to start. The OCR enforces the HIPAA Privacy Rule, Security Rule, Breach Notification Rule and the confidentiality provisions of the Patient Safety Rule.

The Office of Civil Rights’ “Lessons Learned from OCR Privacy and Security Audits” revealed the most common findings and causes identified in 2011-2012 audits. This program only involved covered entities as the audit date occurred before the compliance deadline for business associates.

img class=”size-medium wp-image-1372 aligncenter” title=”HIPPA Audit ” src=”https://1sthcc.com/wp-content/uploads/2014/05/Screen-shot-2014-05-28-at-5.57.27-PM-300×172.png” alt=”HIPAA ” width=”300″ height=”172″ />

AUDIT FINDINGS: COVERED ENTITIES AWARENESS OF HIPAA/HITECH REQUIREMENTS

The audit results showed that 30% of the findings uncovered the fact that the entities were simply unaware of any specific HIPAA/HITECH requirement. Of the total audit findings, this lack of awareness represented 39% of the Privacy Rule, 27% of the Security Rule and 12% of the Breach Notification findings.

Healthcare Security

PERCENTAGE OF TOTAL AUDIT FINDINGS DUE TO LACK OF AWARENESS

Source: OCR March 7, 2013

Interestingly, the majority of the HIPAA/HITECH requirements state exactly what the covered entities should be doing to be in compliance. Specific areas where the entity was unaware of any requirements:

Privacy Rule

  • Notice of Privacy Practices
  • Access of Individuals
  • Uses and Disclosures (Minimum Necessary and Authorizations)

Security Rule

  • Risk Analysis
  • Media Movement and Disposal
  • Audit Controls and Monitoring

Other detected causes identified included lack of usage of available resources, incomplete implementation and willful disregard.

The OCR auditors evaluated policy and procedures and reviewed the relevant documentation for:

Breach Notification

  • Notification to Individuals
  • Timeliness of Notification
  • Methods of Individual Notification
  • Burden of Proof

Security (Administrative, Physical and Technical Safeguards)

  • Risk Analysis
  • Access Management
  • Security Incident Procedures
  • Contingency Planning and Backups
  • Media Movement and Destruction
  • Encryption
  • Audit Controls and Monitoring
  • Integrity Controls

Privacy

  • Notice of Privacy Practices
  • Rights to Request Privacy Protection of PHI
  • Access of Individuals to PHI
  • Administrative Requirement
  • Uses and Disclosures of PHI
  • Amendment of PHI
  • Accounting of Disclosures

Audit Findings

AUDIT FINDINGS AND OBSERVATIONS BY TYPE OF COVERED ENTITY

Source: OCR March 7, 2013

Smaller entities had issues with Breach Notification, Privacy and Security Rules. The healthcare providers had the greatest proportion of findings compared to other covered entities.

HIPAA

AUDIT FINDINGS AND OBSERVATIONS BY RULE

Source: OCR March 7, 2013

Compliance with the Security Rule seemed to be the most troublesome, accounting for almost 2/3 of the audit findings. Under the Privacy Rule’s Administrative requirements, the majority of the issues related to policies and procedures and adequate training.

Review these focus areas in your practice and make sure you are aware of all of the current requirements. Please do not wait for an OCR audit to start your compliance program.

Tags: Breach, compliance, Health IT, HIPAA, HITECH, OCR, Privacy, Security
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg 0 0 First Healthcare Compliance Staff https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg First Healthcare Compliance Staff2014-05-28 22:00:012025-04-15 12:58:08What Would The Office Of Civil Rights Most Likely Find In a HIPAA/HITECH Audit?
You might also like
The Insecurity of Everything: The Vital Importance of Hardware Data Security
HIPAA Omnibus Final Rule and Your Practice
HIPAA Compliance or Else
Healthcare Cybersecurity Awareness Training Healthcare Cybersecurity Awareness Training
Recent Developments in Health Information Privacy: HIPAA Right of Access
Business Associates under HIPAA: Compliance Requirements, Liability Considerations, and the Anatomy of a Breach

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only