HIPAA · Common question
What triggers a HIPAA audit?
Short answer
OCR audits are not random. The four main triggers are: (1) a patient or employee complaint, (2) a breach report of 500+ affected individuals, (3) media coverage of a suspected violation, and (4) referral from another federal agency. Most audits stem from complaints.
The Office for Civil Rights (OCR) — which enforces HIPAA — investigates around 25,000 complaints per year, and its formal audits are almost never random. The top four triggers, in order of volume:
1) A patient complaint. This is by far the most common trigger. A single patient filing a complaint about record access, disclosure, or handling can open an OCR investigation. Employees are the second most-common complainants.
2) A breach report affecting 500+ individuals. HIPAA's Breach Notification Rule requires reporting these breaches to OCR within 60 days, and they are automatically added to the public HHS 'Wall of Shame'. OCR investigates almost every one.
3) Media coverage. OCR monitors news stories about healthcare data exposure. A local news story about a laptop stolen from a clinic can trigger a call.
4) Cross-agency referrals. FTC, state attorneys general, and CMS routinely refer HIPAA-adjacent matters to OCR.
The single best defense against enforcement is a documented, current risk analysis and evidence that safeguards were operating at the time of any incident. OCR settlements repeatedly cite 'no risk analysis in the last 12 months' as an aggravating factor.
Related
Still have questions?
Book a 20-minute walkthrough.
