- What is an OCR audit?
- Two different processes get that name. The first is OCR's HIPAA Audit Program, a proactive review that HITECH requires HHS to carry out periodically; entities are selected rather than reported, and the 2024–2025 round covers 50 covered entities and business associates. The second — and the one most people mean, because it is what generates a letter — is an OCR investigation or compliance review, which is reactive and usually follows a complaint or a reported breach. The audit programme produces findings and an industry report. An investigation can produce a corrective action plan or a civil money penalty.
- What triggers an OCR investigation?
- Most commonly a complaint filed with OCR, or a breach you reported yourself. OCR states that it enforces the Privacy and Security Rules by investigating complaints filed with it, conducting compliance reviews, and performing education and outreach. A large breach report is the single most reliable way to attract a compliance review, which is why the quality of the records you already hold matters more than anything you can assemble afterwards.
- What does the 2024–2025 HIPAA audit programme look at?
- Selected provisions of the HIPAA Security Rule that OCR identifies as most relevant to hacking and ransomware attacks — not the whole rule, and not the Privacy Rule. In practice that centres on the risk analysis at 45 CFR 164.308(a)(1)(ii)(A) and the risk management process at 164.308(a)(1)(ii)(B), which are the two findings that have recurred across OCR's enforcement actions for a decade.
- Are business associates audited?
- Yes, and it is not a footnote. The 2016–2017 round audited 166 covered entities and 41 business associates, and the 2024–2025 round names business associates alongside covered entities in its scope. If you are a billing company, an MSP, a software vendor or any other business associate, you are directly in scope rather than covered by your client's programme.
- How much notice do you get?
- Less than you would like, and the useful answer is that it does not matter much. Both processes ask for contemporaneous evidence — records that existed before the request, with dates that predate it. A risk analysis dated last quarter answers the question. One produced the week after a letter arrives answers a different question, visibly.