HHS Launches Phase 2 of HIPAA Audits
Time 2 Minute Read

On March 21, 2016, the Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced that it has commenced Phase 2 of the HIPAA Audit Program. Phase 1 of the HIPAA Audit Program ran from 2011-2012 and produced several notable findings, including that two-thirds of covered entities had not performed a risk assessment as required by the HIPAA Security Rule.

Phase 2 will launch with desk audits of covered entities. During these desk audits, covered entities will submit documentation via OCR’s secure online portal. The documentation, which must be submitted within ten days of the initial request, will help OCR auditors examine the entities’ compliance with specific requirements of the HIPAA Privacy, Security or Breach Notification Rules. Following these initial audits, OCR plans to conduct desk audits of business associates. After the desk audits have been completed, some covered entities and business associates may be selected for onsite audits that will be conducted over a three to five day period and will examine a broader scope of HIPAA requirements.

Although the Phase 2 audits are intended to help improve compliance, OCR has indicated that it may initiate compliance reviews if an audit report reveals serious issues. OCR has stated that the desk audits will be completed by the end of December 2016, but has not determined a completion date for the onsite audits since they are contingent upon the results of the desk audits.

View the details of Phase 2 of the HIPAA Audit Program, including a list of frequently asked questions about the program.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page