11/25/2024 | Press release | Distributed by Public on 11/25/2024 08:24
Issued on 11/21/2024 | Posted on 11/25/2024 | Report number: A-18-21-08014
OCR fulfilled its requirement under the HITECH Act to perform periodic HIPAA audits. However:
We made a series of recommendations to OCR to enhance its HIPAA audit program, including that it expand the scope of its HIPAA audits to assess compliance with physical and technical safeguards from the HIPAA Security Rule, document and implement standards and guidance for ensuring that deficiencies identified during the HIPAA audits are corrected in a timely manner, and define metrics for monitoring the effectiveness of OCR's HIPAA audits at improving audited covered entities and business associates' protections over ePHI and periodically review whether these metrics should be refined. The full recommendations are in the report.
OCR did not concur with one recommendation but concurred with our three other recommendations and detailed steps it has taken and plans to take in response.