Desk Audit
A desk audit is a review that a regulator or auditing body conducts remotely, typically by requesting and examining documents and records rather than visiting the organization in person. In the HIPAA context, it generally refers to a document-based compliance review of a covered entity or business associate. The specific procedures and scope depend on the reviewing authority and the applicable audit protocol.
In HIPAA compliance practice, a desk audit generally denotes a remote, documentation-focused examination in which the reviewing authority requests written evidence of policies, procedures, and other records to evaluate an organization's adherence to applicable HIPAA requirements, in contrast to an on-site audit. The evidence provided in this packet describes 'desk audit' only in an unrelated position-classification and job-evaluation context (a workplace process of collecting job-related information through interviews and observation) and does not supply authoritative detail on HIPAA desk audit scope, procedures, thresholds, or the conduct of HHS Office for Civil Rights (OCR) reviews. Readers should verify the specific meaning, scope, and procedures of any HIPAA-related desk audit against current HHS OCR guidance and the applicable audit protocol, and should not treat the general definition above as establishing regulatory requirements.
Why it matters
For covered entities and business associates, understanding what a desk audit generally involves helps organizations prepare for the possibility of a remote, documentation-based compliance review rather than an on-site inspection. Because a desk audit typically depends on the written evidence an organization can produce on request, the quality and accessibility of policies, procedures, and supporting records can shape how such a review proceeds. Organizations that maintain current, well-organized documentation are generally better positioned to respond to a document request within the timelines a reviewing authority may set.
It is important to note a significant limitation: the evidence available for this entry describes "desk audit" only in an unrelated job and position-classification context, not in a HIPAA enforcement context. As a result, this entry does not establish the specific scope, procedures, selection thresholds, or conduct of any HIPAA desk audit, including reviews administered by the HHS Office for Civil Rights (OCR). The general description above should be treated as practitioner context only, not as a statement of regulatory requirements.
Because the details of any HIPAA-related desk audit, such as what documents may be requested, applicable response deadlines, and how findings are handled, are not supported by the evidence in this packet, readers should verify the specific meaning and procedures against current HHS OCR guidance and the applicable audit protocol before relying on them. State law, the HITECH Act, or other frameworks may also impose additional obligations beyond HIPAA.
Who it's relevant to
Inside Desk Audit
Common questions
Answers to the questions practitioners most commonly ask about Desk Audit.