Skip to main content
Category: OCR Enforcement and Penalties

Audit Protocol

Also known as: HIPAA Audit Protocol, OCR Audit Protocol
Simply put

An audit protocol is a structured framework used to conduct compliance audits in an organized, systematic way. In the HIPAA context, HHS Office for Civil Rights (OCR) publishes an audit protocol that lays out the specific requirements it examines when reviewing whether an organization is meeting its obligations. It serves as a guide to how compliance with the rules is assessed, though readers should always confirm details against the current version published by OCR.

Formal definition

In the HIPAA context, the audit protocol is a published tool developed by HHS OCR that is organized by Rule and regulatory provision and addresses separately the elements of the Privacy Rule, the Security Rule, and the Breach Notification Rule. It sets out the established performance criteria and audit inquiries OCR uses to evaluate covered entities and business associates against applicable requirements. More broadly, an audit protocol is a structured framework for conducting audits systematically to assess compliance with regulations and standards; the scope, criteria, and covered provisions vary by the specific protocol, and practitioners should verify the current OCR audit protocol content, as it is periodically updated. This entry addresses the compliance-assessment meaning of the term and does not describe unrelated program audit or environmental audit protocols referenced in other contexts.

Why it matters

The HIPAA audit protocol matters because it makes the government's compliance expectations transparent. Rather than leaving covered entities and business associates to guess how HHS Office for Civil Rights (OCR) evaluates adherence to the rules, the protocol is organized by Rule and regulatory provision and addresses separately the elements of the Privacy Rule, the Security Rule, and the Breach Notification Rule. This gives organizations a concrete reference point for understanding the specific requirements and audit inquiries OCR uses when assessing compliance.

For compliance teams, the protocol functions as more than an enforcement tool; it is a practical benchmark for internal readiness. Organizations frequently use the established performance criteria set out in the protocol to conduct self-assessments and identify gaps before OCR ever gets involved. Because the protocol distinguishes between the Privacy Rule (which covers PHI in all forms, including oral and paper) and the Security Rule (which governs only electronic PHI), it also helps practitioners map their obligations to the correct rule rather than treating HIPAA as a single undifferentiated standard.

A key limitation is that the protocol is periodically updated, and the criteria and covered provisions can change over time. Aligning to the protocol supports compliance efforts but does not by itself guarantee compliance or prevent breaches, and it does not address obligations that may arise under state law or the HITECH Act. Readers should always confirm details against the current version published by OCR rather than relying on prior editions.

Who it's relevant to

Privacy and Security Officers
Officers responsible for HIPAA compliance can use the audit protocol as a structured reference for self-assessment, mapping their programs to the performance criteria OCR examines under the Privacy, Security, and Breach Notification Rules. Because the protocol separates these rules, it helps officers confirm that ePHI safeguards and broader PHI handling are each addressed against the correct requirements.
Covered Entities and Business Associates
Both covered entities and business associates fall within the scope of OCR's evaluation, and the protocol reflects the requirements applicable to each. Understanding the audit inquiries in advance helps these organizations prepare documentation and demonstrate how they meet applicable obligations, while recognizing that specific obligations flow through defined relationships and business associate agreements.
Internal Auditors and Compliance Consultants
Auditors and consultants who assess healthcare organizations can use the protocol as a benchmark for structuring reviews, drawing on its provision-by-provision organization to plan field work and reporting. They should confirm they are working from the current OCR version and note where state law or the HITECH Act may impose requirements beyond what the protocol covers.
Legal and Regulatory Advisors
Attorneys and regulatory advisors supporting healthcare clients can reference the protocol to explain how OCR frames its assessment of compliance obligations. Because penalty tiers and enforcement approaches are set and adjusted by HHS OCR over time, advisors should treat the protocol as a guide to assessment criteria and confirm enforcement details against current OCR guidance.

Inside Audit Protocol

Privacy Rule Audit Elements
Portions of the protocol that assess compliance with the HIPAA Privacy Rule, covering PHI in all forms including oral, paper, and electronic. These typically address areas such as notice of privacy practices, individual rights, uses and disclosures, and minimum necessary requirements.
Security Rule Audit Elements
Portions that evaluate safeguards for electronic protected health information (ePHI) only. These generally map to the administrative, physical, and technical safeguard categories and address both required and addressable implementation specifications.
Breach Notification Rule Audit Elements
Components assessing whether an entity has processes for identifying, evaluating, and reporting breaches of unsecured PHI to the appropriate parties, as required under the Breach Notification Rule.
Applicability to Covered Entities and Business Associates
The protocol distinguishes obligations that apply to covered entities from those applicable to business associates, reflecting that certain requirements flow through business associate agreements rather than attaching to every vendor directly.
Established Performance Criteria
Each audited requirement is generally tied to specific criteria drawn from the applicable regulatory text against which an entity's documentation and practices are compared.

Common questions

Answers to the questions practitioners most commonly ask about Audit Protocol.

Does passing an OCR audit mean my organization is fully HIPAA compliant?
No. The OCR Audit Protocol assesses selected elements of compliance with the Privacy, Security, and Breach Notification Rules, but an audit generally provides only a point-in-time review of specific requirements. It does not certify overall compliance, and no audit result guarantees that all obligations are met or that breaches will be prevented. Organizations should treat the protocol as a self-assessment and preparation tool rather than as proof of compliance, and should verify their obligations against the current regulatory text.
Is the OCR Audit Protocol the same thing as HITRUST certification?
No. The OCR Audit Protocol is published by HHS OCR to evaluate compliance with HIPAA rules and reflects a federal regulatory framework. HITRUST is a private organization, and its CSF is a certifiable control framework that is not a legal requirement. HITRUST certification does not by itself establish HIPAA compliance, and it is separate from the OCR Audit Protocol. The two can be complementary, but they are distinct in authority, purpose, and legal weight.
How can we use the Audit Protocol to prepare for a potential OCR audit?
Many organizations use the protocol as a structured self-assessment tool, walking through its audit inquiries to identify gaps in their policies, procedures, and documentation across the Privacy, Security, and Breach Notification Rules. This typically involves gathering the documentation the protocol references and comparing current practices against the stated expectations. Because the protocol may be updated, confirm you are working from the current version and cross-reference it against the applicable regulatory text.
Which HIPAA rules does the Audit Protocol cover?
The protocol generally addresses requirements drawn from the Privacy Rule, the Security Rule, and the Breach Notification Rule. Keep in mind that the Privacy Rule covers PHI in all forms, including oral and paper, while the Security Rule applies only to electronic PHI. When reviewing protocol items, it helps to map each inquiry to the correct rule so that safeguards intended for ePHI are not confused with broader privacy obligations.
How should we document our responses to the audit inquiries?
In most cases, organizations maintain written policies, procedures, and evidence that correspond to the specific inquiries in the protocol. For Security Rule items, it is useful to note whether an implementation specification is required or addressable, and, for addressable specifications, to document the reasoning and any alternative measures adopted, since addressable does not mean optional. Retain evidence in a manner that can be readily produced if requested.
Do business associates need to consider the Audit Protocol?
Yes, in many cases. The protocol includes provisions relevant to business associates, whose direct obligations under certain HIPAA rules and through business associate agreements can be subject to OCR review. Business associates and their subcontractors should assess the applicable portions of the protocol, recognizing that obligations attach through defined relationships and BAAs rather than to every vendor that touches data. Confirm scope against the current protocol and the underlying regulatory text.

Common misconceptions

Passing or aligning with the Audit Protocol guarantees HIPAA compliance.
The protocol is a tool that reflects requirements as of the applicable regulatory text; alignment with it does not by itself guarantee compliance or prevent all breaches. Entities remain responsible for meeting current obligations, and state law or the HITECH Act may impose additional requirements. Readers should verify against current guidance.
The Audit Protocol and its Security Rule elements apply to PHI in all forms.
The Security Rule portions of the protocol address only electronic protected health information (ePHI). PHI in oral and paper forms falls under the Privacy Rule elements, not the Security Rule elements.
HITRUST CSF certification satisfies the Audit Protocol or establishes HIPAA compliance.
HITRUST is a private organization and its CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. The Audit Protocol is tied to HIPAA requirements enforced by HHS OCR, which is a separate authority.

Best practices

Map your policies, procedures, and documentation to the specific Privacy, Security, and Breach Notification elements of the protocol rather than treating it as a single undifferentiated checklist.
When reviewing Security Rule elements, confirm coverage of administrative, physical, and technical safeguards, and document your rationale for how each addressable implementation specification is met, since addressable does not mean optional.
Determine whether each requirement applies to you as a covered entity or business associate, and confirm that obligations flowing through business associate agreements are reflected in your contracts.
Verify each protocol element against the current regulatory text and current HHS OCR guidance, as criteria, penalty tiers, and figures are adjusted over time.
Do not rely on HITRUST CSF certification as evidence of protocol compliance; treat the two as separate exercises and confirm the current HITRUST CSF version if using it as a supporting framework.
Assess whether state law or the HITECH Act imposes additional requirements beyond those reflected in the protocol, and document these separately.