The long-awaited "Phase 2 HIPAA Audits" by the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) have begun! HHS announced the new phase of audits, which will assess compliance with the HIPAA Privacy, Security, and Breach Notification Rules by business associates as well as covered entities, on March 21.

OCR kicked off the process by sending an email to covered entities and business associates requesting their contact information. Next, OCR will send out a pre-audit questionnaire that will help the agency determine potential audit subjects.

HIPAA audits were discussed most recently here and in more detail in this article, and we will certainly have much more to say about the audit process as it progresses.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.