OCR Audit Program
The OCR Audit Program is a review process run by the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) to check whether healthcare organizations and their vendors are following HIPAA rules. It uses a published set of review criteria to examine the policies, processes, and controls these organizations have in place. It is one of the ways OCR oversees HIPAA compliance, though a review by OCR examines an organization's practices against HIPAA requirements rather than against private certification frameworks.
The OCR HIPAA Audit Program is an oversight mechanism administered by HHS OCR, established pursuant to the audit mandate under the HITECH Act, that analyzes the processes, controls, and policies of selected covered entities and business associates to assess compliance with applicable HIPAA requirements. OCR conducts these audits using a comprehensive published audit protocol; the protocol referenced in the evidence was last updated July 2018, and practitioners should verify the current protocol version and scope against OCR's published materials. The program is distinct from OCR's complaint-driven and compliance-review investigations, though findings may inform broader enforcement activity. Per an HHS Office of Inspector General report (November 2024), OCR oversight of the audit program was found not to be effective at improving cybersecurity protections at audited entities, indicating that undergoing an audit does not by itself establish or guarantee HIPAA compliance. The program addresses HIPAA obligations enforced by OCR and does not extend to state law, additional HITECH provisions, or private frameworks such as the HITRUST CSF; readers should confirm current audit scope, selection methods, and protocol content against current OCR guidance.
Why it matters
The OCR Audit Program represents one of the ways HHS OCR proactively examines HIPAA compliance rather than waiting for a complaint or a reported breach. Because audits are conducted against a published protocol and can involve both covered entities and business associates, organizations across the healthcare sector may be selected to demonstrate how their policies, processes, and controls map to applicable HIPAA requirements. Understanding the program helps organizations anticipate what OCR may scrutinize and maintain documentation that reflects their actual practices.
Importantly, undergoing an OCR audit does not by itself establish or guarantee HIPAA compliance. An HHS Office of Inspector General report issued in November 2024 found that OCR's oversight of the audit program was not effective at improving cybersecurity protections at audited covered entities and business associates. This finding underscores that an audit is a review activity, not a certification, and that organizations remain responsible for continuously meeting HIPAA obligations regardless of whether they have been audited or what an audit concluded.
The program is also distinct from private certification frameworks. An OCR audit measures an organization's practices against HIPAA requirements enforced by OCR, not against frameworks such as the HITRUST CSF. Holding a private certification does not exempt an organization from OCR review, and the audit scope does not extend to state law or to additional obligations that may arise under other frameworks. Readers should confirm current audit scope, selection methods, and protocol content against current OCR guidance.
Who it's relevant to
Inside OCR Audit Program
Common questions
Answers to the questions practitioners most commonly ask about OCR Audit Program.