OCR releases audit protocol
HIM-HIPAA Insider, July 16, 2012
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Want to know what the OCR audits will look like? OCR has let us know.
The HIPAA privacy and security enforcer has released its audit protocol on its website. OCR breaks down 77 areas for which it will be reviewing during its initial phase of audits. OCR, per HITECH, is required to audit covered entities and business associates for HIPAA compliance. It has audited 20 in its test phase and plans to audit 95 more by the end of 2012.
“OCR established a comprehensive audit protocol that contains the requirements to be assessed through these performance audits,” according to the OCR website. “The entire audit protocol is organized around modules, representing separate elements of privacy, security, and breach notification. The combination of these multiple requirements may vary based on the type of covered entity selected for review.”
- Notice of privacy practices for PHI
- Rights to request privacy protection for PHI
- Access of individuals to PHI
- Administrative requirements
- Uses and disclosures of PHI
- Amendment of PHI
- Accounting of disclosures
- Security Rule requirements for administrative, physical, and technical safeguards
- Breach Notification Rule requirements
For the latest HIPAA news and information, visit the HIPAA Update blog.
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Related Products
Most Popular
- Articles
-
- Note similarities and differences between HCPCS, CPT® codes
- Practice the six rights of medication administration
- Don't forget the three checks in medication administration
- OB services: Coding inside and outside of the package
- Joint Commission clarifies ligature risk requirements
- What to include on the incident report
- Q&A: Primary, principal, and secondary diagnoses
- 3 ways CNOs can improve workplace culture
- Code diagnoses and outpatient treatment for PTSD
- Complications from immobility by body system
- E-mailed
-
- OB services: Coding inside and outside of the package
- Q: What are the requirements of an agency's professional advisory committee (PAC)?
- Q/A: Reporting L code and CPT code for splinting
- Q&A: Charging for drug administration during urgent care visit
- Prioritize sepsis assessments in your overcrowded emergency department
- Know guidelines and subtle differences in code descriptions for laceration repairs
- Joint Commission clarifies ligature risk requirements
- Food and drink in patient care areas
- Don't bill 59025, 76818 separately without separate physician orders
- Crossing state lines: What are the rules?
- Searched