It appears that HHS has engaged PriceWaterhouseCoopers to perform HIPAA compliance audits at hospitals that…
The long-awaited HIPAA Phase 2 audits draw ever nearer, and more information is now available about timing and content. Here are some resources:
Deven McGraw, Deputy Director of Health Information Privacy at OCR, said in an interview that
OCR plans to conduct this year about 200 remote desk audits focusing on compliance with only a small subset of HIPAA requirements and 10 to 25 “full scale audits” that will involve onsite visits.
Thus, while the Phase 2 audit protocol is more comprehensive than the Phase 1 protocol, just a fraction of it will be deployed in each of the desk audits. OCR experience with Phase 2 will inform development of the “permanent” audit program.
More recently, McGraw “announced at an event that covered entities would receive letters about desk audits in May, while business associates will receive such letters in June or July.”
While the number of covered entities and business associates to be audited in this round is tiny, relative to the size of the regulated community, it is worth noting that data breaches have been in the news — and these likely barely scratch the surface of the exposure that covered entities and business associates have to privacy and security risks. It is always a good time to ensure that HIPAA compliance plans and their implementation are up to snuff.
David Harlow
The Harlow Group LLC
Health Care Law and Consulting
Healthcare NOW Radio Podcast Network · Harlow on Healthcare
In this episode I speak with Ryne Natzke, Chief Revenue Officer of TrustCommerce, a Sphere…
Natalie Davis, CEO of United States of Care, returned to Harlow on Healthcare to discuss…
If the EHR is the system of record, then Lumeon is the system of action.…
Blockchain in healthcare? Well, it can solve some problems. Have a listen to my conversation…
Joel Diamond, Chief Medical Officer at 2bPrecise, speaks with me about bringing genetic testing information…