{"id":14509,"date":"2017-04-03T14:33:00","date_gmt":"2017-04-03T19:33:00","guid":{"rendered":"https:\/\/medsafe5stg.wpenginepowered.com\/?p=14509"},"modified":"2025-04-22T00:40:35","modified_gmt":"2025-04-21T16:40:35","slug":"hipaa-audits-of-covered-entities-and-business-associates","status":"publish","type":"post","link":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/","title":{"rendered":"HIPAA Audits of Covered Entities and Business Associates"},"content":{"rendered":"\n<p>In August, Advocate Health Care Network agreed to pay a $5.55 million settlement with the U.S. Department of Health and Human Services Office for Civil Rights (OCR), for multiple HIPAA violations. In addition, HHS also recently announced a $650,000 resolution settlement against the Catholic Health Care Services of the Archdiocese of Philadelphia.<\/p>\n\n\n\n<p>These multi-million dollar penalties should be a warning for all covered entities or business associates.&nbsp; Especially, with the next phase of audits now underway. During this phase, OCR is reviewing the policies and procedures utilized by covered entities and their business associates to ensure they meet the standards and specifications of the Privacy, Security, and Breach Notification Rules. These will mostly be desk audits. However, there will be some on-site audits conducted as well.<\/p>\n\n\n\n<p>The audit process began in May 2016 when OCR audit sent emails to verify entity\u2019s address and contact information. The next step was a pre-audit questionnaire that was used to gather information about the size, type, and operations of the facilities. Those who participate in the desk audits are required to provide a list of their business associates and their contact information. Emails will go out to the chosen business associates, who are expected to respond promptly. The audits are expected to focus heavily on breach responses. If a business associate does not respond within the timeframe, they will be scheduled in January 2017 for the comprehensive audits.<\/p>\n\n\n\n<p><strong>Some frequently asked questions regarding audits include:<\/strong><\/p>\n\n\n\n<p><strong>Who Will Be Audited?<\/strong><\/p>\n\n\n\n<p>Every covered entity and business associate are eligible for an audit, including covered individual and organizational providers of health services; health plans, health care clearinghouses; and a range of business associates of these entities.<\/p>\n\n\n\n<p><strong>What is a Business Associate?<\/strong><\/p>\n\n\n\n<p>Business associates are considered any third-party contractor that performs work or activities on behalf of a healthcare organization or covered entity that involve the use or disclosure of protected health information (1).&nbsp; A few examples may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Example of business associates: lawyer\u2019s working on a case, a medical transcription or medical billing companies, document storage or disposal companies, answering services, software vendors, and consultants, patient safety and accreditation organizations, health information exchanges, etc.)<\/li>\n\n\n\n<li>Examples NOT typically considered business associates: an employee, maintenance or repair personnel, a financial or banking institution that only performs payment activities or a janitorial service.<strong>&nbsp;<\/strong><\/li>\n<\/ul>\n\n\n\n<p><strong>What are Business Associate Agreements?<\/strong><\/p>\n\n\n\n<p>HIPAA and HITECH require practices to sign a business associate agreement (BA) with business associates that ensures they will protect all patient&#8217;s PHI. The contract protects personal health information (PHI) by HIPAA guidelines. Business associates can be held accountable for any data breach and penalized for noncompliance (1).<\/p>\n\n\n\n<p><strong>Why are Business Associates Agreements important?<\/strong><\/p>\n\n\n\n<p>Business associate contracts are not only necessary for staying in compliance; they are crucial for the adequate protection of patient PHI.&nbsp; The following are HIPAA requirements for business associate agreements:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Establish the permitted and required uses and disclosures of protected health information by the business associate.<\/li>\n\n\n\n<li>Provide that the business associate will not use or further disclose the information other than as permitted or required by the contract or as required by law.<\/li>\n\n\n\n<li>Require the business associate to implement appropriate safeguards to prevent unauthorized use or disclosure of the information, including implementing requirements of the HIPAA Security Rule about electronic protected health information.<\/li>\n\n\n\n<li>Require the business associate to report to the covered entity any use or disclosure of the information not provided for by its contract, including incidents that constitute breaches of unsecured protected health information.<\/li>\n\n\n\n<li>Require the business associate to disclose protected health information as specified in its contract to satisfy a covered entity\u2019s obligation with respect to individuals&#8217; requests for copies of their protected health information, as well as make available protected health information for amendments (and incorporate any amendments, if required) and accountings.<\/li>\n\n\n\n<li>To the extent the business associate is to carry out a covered entity\u2019s obligation under the Privacy Rule, require the business associate to comply with the requirements applicable to the obligation.<\/li>\n\n\n\n<li>Require the business associate to make available to HHS its internal practices, books, and records relating to the use and disclosure of protected health information received from, or created or received by the business associate on behalf of, the covered entity for purposes of HHS determining the covered entity\u2019s compliance with the HIPAA Privacy Rule.<\/li>\n\n\n\n<li>At termination of the contract, if feasible, require the business associate to return or destroy all protected health information received from, or created or received by the business associate on behalf of, the covered entity.<\/li>\n\n\n\n<li>Require the business associate to ensure that any subcontractors it may engage on its behalf that will have access to protected health information agree to the same restrictions and conditions that apply to the business associate with respect to such information.<\/li>\n\n\n\n<li>Authorize termination of the contract by the covered entity if the business associate violates a material term of the contract.&nbsp; Contracts between business associates and business associates that are subcontractors are subject to these same requirements. (1)<\/li>\n<\/ol>\n\n\n\n<p><strong>How Will Auditees Be Selected?<\/strong><\/p>\n\n\n\n<p>OCR is identifying groups of covered entities and business associates that represent a broad range of health care providers, health plans, health care clearinghouses and business associates.&nbsp; According to HHS, the sampling criteria for selection will include the size of the entity, affiliation with other healthcare organizations, the type of entity and its relationship to individuals, whether an organization is public or private, geographic factors, and present enforcement activity with OCR. OCR will not audit entities with an open complaint investigation or that are currently undergoing a compliance review.<\/p>\n\n\n\n<p><strong>What If an Entity Doesn\u2019t Respond to OCR\u2019s Requests for Information?<\/strong><\/p>\n\n\n\n<p>If an entity does not respond to requests for information from OCR, they will utilize publicly available information about the entity to create its audit pool.&nbsp; An entity that does not respond to OCR may still be selected for an audit or subject to a compliance review.<\/p>\n\n\n\n<p><em>If your organization or practice has a question regarding HIPAA audits or business associate agreements, contact the experts at MedSafe at 1-888-MEDSAFE or visit our website at www.medsafe.com.<\/em><\/p>\n\n\n\n<p>References:<a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/covered-entities\/sample-business-associate-agreement-provisions\/index.html\">http:\/\/www.hhs.gov\/hipaa\/for-professionals\/covered-entities\/sample-business-associate-agreement-provisions\/index.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In August, Advocate Health Care Network agreed to pay a $5.55 million settlement with the U.S. Department of Health and Human Services Office for Civil Rights (OCR), for multiple HIPAA [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[18],"tags":[],"class_list":["post-14509","post","type-post","status-publish","format-standard","hentry","category-hipaa-compliance"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v26.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>HIPAA Audits of Covered Entities and Business Associates - MedSafe<\/title>\n<meta name=\"description\" content=\"Understand the significance of recent multi-million dollar settlements for HIPAA violations and the upcoming phase of audits\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HIPAA Audits of Covered Entities and Business Associates\" \/>\n<meta property=\"og:description\" content=\"Understand the significance of recent multi-million dollar settlements for HIPAA violations and the upcoming phase of audits\" \/>\n<meta property=\"og:url\" content=\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\" \/>\n<meta property=\"og:site_name\" content=\"MedSafe\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/MedSafeCompliance\" \/>\n<meta property=\"article:published_time\" content=\"2017-04-03T19:33:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-21T16:40:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/medsafe.com\/wp-content\/uploads\/2025\/05\/medsafe-organization-logo.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"696\" \/>\n\t<meta property=\"og:image:height\" content=\"696\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Tyler Howard\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tyler Howard\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\"},\"author\":{\"name\":\"Tyler Howard\",\"@id\":\"https:\/\/medsafe.com\/#\/schema\/person\/8e449dab4624185a0388141159b08c10\"},\"headline\":\"HIPAA Audits of Covered Entities and Business Associates\",\"datePublished\":\"2017-04-03T19:33:00+00:00\",\"dateModified\":\"2025-04-21T16:40:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\"},\"wordCount\":1038,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/medsafe.com\/#organization\"},\"articleSection\":[\"HIPAA Compliance\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\",\"url\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\",\"name\":\"HIPAA Audits of Covered Entities and Business Associates - MedSafe\",\"isPartOf\":{\"@id\":\"https:\/\/medsafe.com\/#website\"},\"datePublished\":\"2017-04-03T19:33:00+00:00\",\"dateModified\":\"2025-04-21T16:40:35+00:00\",\"description\":\"Understand the significance of recent multi-million dollar settlements for HIPAA violations and the upcoming phase of audits\",\"breadcrumb\":{\"@id\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/medsafe.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HIPAA Audits of Covered Entities and Business Associates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/medsafe.com\/#website\",\"url\":\"https:\/\/medsafe.com\/\",\"name\":\"MedSafe\",\"description\":\"The Total Compliance Solution\",\"publisher\":{\"@id\":\"https:\/\/medsafe.com\/#organization\"},\"alternateName\":\"MedSafe Healthcare Compliance\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/medsafe.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/medsafe.com\/#organization\",\"name\":\"MedSafe\",\"url\":\"https:\/\/medsafe.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/medsafe.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/medsafe.com\/wp-content\/uploads\/2025\/05\/medsafe-organization-logo.webp\",\"contentUrl\":\"https:\/\/medsafe.com\/wp-content\/uploads\/2025\/05\/medsafe-organization-logo.webp\",\"width\":696,\"height\":696,\"caption\":\"MedSafe\"},\"image\":{\"@id\":\"https:\/\/medsafe.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/MedSafeCompliance\",\"https:\/\/www.instagram.com\/medsafetcs\/\",\"https:\/\/www.youtube.com\/@MedSafeTCS\/featured\",\"https:\/\/www.linkedin.com\/company\/medsafe-the-total-compliance-solution-\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/medsafe.com\/#\/schema\/person\/8e449dab4624185a0388141159b08c10\",\"name\":\"Tyler Howard\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/medsafe.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6bf709312d28530eb3e3156e3916ce52728f96c99a0b4795127070d6ddde124b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6bf709312d28530eb3e3156e3916ce52728f96c99a0b4795127070d6ddde124b?s=96&d=mm&r=g\",\"caption\":\"Tyler Howard\"},\"description\":\"Tyler Howard is a passionate writer and industry expert with a keen eye for technology, business insights, and digital innovation. With years of experience in content creation, he brings engaging and informative articles that keep readers ahead of the curve. Whether exploring emerging trends or offering practical advice, Tyler's work aims to educate, inspire, and empower his audience. Stay tuned for his latest insights and thought-provoking discussions.\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"HIPAA Audits of Covered Entities and Business Associates - MedSafe","description":"Understand the significance of recent multi-million dollar settlements for HIPAA violations and the upcoming phase of audits","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/","og_locale":"en_US","og_type":"article","og_title":"HIPAA Audits of Covered Entities and Business Associates","og_description":"Understand the significance of recent multi-million dollar settlements for HIPAA violations and the upcoming phase of audits","og_url":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/","og_site_name":"MedSafe","article_publisher":"https:\/\/www.facebook.com\/MedSafeCompliance","article_published_time":"2017-04-03T19:33:00+00:00","article_modified_time":"2025-04-21T16:40:35+00:00","og_image":[{"width":696,"height":696,"url":"https:\/\/medsafe.com\/wp-content\/uploads\/2025\/05\/medsafe-organization-logo.webp","type":"image\/webp"}],"author":"Tyler Howard","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Tyler Howard","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/#article","isPartOf":{"@id":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/"},"author":{"name":"Tyler Howard","@id":"https:\/\/medsafe.com\/#\/schema\/person\/8e449dab4624185a0388141159b08c10"},"headline":"HIPAA Audits of Covered Entities and Business Associates","datePublished":"2017-04-03T19:33:00+00:00","dateModified":"2025-04-21T16:40:35+00:00","mainEntityOfPage":{"@id":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/"},"wordCount":1038,"commentCount":0,"publisher":{"@id":"https:\/\/medsafe.com\/#organization"},"articleSection":["HIPAA Compliance"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/","url":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/","name":"HIPAA Audits of Covered Entities and Business Associates - MedSafe","isPartOf":{"@id":"https:\/\/medsafe.com\/#website"},"datePublished":"2017-04-03T19:33:00+00:00","dateModified":"2025-04-21T16:40:35+00:00","description":"Understand the significance of recent multi-million dollar settlements for HIPAA violations and the upcoming phase of audits","breadcrumb":{"@id":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/medsafe.com\/hipaa-compliance\/hipaa-audits-of-covered-entities-and-business-associates\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/medsafe.com\/"},{"@type":"ListItem","position":2,"name":"HIPAA Audits of Covered Entities and Business Associates"}]},{"@type":"WebSite","@id":"https:\/\/medsafe.com\/#website","url":"https:\/\/medsafe.com\/","name":"MedSafe","description":"The Total Compliance Solution","publisher":{"@id":"https:\/\/medsafe.com\/#organization"},"alternateName":"MedSafe Healthcare Compliance","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/medsafe.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/medsafe.com\/#organization","name":"MedSafe","url":"https:\/\/medsafe.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/medsafe.com\/#\/schema\/logo\/image\/","url":"https:\/\/medsafe.com\/wp-content\/uploads\/2025\/05\/medsafe-organization-logo.webp","contentUrl":"https:\/\/medsafe.com\/wp-content\/uploads\/2025\/05\/medsafe-organization-logo.webp","width":696,"height":696,"caption":"MedSafe"},"image":{"@id":"https:\/\/medsafe.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/MedSafeCompliance","https:\/\/www.instagram.com\/medsafetcs\/","https:\/\/www.youtube.com\/@MedSafeTCS\/featured","https:\/\/www.linkedin.com\/company\/medsafe-the-total-compliance-solution-\/"]},{"@type":"Person","@id":"https:\/\/medsafe.com\/#\/schema\/person\/8e449dab4624185a0388141159b08c10","name":"Tyler Howard","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/medsafe.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6bf709312d28530eb3e3156e3916ce52728f96c99a0b4795127070d6ddde124b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6bf709312d28530eb3e3156e3916ce52728f96c99a0b4795127070d6ddde124b?s=96&d=mm&r=g","caption":"Tyler Howard"},"description":"Tyler Howard is a passionate writer and industry expert with a keen eye for technology, business insights, and digital innovation. With years of experience in content creation, he brings engaging and informative articles that keep readers ahead of the curve. Whether exploring emerging trends or offering practical advice, Tyler's work aims to educate, inspire, and empower his audience. Stay tuned for his latest insights and thought-provoking discussions."}]}},"_links":{"self":[{"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/posts\/14509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/comments?post=14509"}],"version-history":[{"count":0,"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/posts\/14509\/revisions"}],"wp:attachment":[{"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/media?parent=14509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/categories?post=14509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/medsafe.com\/wp-json\/wp\/v2\/tags?post=14509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}