SlideShare a Scribd company logo
1 of 2
Download to read offline
FISHERBROYLES.COM
TH E NE XT GE N E R AT IO N LA W FI RM ®
HIPAA 2016 Audits Phase 2: Covered Entities and Business
Associates Take Notice
PRACTICE AREA / INDUSTRY: HEALTHCARE; WHITE COLLAR LITIGATION &
GOVERNEMENT INVESTIGATIONS
Brian E. Dickerson Anthony J. Calamunci
brian.dickerson@fisherbroyles.com anthony.calamunci@fisherbroyles.com
202.570.0248 419.376.1776
Nicole Hughes Waid
nicole.waid@fisherbroyles.com
202.906.9572
March 22, 2016
As part of its continued effort to assess compliance with the HIPAA Privacy, Security and Breach Notification
Rules, the U.S. Department of Health & Human Services (“HHS”) Office for Civil Rights (“OCR”) announced
yesterday that it has begun its next phase of audits of covered entities and their business associates. In the
2016 Phase 2 HIPAA Audit Program, OCR will review the policies and procedures of covered entities and
their business associates through desk audits however, some on-site audits will also be conducted.
This second phase of audits follows OCR’s 2011-2012 pilot program of 115 entities. From the data collected
and results achieved, OCR developed enhanced protocols to be used in the 2016 Phase 2 HIPAA Audit
Program, including a new strategy to test the efficacy of desk audits in evaluating compliance with privacy,
security and breach notification rules. OCR is identifying pools of covered entities and business associates
that represent a wide range of health care providers, health plans, health care clearinghouses and business
associates. OCR will not audit entities with an open complaint investigation or that are currently undergoing a
compliance review.
The first desk audits will be for covered entities, followed by a second round of desk audits of business associates.
All desk audits in this phase will be completed by the end of December 2016. A third set of audits will be onsite
FISHERBROYLES.COM
TH E NE XT GE N E R AT IO N LA W FI RM ®
and will cover a broader scope of requirements from the HIPAA Rules than desk audits. It is anticipated that results
from desk audits may trigger a subsequent onsite audit and potential investigations if deficiencies are uncovered.
The audits are underway to review the policies and procedures of covered entities, beginning with an email
notification requesting contact information from OCR. Click here to view a sample email. The emails will originate
from OSOCRAudit@hhs.gov and if your entity’s spam filtering and virus protection are automatically enabled, OCR
expects you to check your junk or spam folders for their email. Failure to respond to the notification email may
result in OCR using publicly available information to create its audit pool, thus a desk or onsite audit notification
may not reach the appropriate company representative in a timely fashion. OCR will create a pool of targets for
desk and onsite audits from the responses to the initial emails.
If your entity is chosen for a desk audit, requested information must be submitted electronically within 10 business
days of the request. OCR will provide draft findings and auditees will have 10 days to review and return written
comments. Similarly, entities chosen for onsite audits will also receive an email notification. OCR will schedule
an entrance conference to provide more information about the process and onsite audits will be conducted over a
3-5 day period, depending upon the size of the entity. Entities will have 10 business days to review draft findings
and provide written comments to the auditor. OCR will complete and provide a final audit report within 30 business
days.
As we have advised in our recent client alerts regarding HIPAA enforcement trends, we believe the 2016 Phase 2
HIPAA Audit Program will have a keen focus on business associates and covered entities’ Business Associate
Agreements (“BAAs”). Business associates have been covered by HIPAA only since 2013, therefore compliance
with the HIPAA Privacy, Security and Breach Notification Rules may not be as robust or as fully vetted as required
by OCR. Business associates that conduct third-party billing, data analysis, storage and management, as well as
the covered entities who have BAAs with these vendors, are particularly vulnerable to being a target of OCR audits.
Covered entities and business associates must exercise due diligence in reviewing their HIPAA compliance
programs and conducting system wide audits of their PHI safeguards to identify and update areas that may have
vulnerability and could put personal health information at risk.
For further information on the subject matter of this alert, please contact the following FisherBroyles attorneys:
Brian E. Dickerson
brian.dickerson@fisherbroyles.com
202.570.0248
Nicole Hughes Waid
nicole.waid@fisherbroyles.com
202.906.9572
Anthony J. Calamunci
anthony.calamunci@fisherbroyles.com
419.376.1776

More Related Content

Viewers also liked

Mgp suffering slide show
Mgp suffering slide showMgp suffering slide show
Mgp suffering slide showaemberson
 
Scrum master certificacion internacional SMC de ScrumStudy en medelin
Scrum master certificacion internacional SMC de ScrumStudy en medelinScrum master certificacion internacional SMC de ScrumStudy en medelin
Scrum master certificacion internacional SMC de ScrumStudy en medelinOpen Source Pyme
 
1. 2016 md vendor overview
1. 2016 md vendor overview1. 2016 md vendor overview
1. 2016 md vendor overviewBarry Mathis
 
HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016Compliancy Group
 
BitRush Investors Deck Update Oct 2015
BitRush Investors Deck Update Oct 2015BitRush Investors Deck Update Oct 2015
BitRush Investors Deck Update Oct 2015BitRush Corp
 
From KPIs and Dashboards to Customer Centricity and beyond
From KPIs and Dashboards to Customer Centricity and beyondFrom KPIs and Dashboards to Customer Centricity and beyond
From KPIs and Dashboards to Customer Centricity and beyondAurélie Pols
 
Marco referencial 2
Marco referencial 2Marco referencial 2
Marco referencial 2Tensor
 
Sistema reproductor-masculino-y-femenino
Sistema reproductor-masculino-y-femeninoSistema reproductor-masculino-y-femenino
Sistema reproductor-masculino-y-femeninoDaniel Escalante
 

Viewers also liked (10)

Mgp suffering slide show
Mgp suffering slide showMgp suffering slide show
Mgp suffering slide show
 
Scrum master certificacion internacional SMC de ScrumStudy en medelin
Scrum master certificacion internacional SMC de ScrumStudy en medelinScrum master certificacion internacional SMC de ScrumStudy en medelin
Scrum master certificacion internacional SMC de ScrumStudy en medelin
 
1. 2016 md vendor overview
1. 2016 md vendor overview1. 2016 md vendor overview
1. 2016 md vendor overview
 
HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016
 
Otras sesiones neurocirugia_2010
Otras sesiones neurocirugia_2010Otras sesiones neurocirugia_2010
Otras sesiones neurocirugia_2010
 
BitRush Investors Deck Update Oct 2015
BitRush Investors Deck Update Oct 2015BitRush Investors Deck Update Oct 2015
BitRush Investors Deck Update Oct 2015
 
From KPIs and Dashboards to Customer Centricity and beyond
From KPIs and Dashboards to Customer Centricity and beyondFrom KPIs and Dashboards to Customer Centricity and beyond
From KPIs and Dashboards to Customer Centricity and beyond
 
Marco referencial 2
Marco referencial 2Marco referencial 2
Marco referencial 2
 
Emb. Snc
Emb. SncEmb. Snc
Emb. Snc
 
Sistema reproductor-masculino-y-femenino
Sistema reproductor-masculino-y-femeninoSistema reproductor-masculino-y-femenino
Sistema reproductor-masculino-y-femenino
 

Similar to HIPAA 2016 Phase 2 Audits of Covered Entities and Business Associates

Billing compliance results management-2013
Billing compliance results management-2013Billing compliance results management-2013
Billing compliance results management-2013nbattah
 
Understanding HIPAA / HITECH as a Mail Service Provider
Understanding HIPAA / HITECH as a Mail Service ProviderUnderstanding HIPAA / HITECH as a Mail Service Provider
Understanding HIPAA / HITECH as a Mail Service ProviderKarla Humphrey
 
HIPAA HHS OCR Audit Questions
HIPAA HHS OCR Audit QuestionsHIPAA HHS OCR Audit Questions
HIPAA HHS OCR Audit QuestionsDavid Sweigert
 
HIPAA Security Trends and Future Expectations
HIPAA Security Trends and Future ExpectationsHIPAA Security Trends and Future Expectations
HIPAA Security Trends and Future ExpectationsPYA, P.C.
 
What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sIatric Systems
 
HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?Redspin, Inc.
 
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...Brian Dickerson
 
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...Nicole Waid
 
In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...
In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...
In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...Patton Boggs LLP
 
Preparing & Responding to an OCR HIPAA Audit
Preparing & Responding to an OCR HIPAA AuditPreparing & Responding to an OCR HIPAA Audit
Preparing & Responding to an OCR HIPAA AuditPYA, P.C.
 
Solvency II News, October 2012
Solvency II News, October 2012Solvency II News, October 2012
Solvency II News, October 2012Compliance LLC
 
Seven Hiring Mistakes that Could Cost You Thousands
Seven Hiring Mistakes that Could Cost You ThousandsSeven Hiring Mistakes that Could Cost You Thousands
Seven Hiring Mistakes that Could Cost You ThousandsPatrick Barnett
 
Employee Background Checks: Avoid the Pitfalls
Employee Background Checks: Avoid the PitfallsEmployee Background Checks: Avoid the Pitfalls
Employee Background Checks: Avoid the PitfallsHuman Resources & Payroll
 
Cga Assignment Au1 Essay
Cga Assignment Au1 EssayCga Assignment Au1 Essay
Cga Assignment Au1 EssaySandra Arveseth
 
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...Compliancy Group
 
Final parkin orendac background screening
Final  parkin orendac background screeningFinal  parkin orendac background screening
Final parkin orendac background screeningStephenZiemkowski
 
DHHS OCR steps up to increase HIPAA audits of Business Associates
DHHS OCR steps up to increase HIPAA audits of Business AssociatesDHHS OCR steps up to increase HIPAA audits of Business Associates
DHHS OCR steps up to increase HIPAA audits of Business AssociatesDavid Sweigert
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...Polsinelli PC
 

Similar to HIPAA 2016 Phase 2 Audits of Covered Entities and Business Associates (20)

Billing compliance results management-2013
Billing compliance results management-2013Billing compliance results management-2013
Billing compliance results management-2013
 
Understanding HIPAA / HITECH as a Mail Service Provider
Understanding HIPAA / HITECH as a Mail Service ProviderUnderstanding HIPAA / HITECH as a Mail Service Provider
Understanding HIPAA / HITECH as a Mail Service Provider
 
HIPAA HHS OCR Audit Questions
HIPAA HHS OCR Audit QuestionsHIPAA HHS OCR Audit Questions
HIPAA HHS OCR Audit Questions
 
HIPAA Security Trends and Future Expectations
HIPAA Security Trends and Future ExpectationsHIPAA Security Trends and Future Expectations
HIPAA Security Trends and Future Expectations
 
What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​s
 
HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?
 
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
 
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Mill...
 
In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...
In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...
In Good News For Providers, OIG and CMS Propose Extensions And Modifications ...
 
Performing an ocr hipaa audit
Performing an ocr hipaa auditPerforming an ocr hipaa audit
Performing an ocr hipaa audit
 
Preparing & Responding to an OCR HIPAA Audit
Preparing & Responding to an OCR HIPAA AuditPreparing & Responding to an OCR HIPAA Audit
Preparing & Responding to an OCR HIPAA Audit
 
Solvency II News, October 2012
Solvency II News, October 2012Solvency II News, October 2012
Solvency II News, October 2012
 
Seven Hiring Mistakes that Could Cost You Thousands
Seven Hiring Mistakes that Could Cost You ThousandsSeven Hiring Mistakes that Could Cost You Thousands
Seven Hiring Mistakes that Could Cost You Thousands
 
Employee Background Checks: Avoid the Pitfalls
Employee Background Checks: Avoid the PitfallsEmployee Background Checks: Avoid the Pitfalls
Employee Background Checks: Avoid the Pitfalls
 
Cga Assignment Au1 Essay
Cga Assignment Au1 EssayCga Assignment Au1 Essay
Cga Assignment Au1 Essay
 
CEA SSAE16
CEA SSAE16CEA SSAE16
CEA SSAE16
 
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...
 
Final parkin orendac background screening
Final  parkin orendac background screeningFinal  parkin orendac background screening
Final parkin orendac background screening
 
DHHS OCR steps up to increase HIPAA audits of Business Associates
DHHS OCR steps up to increase HIPAA audits of Business AssociatesDHHS OCR steps up to increase HIPAA audits of Business Associates
DHHS OCR steps up to increase HIPAA audits of Business Associates
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
 

More from Brian Dickerson

The New Overtime Regulations
The New Overtime RegulationsThe New Overtime Regulations
The New Overtime RegulationsBrian Dickerson
 
FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...
FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...
FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...Brian Dickerson
 
FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...
FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...
FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...Brian Dickerson
 
FCPA Self-Reporting Pilot Program: Motivation to Self-Report?
FCPA Self-Reporting Pilot Program: Motivation to Self-Report?FCPA Self-Reporting Pilot Program: Motivation to Self-Report?
FCPA Self-Reporting Pilot Program: Motivation to Self-Report?Brian Dickerson
 
Court Says NJ Took Too Long For Subpoenas In FCA Claim
Court Says NJ Took Too Long For Subpoenas In FCA ClaimCourt Says NJ Took Too Long For Subpoenas In FCA Claim
Court Says NJ Took Too Long For Subpoenas In FCA ClaimBrian Dickerson
 

More from Brian Dickerson (6)

SDM Eclipse Poetry
SDM Eclipse PoetrySDM Eclipse Poetry
SDM Eclipse Poetry
 
The New Overtime Regulations
The New Overtime RegulationsThe New Overtime Regulations
The New Overtime Regulations
 
FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...
FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...
FisherBroyles Alert - Miami Pharmacies Charged with Submitting $26 Million in...
 
FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...
FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...
FisherBroyles Client Alert - FDA Issues Draft Guidance for Compounding Operat...
 
FCPA Self-Reporting Pilot Program: Motivation to Self-Report?
FCPA Self-Reporting Pilot Program: Motivation to Self-Report?FCPA Self-Reporting Pilot Program: Motivation to Self-Report?
FCPA Self-Reporting Pilot Program: Motivation to Self-Report?
 
Court Says NJ Took Too Long For Subpoenas In FCA Claim
Court Says NJ Took Too Long For Subpoenas In FCA ClaimCourt Says NJ Took Too Long For Subpoenas In FCA Claim
Court Says NJ Took Too Long For Subpoenas In FCA Claim
 

Recently uploaded

Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...Sheetaleventcompany
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetraisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012Call Girls Service Gurgaon
 
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in FaridabadNepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabadgragteena
 
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...gurkirankumar98700
 
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in UdaipurUdaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipurseemahedar019
 
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★indiancallgirl4rent
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...Vip call girls In Chandigarh
 
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In ChandigarhHot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In ChandigarhVip call girls In Chandigarh
 
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...Russian Call Girls Amritsar
 
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.ktanvi103
 
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking ModelsDehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Modelsindiancallgirl4rent
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Memriyagarg453
 
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetCall Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meetpriyashah722354
 
Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...
Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...
Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...Niamh verma
 
pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...
pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...
pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...Call Girls Noida
 
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 

Recently uploaded (20)

Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetraisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
 
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in FaridabadNepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
 
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
 
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in UdaipurUdaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipur
 
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
 
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In ChandigarhHot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
 
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
 
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
 
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
 
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking ModelsDehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
 
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetCall Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
 
Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...
Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...
Call Girls Amritsar 💯Call Us 🔝 8725944379 🔝 💃 Independent Escort Service Amri...
 
pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...
pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...
pOOJA sexy Call Girls In Sector 49,9999965857 Young Female Escorts Service In...
 
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 

HIPAA 2016 Phase 2 Audits of Covered Entities and Business Associates

  • 1. FISHERBROYLES.COM TH E NE XT GE N E R AT IO N LA W FI RM ® HIPAA 2016 Audits Phase 2: Covered Entities and Business Associates Take Notice PRACTICE AREA / INDUSTRY: HEALTHCARE; WHITE COLLAR LITIGATION & GOVERNEMENT INVESTIGATIONS Brian E. Dickerson Anthony J. Calamunci brian.dickerson@fisherbroyles.com anthony.calamunci@fisherbroyles.com 202.570.0248 419.376.1776 Nicole Hughes Waid nicole.waid@fisherbroyles.com 202.906.9572 March 22, 2016 As part of its continued effort to assess compliance with the HIPAA Privacy, Security and Breach Notification Rules, the U.S. Department of Health & Human Services (“HHS”) Office for Civil Rights (“OCR”) announced yesterday that it has begun its next phase of audits of covered entities and their business associates. In the 2016 Phase 2 HIPAA Audit Program, OCR will review the policies and procedures of covered entities and their business associates through desk audits however, some on-site audits will also be conducted. This second phase of audits follows OCR’s 2011-2012 pilot program of 115 entities. From the data collected and results achieved, OCR developed enhanced protocols to be used in the 2016 Phase 2 HIPAA Audit Program, including a new strategy to test the efficacy of desk audits in evaluating compliance with privacy, security and breach notification rules. OCR is identifying pools of covered entities and business associates that represent a wide range of health care providers, health plans, health care clearinghouses and business associates. OCR will not audit entities with an open complaint investigation or that are currently undergoing a compliance review. The first desk audits will be for covered entities, followed by a second round of desk audits of business associates. All desk audits in this phase will be completed by the end of December 2016. A third set of audits will be onsite
  • 2. FISHERBROYLES.COM TH E NE XT GE N E R AT IO N LA W FI RM ® and will cover a broader scope of requirements from the HIPAA Rules than desk audits. It is anticipated that results from desk audits may trigger a subsequent onsite audit and potential investigations if deficiencies are uncovered. The audits are underway to review the policies and procedures of covered entities, beginning with an email notification requesting contact information from OCR. Click here to view a sample email. The emails will originate from OSOCRAudit@hhs.gov and if your entity’s spam filtering and virus protection are automatically enabled, OCR expects you to check your junk or spam folders for their email. Failure to respond to the notification email may result in OCR using publicly available information to create its audit pool, thus a desk or onsite audit notification may not reach the appropriate company representative in a timely fashion. OCR will create a pool of targets for desk and onsite audits from the responses to the initial emails. If your entity is chosen for a desk audit, requested information must be submitted electronically within 10 business days of the request. OCR will provide draft findings and auditees will have 10 days to review and return written comments. Similarly, entities chosen for onsite audits will also receive an email notification. OCR will schedule an entrance conference to provide more information about the process and onsite audits will be conducted over a 3-5 day period, depending upon the size of the entity. Entities will have 10 business days to review draft findings and provide written comments to the auditor. OCR will complete and provide a final audit report within 30 business days. As we have advised in our recent client alerts regarding HIPAA enforcement trends, we believe the 2016 Phase 2 HIPAA Audit Program will have a keen focus on business associates and covered entities’ Business Associate Agreements (“BAAs”). Business associates have been covered by HIPAA only since 2013, therefore compliance with the HIPAA Privacy, Security and Breach Notification Rules may not be as robust or as fully vetted as required by OCR. Business associates that conduct third-party billing, data analysis, storage and management, as well as the covered entities who have BAAs with these vendors, are particularly vulnerable to being a target of OCR audits. Covered entities and business associates must exercise due diligence in reviewing their HIPAA compliance programs and conducting system wide audits of their PHI safeguards to identify and update areas that may have vulnerability and could put personal health information at risk. For further information on the subject matter of this alert, please contact the following FisherBroyles attorneys: Brian E. Dickerson brian.dickerson@fisherbroyles.com 202.570.0248 Nicole Hughes Waid nicole.waid@fisherbroyles.com 202.906.9572 Anthony J. Calamunci anthony.calamunci@fisherbroyles.com 419.376.1776