JUN 26, 2012 10:44pm ET

Related Links

HIT Vendor Round-up: Prognosis, HealthInfoNet, PracticeMax & McKesson
May 23, 2013
Using Analytics to Support an ‘Ambulatory ICU’ Model
May 23, 2013
Feds: 2013 Goal for Meaningful Use Participation Already Met
May 22, 2013
First Vendors Get Accredited for Direct Messaging Services
May 22, 2013
New WEDI Program Facilitates State ICD-10 Cooperation
May 22, 2013
Consumer Groups, EHR Vendors Talk Back to GOP Senators
May 21, 2013
Healthland Acquisition Targets the Continuum of Care
May 21, 2013

HHS/OCR Unveils the Protocol for HIPAA Privacy & Security Audits

Print
Reprints
Email

The HHS Office for Civil Rights on June 26 issued the following notice on the protocol being used to conduct HIPAA Privacy and Security Rule audits:

Today, OCR posted on its website the protocol used to conduct the audits required by the HITECH Act.  The OCR HIPAA Audit program analyzes key processes, controls, and policies of selected covered entities pursuant to the HITECH Act audit requirement.  OCR established a comprehensive audit protocol that contains the requirements to be assessed through these performance audits. The entire audit protocol is organized around modules, representing separate elements of privacy, security, and breach notification.  The combination of these multiple requirements may vary based on the type of covered entity selected for review.

* The audit protocol covers Privacy Rule requirements for (1) notice of privacy practices for PHI, (2) rights to request privacy protection for PHI, (3) access of individuals to PHI, (4) administrative requirements, (5) uses and disclosures of PHI, (6) amendment of PHI, and (7) accounting of disclosures.

* The protocol covers Security Rule requirements for administrative, physical, and technical safeguards.

* The protocol covers requirements for the Breach Notification Rule.

Please visit the website at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/audit/index.html to learn more about the OCR HIPAA Audit Program and to access the audit protocol.

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

As the feds ramp up enforcement of privacy and security rules, providers look to fill protection gaps.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.