CompyMax

What is an OCR audit?

Two different things get called one. The HHS Office for Civil Rights runs a periodic audit programme that HITECH requires, where entities are selected rather than reported — and it separately conducts investigations and compliance reviews, which are reactive and usually start with a complaint or a breach you filed yourself. They have different triggers, different scope and different consequences, and almost everyone searching this phrase means the second.

Last reviewed .

If a letter has already arrived, start with a lawyer

This page is about preparation. We do not provide legal advice and do not act for anyone before a regulator — if OCR has contacted you, engage counsel experienced in these matters before you respond, and do it before you start assembling documents. What follows is about the records you should already hold, which is a different problem and a far cheaper one.

The two processes, side by side

Proactive

The HIPAA Audit Program

HITECH requires HHS to periodically audit covered entities and business associates for compliance with the Privacy, Security and Breach Notification Rules. You are selected, not reported. OCR describes the purpose as examining mechanisms for compliance and discovering risks that its complaint investigations would not surface, and it publishes an industry report of overall findings when a round completes.

Scope: The 2024–2025 round: 50 covered entities and business associates, reviewed against selected Security Rule provisions most relevant to hacking and ransomware attacks.

Reactive

An investigation or compliance review

This is what people usually mean, because it is the one that arrives addressed to you. OCR enforces the rules by investigating complaints filed with it and by conducting compliance reviews — the latter frequently following a breach you reported. 45 CFR 160.310 sets out what you owe once it starts: records and compliance reports on request, cooperation with the review, and access to books, records and other sources of information.

Scope: Whatever the complaint or breach concerns, which in practice widens quickly once records are produced.

What the current audit round is actually looking at

OCR has stated that the 2024–2025 HIPAA Audits review 50 covered entities’ and business associates’ compliance with selected provisions of the Security Rule most relevant to hacking and ransomware attacks — not the whole rule, and not the Privacy Rule. The stated reason is the increase in large breaches involving hacking and ransomware reported to OCR.

For scale, the previous round — the 2016–2017 audits, whose industry report OCR published — covered 166 covered entities and 41 business associates. Fifty is a small number against the size of the regulated population, which is the honest answer to “what are the odds.” It is also the wrong question: the same records the audit programme asks for are the records a breach-triggered compliance review asks for, and that is the far likelier event.

OCR also publishes the Audit Program Protocol it works from, which is worth reading as a description of what adequate documentation looks like rather than as a study guide.

The six records both processes ask for

  • A risk analysis with a date on it

    The recurring finding across a decade of OCR enforcement, and the explicit focus of the current audit round. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of the risks to all electronic protected health information you hold — every system, not the clinical one.

  • Evidence you acted on what it found

    The risk analysis and the risk management process at 164.308(a)(1)(ii)(B) are separate requirements, and producing the first without the second is a common and visible gap. An open remediation item with a named owner and a target date is a functioning programme; the same gap with nothing attached is a finding.

  • Policies with version history

    Documentation must be retained for six years from creation or from when it was last in effect, whichever is later — 45 CFR 164.316(b)(2)(i). Overwriting a policy in place destroys the record the retention rule requires.

  • Training records per person, with dates

    “We train annually” is an assertion. A list of names, completion dates and certificate numbers is evidence, and it is the difference between a short exchange and a long one.

  • Executed business associate agreements

    For every vendor that touches patient data, with dates, and covering the subcontractors underneath them. A register that lists agreements you cannot produce is worse than no register.

  • The incident log, including what came to nothing

    Most incidents are not reportable breaches. Recording the ones you assessed and closed, with the reasoning, is what the burden of proof at 45 CFR 164.414(b) expects. An empty log does not show nothing happened — it shows nothing was recorded.

Common questions

What is an OCR audit?
Two different processes get that name. The first is OCR's HIPAA Audit Program, a proactive review that HITECH requires HHS to carry out periodically; entities are selected rather than reported, and the 2024–2025 round covers 50 covered entities and business associates. The second — and the one most people mean, because it is what generates a letter — is an OCR investigation or compliance review, which is reactive and usually follows a complaint or a reported breach. The audit programme produces findings and an industry report. An investigation can produce a corrective action plan or a civil money penalty.
What triggers an OCR investigation?
Most commonly a complaint filed with OCR, or a breach you reported yourself. OCR states that it enforces the Privacy and Security Rules by investigating complaints filed with it, conducting compliance reviews, and performing education and outreach. A large breach report is the single most reliable way to attract a compliance review, which is why the quality of the records you already hold matters more than anything you can assemble afterwards.
What does the 2024–2025 HIPAA audit programme look at?
Selected provisions of the HIPAA Security Rule that OCR identifies as most relevant to hacking and ransomware attacks — not the whole rule, and not the Privacy Rule. In practice that centres on the risk analysis at 45 CFR 164.308(a)(1)(ii)(A) and the risk management process at 164.308(a)(1)(ii)(B), which are the two findings that have recurred across OCR's enforcement actions for a decade.
Are business associates audited?
Yes, and it is not a footnote. The 2016–2017 round audited 166 covered entities and 41 business associates, and the 2024–2025 round names business associates alongside covered entities in its scope. If you are a billing company, an MSP, a software vendor or any other business associate, you are directly in scope rather than covered by your client's programme.
How much notice do you get?
Less than you would like, and the useful answer is that it does not matter much. Both processes ask for contemporaneous evidence — records that existed before the request, with dates that predate it. A risk analysis dated last quarter answers the question. One produced the week after a letter arrives answers a different question, visibly.

Contemporaneous beats comprehensive.

Run the risk assessment and record what you did about it, keep policies versioned, log training per person, and write down the incidents that came to nothing. Then producing evidence is an export rather than a fortnight. 14 days free, no credit card, no sales call.

Informational only. Based on the published text of 45 CFR Parts 160 and 164, and on OCR’s own description of its audit programme and enforcement process as published at hhs.gov and read on August 13, 2026. This is not legal advice, and no organization or product can be “HIPAA certified” — no such designation exists. We do not provide audit defence, representation before regulators, or any assurance as to the outcome of an investigation. See our editorial standards.