Highlights
- HHS has announced that its HIPAA audit program will resume.
- Fifty covered entities and business associates will be selected for an audit.
- The audits will focus on selected provisions of the HIPAA Security Rule most relevant to hacking and ransomware attacks.
- Although HIPAA audits are primarily a compliance improvement activity, HHS may investigate a regulated entity if an audit reveals a serious compliance issue.
HIPAA Security Rule
The HIPAA Security Rule sets a national floor for the protection of individuals’ electronic protected health information (ePHI) by covered entities (health plans, health care clearinghouses and most health care providers) and their business associates. These standards require regulated entities to analyze the risks and vulnerabilities of the confidentiality, integrity and availability of their ePHI. The risk assessment process helps regulated entities implement reasonable and appropriate administrative, physical and technical safeguards to protect their ePHI.
HIPAA Audit Program
This article is not intended to be exhaustive nor should any discussion or opinions be construed as legal advice. Readers should contact legal counsel for legal advice. ©2025 Zywave, Inc. All rights reserved.