• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

OCR Notice

Did You Receive an OCR Notice for the Phase 2 Audit? What’s Next?

June 16, 2016/in Blog, OCR

Now that OCR has officially started the Phase 2 HIPAA Audit Program, are you adequately prepared to be an auditee? OCR is currently compiling its pools of potential auditees that will be selected at random for auditing purposes. Many healthcare providers have already received this OCR notice requesting verification of contact information which must be responded to within 14 days. While this notice does not necessarily indicate that the provider will be audited, the provider will be entered into the pool of potential auditees. In conducting its data gathering efforts, OCR will also request completion of an Audit Pre-Screening Questionnaire to gather information on the size, type, and operations of potential auditees, which can be viewed on the HHS website.

1st Round- Desk Audits

The first round of audits will be in the form of desk audits, which is scheduled to be completed by December 2016. These desk audits will be completed in two sets, with the first set focused on covered entities and the second set focused on business associates. Selected auditees will receive email notification from OCR along with an initial request for documentation and data. Auditees will only have 10 business days to respond to the request by submitting the requested information via OCR’s new secure online portal. Providers will be required to identify and provide detailed information on each of its business associates. And depending on the findings of the desk audit, auditees may be subject to a subsequent onsite audit. Upon completion of the desk audit, OCR will prepare and share its draft findings. Auditees are granted 10 business days to respond to the draft findings with any written comments, and OCR will then issue a final audit report within 30 days.

2nd Round- Onsite Audits

The second round of audits will be conducted in the form of onsite visits, which will encompass a more comprehensive examination compared to that of the desk audit. Selected auditees will receive email notification from OCR. The on-site audit starts with an entrance conference that will review the audit process, followed by the actual audit that can last from three to five days.

Auditees selected for the onsite audit will have the same amount of time to review the OCR’s draft findings as mentioned above before a final audit report is issued. OCR may ensue a compliance review if it uncovers serious compliance issues during this audit.  

OCR’s Revised Audit Protocol

Last month, OCR revised its Audit Protocol to incorporate requirements from the HIPAA Omnibus Final Rule of 2013. This protocol will be used by its auditors in conducting the Phase 2 audits and serves as guidance on areas a potential audit may focus on and can be used as a risk assessment tool to evaluate a provider’s current compliance program.

Prepare As If You Are Going to Be Audited!

Preparation is key to successfully surviving the audit and continuing with the main goal of providing high quality patient care. Providers should be adequately prepared to participate in Phase 2 by (i) reviewing updating and enforcing internal policies and procedures relevant to HIPAA Privacy, Security, and Breach Notification Rules; (ii) having documentation of compliance efforts readily available; (iii) reviewing OCR’s updated Audit Protocol; and (iv) preparing staff in the event of an audit. Time is of the essence when it comes to preparedness as providers will have limited time to respond to OCR’s audit requests once identified as an auditee. Moreover, providers can expect to be the target of a separate compliance review if violations are uncovered during an audit. This is especially true since the Office of Inspector General issued its September 2015 report criticizing the OCR’s oversight efforts over covered entities, as mentioned in our previous blog post, Are You Prepared for the HIPAA Phase 2 Audits?.

Tags: audit protocol, HHS, HIPAA, HIPPA, OCR, ocr audit, Omnibus Rule, phase 2, phase two
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2016/06/OCR-Audits-2-1-scaled.jpg 1600 2560 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2016-06-16 11:00:442025-04-15 12:58:01Did You Receive an OCR Notice for the Phase 2 Audit? What’s Next?
You might also like
Resources for Healthcare Professionals during the COVID-19 Crisis
The Virtual HIPAA Privacy and Security Workshop 2022 on Nov 3, 2022 offers Multiple Learning Credits HIPAA Enforcement Data
First Healthcare Compliance to Showcase Compliance Solutions at the 27th Annual Compliance Institute in Anaheim, California First Healthcare Compliance to Showcase Compliance Solutions at the 27th Annual Compliance Institute in Anaheim, California
cybersecurity, data privacy, and electronic discovery Updates on Data Privacy Regulations
The Virtual HIPAA Privacy and Security Workshop 2022 on Nov 3, 2022 offers Multiple Learning Credits The Virtual HIPAA Privacy and Security Workshop 2022 on Nov 3, 2022 offers Multiple Learning Credits
The Virtual HIPAA Privacy and Security Workshop 2022 on Nov 3, 2022 offers Multiple Learning Credits Coding Vaccinations

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • The OIG Exclusions List: First Line of Employment Defense
  • Navigating the HIPAA Security Landscape: A Comprehensive Guide to Security Risk Assessments
  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only