When investigating breaches of protected health information, the HHS Office for Civil Rights has often found that organizations in many ways were not compliant with the HIPAA Security Rule to consistently secure protected health information. In particular, a risk analysis often was not performed or was done but never updated as the vulnerability landscape changed.

Consequently, OCR is conducting random HIPAA audits to assess provider, payer and claims clearinghouse compliance with the Security Rule, as well as compliance by their business associates, and expects to ramp up the number of audits. Further, the HHS Office of Inspector General has started its own security audit program to determine if organizations attesting for EHR meaningful use are as compliant with HIPAA as they contend.

Register or login for access to this item and much more

All Health Data Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access