Compliance Review
In the HIPAA context, a compliance review is an investigation-style review conducted by the federal government (HHS Office for Civil Rights, or OCR) to determine whether a covered entity or business associate is following HIPAA rules. Unlike a complaint-driven investigation, a compliance review is generally initiated by OCR itself rather than in response to an outside complaint. Note that outside of HIPAA, the same phrase is also used broadly in other industries to describe an organization's own internal self-checks, which is a different concept.
Under the HIPAA Enforcement Rule (generally at 45 CFR Part 160, Subpart C), a compliance review is one of the mechanisms through which the Secretary of HHS, acting through OCR, assesses whether a covered entity or business associate is in compliance with the applicable HIPAA Administrative Simplification provisions, including the Privacy Rule, Security Rule, and Breach Notification Rule. It is distinct from a complaint investigation in that OCR may initiate a compliance review on its own initiative rather than upon receipt of a complaint; both can lead to requests for information, findings, resolution agreements, corrective action plans, or civil money penalties. This regulatory meaning should not be conflated with the general business or financial-industry usage of 'compliance review' as an internal, self-initiated audit performed by an organization's own compliance function. Readers should verify the specific regulatory authority, scope, and procedures against the current text of the HIPAA Enforcement Rule, as provisions and enforcement practices are subject to change.
Why it matters
A HIPAA compliance review matters because it represents one of the ways federal enforcement can reach an organization without any outside complaint ever being filed. OCR may initiate a compliance review on its own initiative, meaning a covered entity or business associate can come under scrutiny based on OCR's own awareness of a potential issue rather than because a patient, employee, or competitor reported something. Understanding this distinction helps organizations recognize that maintaining HIPAA compliance is not only about responding to complaints; it is about being prepared for federal review at any time.
The outcome of a compliance review can be significant. Like a complaint investigation, a compliance review can lead to requests for information, formal findings, resolution agreements, corrective action plans, or civil money penalties. Because these enforcement mechanisms are administered by HHS OCR and can carry both financial and reputational consequences, organizations generally treat readiness for a compliance review as an integral part of their overall HIPAA program.
There is also an important terminology caution. Outside of HIPAA, the phrase 'compliance review' is widely used across other industries to describe an organization's own internal self-checks or self-audits performed by its compliance function. That common usage is a different concept from the HIPAA meaning, where a compliance review is an investigation-style review conducted by OCR. Conflating the two can lead to confusion about who is conducting the review and what authority backs it, so professionals should be clear about which sense of the term is intended in a given context.
Who it's relevant to
Inside Compliance Review
Common questions
Answers to the questions practitioners most commonly ask about Compliance Review.