OCR HIPAA Audit Program Recommences

At the 42nd Virtual HIPAA Summit this week, Tim Noonan, deputy director of health information privacy, data, and cybersecurity at the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) confirmed that the third phase of HIPAA compliance audits is underway, having quietly commenced in December last year.

Under the HITECH Act, the HHS is required to conduct periodic audits of regulated entities to assess HIPAA compliance. Since the HITECH Act was enacted in 2009, OCR has conducted two rounds of audits, the first commenced in 2012, and the second in 2016/2017. The latest round will involve audits of 50 HIPAA-covered entities and business associates and will focus on HIPAA Security Rule compliance, specifically implementation specifications of the HIPAA Security Rule relevant to the prevention of hacking and ransomware incidents.

As OCR has previously explained, hacking incidents and ransomware attacks on the healthcare sector have increased significantly in recent years. According to Noonan, between 2020 and 2024, hacking incidents increased by 30% and ransomware attacks on the healthcare sector increased by 45%. Last year, 81% of data breaches that affected 500 or more individuals were due to hacking incidents.

The HHS’ Office of Inspector General (HHS-OIG) recently audited OCR’s 2016/2017 audit program, and one of its recommendations was for OCR to recommence the audit program, which has been dormant for 8 years. The problem at OCR has been a lack of funding, which successive OCR directors have stated has prevented OCR from establishing a permanent audit program.

HHS-OIG found that for the period of its audit, OCR had met its responsibilities under the HITECH Act to conduct periodic audits, but said the audits were too narrow in scope as they only covered 8 of the 180 HIPAA Rule requirements and only 2 of the 8 were related to the administrative safeguards of the HIPAA Security Rule, and none were related to the physical or technical safeguards. Noonan did not state how extensive the latest round of audits is or the specific implementation specifications that are being audited.

HHS-OIG also said in its report that OCR’s oversight of its HIPAA audit program was not effective at improving cybersecurity protections at HIPAA-regulated entities. HHS-OIG recommended that OCR implement standards and guidance for ensuring that any compliance deficiencies identified in the audits are corrected in a timely manner.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

When OCR investigates data breaches and identifies HIPAA violations, the alleged violations can be resolved with a settlement agreement, which involves a financial penalty and a corrective action plan to address the HIPAA deficiencies. If the regulated entity opts not to settle and its defense does not support a waiver of a financial penalty, OCR imposes a civil monetary penalty; however, it cannot compel a regulated entity to implement a corrective action plan.

Similarly with audits, OCR cannot compel a regulated entity to implement a corrective action plan to correct any deficiencies, as OCR explained in its response to the HHS-OIG report. Instead, audited entities will benefit from an assessment of their compliance efforts, which will give them insights into how those programs can be improved. It will be up to each audited entity to implement changes to their compliance programs to correct any deficiencies.

As with previous rounds of audits, OCR will publish a report summarising the findings. Both previous rounds of audits found several areas where regulated entities were not fully compliant with the HIPAA Rules, including the risk analysis requirement and patient medical record access, both of which are now enforcement initiatives at OCR.

In January 2025, one of the last actions taken by OCR under the Biden Administration before the administration change was to issue a Notice of Proposed Rulemaking (NPRM) updating the HIPAA Security Rule. The NPRM ran to almost 400 pages and included extensive updates to definitions and a swathe of new cybersecurity requirements.

The comment period ended on March 7, 2025, and OCR is now reviewing the comments. Noonan explained that OCR has received 4,745 comments in response to the NPRM and will be reading all submitted comments. Noonan said the comments will be split into categories to try to get a sense of the public response to the NPRM, and after the review, “we will work within HHS on what future actions we might take.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/