OCR Program Guide for Audits

Practical guidance for healthcare teams and business associates

The OCR HIPAA audit program is a compliance enforcement initiative operated by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Mandated by the HITECH Act of 2009, the program proactively evaluates whether covered entities and business associates comply with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule - without waiting for a breach or complaint to trigger a review.

Key Facts About the OCR Audit Program

  • Response window: Organizations typically have 10 business days to respond to documentation requests during a desk audit.
  • Audit types: Desk audits (remote document review, focused on 2-3 protocol areas) and on-site audits (comprehensive, includes staff interviews and physical inspection).
  • Who is subject: All covered entities (health plans, healthcare providers, clearinghouses) and business associate.
  • Selection criteria: Organization size and type, geographic diversity, prior compliance history, breach reports, and random selection.
  • Historical enforcement context: OCR has imposed over $142 million in HIPAA penalties since the enforcement program began, with the majority of cases citing inadequate risk assessments (45 CFR 164.308(a)(1)(ii)(A)) as a primary or contributing finding.
  • Key CFR references: Administrative safeguards (45 CFR 164.308), documentation retention (45 CFR 164.530(j) - six-year minimum).

The OCR audit program is one of the most powerful enforcement tools available to the Department of Health and Human Services (HHS) Office for Civil Rights. Since its inception, the program has at its core reshaped how healthcare groups approach HIPAA compliance. Rather than waiting for a breach to trigger an review, the OCR audit program proactively examines whether covered entities and business associates keep the policies, steps, and protections required by federal law.

For healthcare groups of every size, understanding the OCR audit process is not optional. An audit notice can arrive at any time. The window for producing records is narrow. Groups that prepare in advance greatly reduce their risk of adverse findings and financial penalties. This guide provides a complete overview of how the OCR audit program operates and what your group must do to be ready.

How the OCR Audit Program Works

The HITECH Act of 2009 mandated that HHS conduct regular audits of covered entities and business associates to assess compliance with the HIPAA Privacy, Security, and Breach notice Rules. The OCR was named as the agency responsible for carrying out this mandate. The audit program operates independently from OCRÂ’s complaint-driven reviews, meaning your group can face an audit even if no breach or complaint has been filed.

OCR built its audit step after consulting with industry groups. The result is a structured method that checks specific rules. The process has changed over time. Each round taught OCR new lessons about common gaps and emerging threats.

Audit Selection Process

OCR picks audit targets based on several factors. The agency keeps a database of covered entities and business associates. This list comes from breach reports, past complaints, and public records. Selection criteria include:

  • group size and type (large health systems, small practices, health plans, clearinghouses, business associates).
  • Geographic diversity to ensure national coverage.
  • Prior compliance history including breach reports filed with OCR.
  • Random selection to ensure that any group could be audited no matter what of history.

When selected, groups receive a notice letter requesting specific written records within a defined timeframe, often 10 business days. Failing to respond or providing incomplete written records is itself a compliance gap that OCR records in its findings.

Audit Protocol Areas

The OCR audit step evaluates compliance across three primary rule-based domains:

  • Privacy Rule rules including Notice of Privacy Practices, patient access rights, minimum needed standard, authorizations, and uses and shares of PHI.
  • Security Rule rules including admin protections, physical protections, tech protections, and team-level rule.
  • Breach notice Rule rules including breach risk analysis method, notice steps, and written records of breach decision.

Each area contains specific audit questions tied to rule terms. Auditors check three things. Has the group put required policies in place? Are those policies followed in practice? Does enough written proof exist to show compliance?

Phase 1 and Phase 2 Audits

Phase 1: The Pilot Program

OCR launched Phase 1 of its audit program in 2011-2012 as a pilot effort. During Phase 1, OCR ran 115 on-site audits of covered entities across the country. These complete audits examined compliance with all aspects of the Privacy, Security, and Breach notice Rules.

Key findings from Phase 1 revealed widespread compliance gaps:

  • Security Rule gaps were the most common, especially in risk analysis and risk management.
  • Many groups lacked complete and current policies and steps.
  • Smaller groups showed greatly more compliance gaps than larger group.
  • Risk analysis was the single most frequently cited gap across all audited group.

Phase 1 findings directly influenced the design of Phase 2, as OCR recognized the need for a more scalable approach that could reach a larger number of groups.

Phase 2: Desk Audits and Expanded Scope

Phase 2 of the OCR audit program introduced a at its core different approach. Rather than running resource-intensive on-site visits for every audit, Phase 2 primarily uses desk audits, which are ran remotely through record review. This model allows OCR to audit far more groups while focusing its on-site resources on the most major compliance concerns.

Phase 2 operates in two stages:

  1. Desk audits check specific, focused areas of compliance by requesting targeted written records from the selected group.
  2. On-site audits are ran for a subset of groups, especially those where desk audit findings suggest major compliance concern.

Phase 2 also expanded the scope of the program to include business associates for the first time, reflecting the increasing role that vendors, contractors, and service providers play in handling health data.

Desk Audits vs. On-Site Audits

Understanding Desk Audits

Desk audits are the primary audit tool in the current OCR program. During a desk audit, OCR requests specific written records from the audited group and reviews it remotely. The audit focuses on a limited number of step areas rather than checking every aspect of HIPAA compliance.

A typical desk audit process follows these steps:

  1. OCR sends a notice letter identifying the group for audit.
  2. The group completes a pre-audit screening questionnaire about its size, operations, and contact information.
  3. OCR requests specific written records related to the selected step area.
  4. The group submits written records within the required timeframe.
  5. OCR auditors review the items and prepare a draft audit report.
  6. The group receives the draft report and has an chance to respond.
  7. OCR finalizes the audit report.

Desk audits often focus on two to three step areas per audit. Common focus areas include risk analysis written records, policies governing access to PHI, breach notice steps, and Notice of Privacy Practices.

Understanding On-Site Audits

On-site audits are more complete and intrusive. OCR auditors physically visit the groupÂ’s facilities to examine compliance in greater depth. On-site audits may include:

  • Interviews with key staff including the Privacy Officer, Security Officer, and other team member.
  • Observation of physical protections such as workstation security, facility access controls, and record handling habit.
  • Review of tech systems including access controls, audit logs, encryption setup, and incident response step.
  • Examination of training records to verify that team members receive required HIPAA training.
  • review of business associate management including BAA list and vendor oversight habit.

On-site audits are often reserved for groups where desk audit findings show possible systemic compliance failures, or where the nature of the groupÂ’s operations warrants more detailed examination.

Common OCR Audit Findings

Most Frequently Cited gaps

Across both Phase 1 and Phase 2 audits, certain compliance failures appear with striking regularity. Understanding these common findings allows groups to prioritize their compliance efforts where they matter most.

Security Rule findings:

  • Incomplete or absent risk analysis remains the number one finding across all audit round.
  • Inadequate risk management plans that fail to address identified weak spot.
  • Missing or outdated policies and steps for Security Rule admin protection.
  • Insufficient access controls including failure to implement unique user finding and automatic logoff.
  • Lack of encryption for ePHI at rest and in transit.
  • Incomplete audit logging and failure to regularly review audit log.

Privacy Rule findings:

  • Deficient Notice of Privacy Practices that fail to include all required element.
  • Failure to implement the minimum needed standard when using or disclosing PHI.
  • Inadequate patient access steps including failure to provide records within required timeframe.
  • Missing or incomplete access rights forms that lack required element.
  • Insufficient team training on Privacy Rule rule.

Breach notice Rule findings:

  • Absent or incomplete breach risk analysis method.
  • Failure to record breach decisions including the four-factor risk analysis.
  • Inadequate notice steps and failure to meet notice timeframe.
  • Incomplete breach log or failure to keep required written records of breaches affecting fewer than 500 people.

groups that address these high-frequency findings before an audit dramatically improve their compliance posture. For a deeper understanding of how penalties escalate from these findings, see our guide on HIPAA penalties and enforcement actions.

Preparing for an OCR Audit

Building a State of Continuous Readiness

The most effective audit preparation strategy is not a last-minute scramble but a continuous audit readiness program that keeps written records current and habits aligned with policy. Healthcare groups should adopt the following preparation strategies:

Conduct a complete risk analysis annually. This is the single most important compliance action you can undertake. Your risk analysis should identify all systems that create, receive, keep, or transmit ePHI, check threats and weak spots to those systems, assess the likelihood and impact of possible risks, and record the security measures in place to reduce identified risks.

keep a complete policy and step library. Every HIPAA rule-based rule should have a corresponding written policy and step. Policies must be reviewed and updated regularly, and updates must be written down with version history. Staff must be trained on relevant policies and must acknowledge that training in writing.

Implement and record a risk management plan. Your risk management plan should directly address every major risk identified in your risk analysis. For each risk, record the reduction strategy selected, the timeline for setup, the responsible party, and the current status.

set up a robust training program. keep detailed training records that include the date of training, topics covered, trainer identity, attendee names, and acknowledgment signatures. Training should occur at hire, annually, and whenever major policy changes are implemented.

Document Categories OCR Typically Requests

When selected for an audit, OCR requests documents in specific categories. Knowing these categories in advance helps. You can gather and organize materials before the 10-business-day response window starts.

  • Risk analysis and risk management - Your current risk analysis methodology, findings, risk register, and the risk management plan showing how identified risks are being addressed (45 CFR 164.308(a)(1)(ii)(A) and (B)).
  • Policies and procedures - All HIPAA-related policies with version history, review dates, and evidence of workforce distribution.
  • Workforce training - Training materials, attendance records, dates, topics covered, and acknowledgment documentation.
  • Business Associate Agreements - Current BAA inventory with signed agreements for all vendors handling PHI.
  • Access control documentation - User access lists, role-based access policies, procedures for granting and revoking access, and unique user identification records (45 CFR 164.312(a)(1)).
  • Audit logs and review records - System activity logs for ePHI-containing systems and evidence of regular log review (45 CFR 164.312(b)).
  • Incident response and breach records - Incident response plan, breach risk assessments, notification records, and breach log.
  • Physical safeguard documentation - Facility security plans, workstation use policies, and device/media disposal record.
  • Contingency planning - Data backup procedures, disaster recovery plan, and emergency mode operation plan (45 CFR 164.308(a)(7)).
  • Sanction policy - Written sanction policy and records of any sanctions applied to workforce members (45 CFR 164.308(a)(1)(ii)(C)).
  • Notice of Privacy Practices - Current NPP with distribution records and acknowledgment form.

Documentation Requirements

OCR auditors rely heavily on written records to assess compliance. Your group must be able to produce the following on short notice (all documentation must be retained for a minimum of six years per 45 CFR 164.530(j)):

  • Current risk analysis with supporting method written record.
  • Risk management plan with setup statu.
  • Complete HIPAA policies and steps with revision history.
  • team training records including content, dates, and attendance.
  • Business Associate Agreements for all vendors handling PHI.
  • Breach notice written records including risk reviews and notice record.
  • Incident response records writing down security incidents and their resolution.
  • System action logs and audit trail reviews.
  • Physical safeguard written records including facility security plan.
  • Sanction policy and records of any sanctions imposed.

keeping a centralized compliance written records storage ensures that your group can respond promptly to audit requests. groups that struggle to locate or produce requested written records face extra scrutiny and adverse findings. For a broader view of what HIPAA requires, review our complete HIPAA rule-keeping guide.

Developing a Corrective Action Plan

When an OCR audit identifies gaps, the group is expected to develop and implement a Corrective Action Plan (CAP). A strong CAP shows good faith and a commitment to compliance, which can influence OCRÂ’s enforcement decisions.

An effective CAP should include:

  • Specific finding of each gap cited in the audit report.
  • Root cause analysis explaining why the gap exist.
  • Detailed fixes steps with clear, measurable action.
  • Responsible parties assigned to each fixes task.
  • setup timeline with realistic but prompt deadline.
  • Verification method explaining how the group will confirm fixes is complete.
  • Monitoring terms to prevent recurrence of the gap.

groups that proactively develop CAPs and show meaningful progress toward fixes are far more likely to resolve audit findings without escalation to formal enforcement action.

What Happens After an Audit

Audit Reports and Follow-Up

After completing its review, OCR issues a draft audit report to the audited group. The group often has 10 business days to review the draft and submit a written response handling the findings. OCR considers the groupÂ’s response when preparing the final audit report.

The final audit report records:

  • The scope of the audit and step areas examined.
  • Findings for each step area, including whether the group met, partially met, or did not meet the relevant rule.
  • Specific gaps identified with reference to the relevant rule-based term.
  • The groupÂ’s response to the draft finding.

Escalation to Enforcement

While the OCR audit program is described as a compliance improvement tool rather than a punitive tool, audit findings can and do lead to enforcement action. If an audit reveals serious or systemic compliance failures, OCR may:

  • Refer the matter to its enforcement division for formal review.
  • Require the group to enter into a Resolution Agreement with a monetary settlement and multi-year CAP.
  • In egregious cases, pursue civil monetary penalties through an admin hearing.

The relationship between audits and enforcement underscores why proactive preparation is essential. groups that treat audit preparation as an ongoing priority rather than a reactive exercise protect themselves from the most serious consequences of non-compliance. If an audit finding escalates into a formal complaint or enforcement action, knowing how to respond to a HIPAA complaint can significantly affect the outcome. Understanding the full scope of HIPAA enforcement helps groups appreciate the stakes involved.

OCR Audit FAQ

How often does OCR conduct audits?

OCR conducts audits in rounds rather than on a fixed annual schedule. The HITECH Act requires regular audits, and OCR has ran multiple rounds since the program launched in 2011. There is no set frequency for person groups, and any covered group or business associate could be selected in any audit round.

Can business associates be audited?

Yes. Phase 2 of the OCR audit program expanded to include business associates. If your group handles PHI on behalf of a covered group, you are subject to audit. This includes IT service providers, billing companies, cloud hosting providers, and any other vendor that creates, receives, maintains, or transmits PHI.

What is the difference between an OCR audit and an OCR review?

An OCR audit is a proactive, scheduled review of compliance that may be triggered by random selection or risk-based criteria. An OCR review is a reactive process triggered by a complaint, breach report, or media coverage. Investigations tend to be more adversarial and are more likely to result in enforcement action, but audit findings can also be referred for review.

How much time do we have to respond to an audit request?

groups often receive 10 business days to respond to written records requests during a desk audit. Given this tight timeline, keeping organized and accessible compliance written records is key. groups that cannot produce requested items within the allotted time face extra adverse findings.

Does passing an audit guarantee compliance?

No. An audit examines selected step areas at a specific point in time. Passing an audit means that the examined areas met rules at the time of review. Compliance is an ongoing duty that requires continuous effort, regular updates, and vigilant tracking across all HIPAA rules.

OCR Audit Takeaways

The OCR audit program represents a major compliance challenge and chance for healthcare groups. groups that invest in continuous compliance readiness, keep thorough written records, and address known gaps proactively are best positioned to navigate an audit successfully. The cost of preparation is far less than the cost of adverse findings, corrective action plans, and possible enforcement action.

One Guy Consulting helps healthcare groups build and keep audit-ready compliance programs. From running complete risk analyses to developing complete policy libraries and training programs, our team provides the expertise needed to face an OCR audit with confidence. Contact us today to assess your groupÂ’s audit readiness and strengthen your HIPAA compliance posture. Document your risk assessment gap analysis

Key stat: The OCR HIPAA Audit Program evaluates covered entities against specific protocol areas drawn from the Privacy, Security, and Breach Notification Rules. In the most recent audit cycle, Security Rule deficiencies outnumbered Privacy Rule deficiencies by a ratio of approximately 3 to 1 - indicating that technical safeguards remain the biggest compliance gap for most organizations.

Sources

Compliance Program Resources

Related: 2025 HIPAA enforcement actions · HIPAA documentation requirements