Skip to main content
Category: OCR Enforcement and Penalties

OCR Audit Program

Also known as: OCR HIPAA Audit Program, HIPAA Audit Program
Simply put

The OCR Audit Program is a review process run by the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) to check whether healthcare organizations and their vendors are following HIPAA rules. It uses a published set of review criteria to examine the policies, processes, and controls these organizations have in place. It is one of the ways OCR oversees HIPAA compliance, though a review by OCR examines an organization's practices against HIPAA requirements rather than against private certification frameworks.

Formal definition

The OCR HIPAA Audit Program is an oversight mechanism administered by HHS OCR, established pursuant to the audit mandate under the HITECH Act, that analyzes the processes, controls, and policies of selected covered entities and business associates to assess compliance with applicable HIPAA requirements. OCR conducts these audits using a comprehensive published audit protocol; the protocol referenced in the evidence was last updated July 2018, and practitioners should verify the current protocol version and scope against OCR's published materials. The program is distinct from OCR's complaint-driven and compliance-review investigations, though findings may inform broader enforcement activity. Per an HHS Office of Inspector General report (November 2024), OCR oversight of the audit program was found not to be effective at improving cybersecurity protections at audited entities, indicating that undergoing an audit does not by itself establish or guarantee HIPAA compliance. The program addresses HIPAA obligations enforced by OCR and does not extend to state law, additional HITECH provisions, or private frameworks such as the HITRUST CSF; readers should confirm current audit scope, selection methods, and protocol content against current OCR guidance.

Why it matters

The OCR Audit Program represents one of the ways HHS OCR proactively examines HIPAA compliance rather than waiting for a complaint or a reported breach. Because audits are conducted against a published protocol and can involve both covered entities and business associates, organizations across the healthcare sector may be selected to demonstrate how their policies, processes, and controls map to applicable HIPAA requirements. Understanding the program helps organizations anticipate what OCR may scrutinize and maintain documentation that reflects their actual practices.

Importantly, undergoing an OCR audit does not by itself establish or guarantee HIPAA compliance. An HHS Office of Inspector General report issued in November 2024 found that OCR's oversight of the audit program was not effective at improving cybersecurity protections at audited covered entities and business associates. This finding underscores that an audit is a review activity, not a certification, and that organizations remain responsible for continuously meeting HIPAA obligations regardless of whether they have been audited or what an audit concluded.

The program is also distinct from private certification frameworks. An OCR audit measures an organization's practices against HIPAA requirements enforced by OCR, not against frameworks such as the HITRUST CSF. Holding a private certification does not exempt an organization from OCR review, and the audit scope does not extend to state law or to additional obligations that may arise under other frameworks. Readers should confirm current audit scope, selection methods, and protocol content against current OCR guidance.

Who it's relevant to

Covered Entities
Healthcare providers, health plans, and healthcare clearinghouses may be selected for an OCR audit and asked to demonstrate how their policies, processes, and controls align with applicable HIPAA requirements. Maintaining accurate, current documentation that reflects actual practices is important, since the audit protocol focuses on processes and controls rather than certifications.
Business Associates and Subcontractors
Business associates are also within the scope of the OCR audit program and may be selected for review of their HIPAA compliance. Because obligations attach through defined relationships and business associate agreements, these organizations should be prepared to show how they meet the HIPAA requirements applicable to them.
Privacy and Security Officers
Those responsible for HIPAA compliance programs should understand the audit protocol structure and keep supporting documentation audit-ready. Given the November 2024 OIG finding that audit oversight was not effective at improving cybersecurity protections, officers should treat an audit as a review activity rather than evidence that their program fully satisfies HIPAA.
Compliance Auditors and Legal Counsel
Professionals advising healthcare organizations should be able to distinguish an OCR audit from complaint-driven and compliance-review investigations, and should recognize that audit findings may inform broader enforcement activity. They should also verify the current protocol version, selection methods, and scope against OCR's published materials, and flag where state law or other frameworks may impose additional requirements beyond HIPAA.

Inside OCR Audit Program

Statutory Basis
The OCR Audit Program is conducted by the HHS Office for Civil Rights (OCR), which is authorized under the HITECH Act to periodically audit covered entities and business associates for compliance with the HIPAA Privacy, Security, and Breach Notification Rules.
Scope of Review
Audits generally assess compliance across the Privacy Rule (covering PHI in all forms), the Security Rule (covering only ePHI through administrative, physical, and technical safeguards), and the Breach Notification Rule. The specific selection of provisions reviewed can vary by audit cycle and should be confirmed against current OCR guidance.
Audited Population
Both covered entities and business associates may be selected. Because HIPAA obligations attach through defined relationships, business associates are subject to audit for the obligations that flow to them, including those established through business associate agreements.
Documentation-Based Assessment
OCR audits typically rely on the entity's ability to produce policies, procedures, and evidence of implementation, such as risk analyses, safeguard documentation, and breach notification records. The precise document requests and timelines depend on the applicable audit protocol.
Audit Protocol
OCR has published an audit protocol enumerating the requirements it evaluates, mapped to Privacy, Security, and Breach Notification Rule provisions. Practitioners should verify the current version, as protocols are updated over time.
Outcome and Enforcement Relationship
Audits are primarily a compliance-review mechanism, though findings can, in some cases, lead to further review or referral for enforcement. Enforcement, penalties, and penalty tiers are administered by OCR and are adjusted over time; figures should be confirmed against current guidance.

Common questions

Answers to the questions practitioners most commonly ask about OCR Audit Program.

If my organization was selected for an OCR audit, does that mean OCR believes we have violated HIPAA?
Not necessarily. Selection for an OCR audit does not, by itself, indicate that OCR has determined a violation occurred. The audit program is generally designed as a compliance assessment mechanism rather than a punitive action, though audit findings could in some cases lead to further review. Organizations should confirm the current purpose and scope of the program against OCR's current published guidance.
Does passing or completing an OCR audit certify that we are HIPAA compliant?
No. Completing an OCR audit does not constitute a certification of HIPAA compliance, and HHS OCR generally does not issue compliance certifications. HIPAA compliance is an ongoing obligation, and an audit typically reflects only a point-in-time review of selected requirements. Organizations should not represent an audit as proof of overall compliance and should verify OCR's current characterization of audit outcomes.
Which entities can be selected for an OCR audit?
The audit program has generally been structured to review both covered entities and business associates, consistent with the distinct HIPAA obligations that attach to each. The specific pool, selection criteria, and eligible entity types can vary by audit cycle, so readers should confirm the current parameters against OCR's applicable guidance for the relevant program phase.
What kinds of documentation should we be prepared to produce for an OCR audit?
Requested materials typically relate to the Privacy Rule, Security Rule, and Breach Notification Rule requirements under review, which may include policies and procedures, risk analysis documentation, and evidence of implemented safeguards. Because the Security Rule addresses electronic PHI while the Privacy Rule covers PHI in all forms, requested documentation can span multiple rules. The precise document requests and response timeframes are set by OCR for each audit and should be confirmed against current instructions.
How should we handle the tight response timeframes that OCR audits can involve?
Audit responses generally must be submitted within timeframes specified by OCR, which can be short. Maintaining current, organized, and readily retrievable documentation, such as risk analyses and up-to-date policies, typically helps organizations respond efficiently. Because specific deadlines vary by audit and cycle, organizations should confirm the applicable response window in OCR's request materials rather than relying on general assumptions.
How does OCR audit readiness relate to frameworks such as the HITRUST CSF?
Using a control framework like the HITRUST CSF may help an organization structure and document its safeguards in ways that can support audit readiness, but HITRUST is a private organization and its certification is not a legal requirement and does not by itself establish HIPAA compliance or satisfy an OCR audit. Audit readiness generally depends on demonstrating compliance with the applicable HIPAA rules directly, so organizations should map any framework-based work back to the specific regulatory requirements.

Common misconceptions

The OCR Audit Program only applies to covered entities such as hospitals and health plans.
Business associates may also be selected for audit. HIPAA obligations attach to business associates through defined relationships and business associate agreements, so they can be reviewed for the requirements applicable to them.
Holding HITRUST CSF certification means an entity will pass an OCR audit or is exempt from being audited.
HITRUST is a private organization and its CSF is a certifiable control framework, not a legal requirement. Certification does not by itself establish HIPAA compliance and does not exempt an entity from selection or review under the OCR Audit Program, which evaluates compliance against the HIPAA Rules as enforced by OCR.
An OCR audit is the same thing as an enforcement action or automatically results in penalties.
Audits are primarily a compliance-review mechanism. While findings can in some cases lead to further review or referral, an audit is distinct from an enforcement action, and penalty determinations follow OCR's enforcement processes.

Best practices

Maintain a current, documented risk analysis and evidence of implemented administrative, physical, and technical safeguards, keeping in mind that addressable implementation specifications are not optional and require documented decisions.
Review the current OCR audit protocol and map your policies, procedures, and evidence to the Privacy, Security, and Breach Notification Rule provisions it addresses, verifying you are using the latest published version.
Ensure business associate agreements are in place and up to date, and confirm that business associates can produce documentation for the obligations that flow to them, since they may be audited independently.
Organize documentation so it can be produced quickly, since OCR audits generally rely on the entity's ability to demonstrate compliance through readily available records within specified timelines.
Do not treat HITRUST certification or any single framework as sufficient to demonstrate HIPAA compliance for audit purposes; assess compliance directly against the applicable HIPAA Rules.
Account for additional requirements that may apply beyond HIPAA, such as state law or HITECH Act provisions, and confirm any penalty or deadline references against current OCR guidance rather than relying on fixed figures.