Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Freedom 250 banner logo Join HHS in Celebrating Freedom 250
    • About HHS

      HHS is a U.S. executive department that touches the lives of nearly all Americans by protecting your rights, research, food safety, health care, aging, and much more.

      Explore About HHS
    • About the Department
      • Leadership
      • HHS Divisions
      • Organizational Chart
      • Priorities
      • Budget in Brief
      • Contact Us
    • Press Room
      • Press Releases
      • Request for Comment
      • Request for Interview
      • Connect on Social Media
      • HHS Live
      • Podcasts
    • Careers
      • Working at HHS
      • Opportunities for Attorneys
      • Join the Health Workforce
      • I am HHS
      • New Employee Orientation
      • Transportation Services
    • Standards and Compliance
      • Gold Standard Science
      • Accessibility
      • Plain Writing
      • Digital Communications Standards
      • Records Management
    • Accountability and Transparency
      • Freedom of Information Act (FOIA)
      • Open Government
      • No Fear Act
      • Privacy at HHS
  • RealFood.gov
  • MAHA
    • Programs & Services

      HHS is responsible for public health, health care, and human/social services for the United States of America. This includes administering over 100 programs and services.

      Explore Programs & Services
    • Health Care
      • Find a Health Center
      • Find an Indian Health Service Facility
      • Find Support for Mental Health, Drugs, or Alcohol
      • Find a Cancer Center
      • Dental Care Options
      • Telehealth
    • Health Insurance
      • Medicare – 65+ or With Disability
      • Medicaid - Low-Income, With Disability, or Pregnant
      • Children’s Health Insurance Programs (CHIP)
      • Find Health Insurance Coverage
      • Insurance Help for Mental Health and Substance Use
      • No Surprise Medicals Bills
    • Social Services
      • Programs for Children and Families
      • Programs for People with Disabilities
      • Programs for Older Adults
      • Resources for Caregivers
    • Public Health and Prevention
      • Emergency Preparedness and Response
      • Healthy Lifestyle
      • Mental Health and Substance Use
      • Food Safety and Nutrition
      • Drug and Product Safety
    • Health Research and Information
      • National Library of Medicine
      • Surgeon General Reports
      • Health Data
      • National Center for Health Statistics
      • Medline Plus
      • Clinical Research Studies
      • Volunteering to Participate in Research
    • Laws & Regulations

      HHS protects and helps you understand the laws and regulations, also known as "rules," that govern the nation. You also have the power to voice your opinion on these laws and regulations.

      Explore Laws & Regulations
    • Regulatory Information
      • What is a Rule?
      • Find Rules by Division
      • Comment on Open Rules
      • Suggest Deregulatory Actions
      • Understand Key Federal Laws
    • Civil Rights
      • Your Civil Rights
      • Civil Rights Laws Enforced by HHS
      • Health Information Privacy
      • Substance Use Disorder Patient Confidentiality
      • Conscience and Religious Freedom
    • Laws and Regulations by Topic
      • HIPAA Privacy Rule
      • Health Insurance Protections
      • Health IT Legislation
      • Food and Drug Safety
      • Public Health Emergencies
    • Human Research Protections
      • The Belmont Report
      • Regulations, Policy, and Guidance
      • Human Subjects Regulations (45 CFR 46)
      • Register IRBs and Obtain FWAs
      • Trainings, Tutorials, and Workshops
      • International Research
    • Complaints and Appeals
      • File a Medicare Complaint
      • File a HIPAA Complaint
      • File a Civil Rights Complaint
      • Appeal an Insurance Company Decision
      • Report Fraud, Waste, and Abuse to OIG
      • Report a Problem to the FDA
      • Report a Tip on the Chemical and Surgical Mutilation of Children
    • Grants & Contracts

      HHS gives the most money in grants of any federal agency in the U.S. Find out about our grants and how your organization can apply for them. We also provide information on how you can work with us and our support of small businesses.

      Explore Grants & Contracts
    • Grants
      • Get Ready for Grants Management
      • Grant Policies and Regulations
      • Research Grants and Funding from NIH
      • Search Grants.gov
      • Avoid Grant Scams
      • Contact HHS Grant Officials
    • Contracts
      • Get Ready to Do Business with HHS
      • Programs for Businesses
      • Contract Policies and Regulations
      • Search Opportunities on SAM.gov
      • Contact HHS Contracting Managers
    • Small Business
      • Contract Opportunities
      • Small Business Programs
      • Small Business Resources
      • Contact Small Business Staff
    • Radical Transparency

      HHS protects and helps you understand the laws and regulations, also known as "rules," that govern the nation. You also have the power to voice your opinion on these laws and regulations.

      Explore Radical Transparency
    • CDC’s ACIP Conflicts of Interest
    • Ending Anti-Semitism on College Campuses
    • Ending Wasteful Spending
    • Keeping Food Ingredients Safe
    • Chemical Contaminants Transparency Tool
  • HIPAA for Individuals
  • Filing a Complaint
  • HIPAA for Professionals
  • Newsroom
Breadcrumb
  1. HHS
  2. HIPAA Home
  3. For Professionals
  4. HIPAA Compliance and Enforcement
  5. OCR's HIPAA Audit Program
  • HIPAA for Professionals
  • Regulatory Initiatives
  • Privacy
    • Summary of the Privacy Rule
    • Guidance
    • Combined Text of All Rules
    • HIPAA Related Links
  • Security
    • Security Rule NPRM
    • Summary of the Security Rule
    • Security Guidance
    • Cyber Security Guidance
  • Breach Notification
    • Breach Reporting
    • Guidance
    • Reports to Congress
    • Regulation History
  • Compliance & Enforcement
    • Enforcement Rule
    • Enforcement Process
    • Enforcement Data
    • Resolution Agreements
    • Case Examples
    • Audit
    • Reports to Congress
    • State Attorneys General
  • Special Topics
    • Parental Access
    • Mental and Behavioral Health
    • Change Healthcare Cybersecurity Incident FAQs
    • HIPAA and COVID-19
    • HIPAA and Reproductive Health
      • HIPAA and Final Rule Notice
    • HIPAA and Telehealth
    • HIPAA and FERPA
    • Research
    • Public Health
    • Emergency Response
    • Health Information Technology
    • Health Apps
  • Patient Safety
  • Covered Entities & Business Associates
    • Business Associate Contracts
    • Business Associates
  • Training & Resources
  • FAQs for Professionals
  • Other Administrative Simplification Rules
  • Substance Use Disorder Confidentiality

OCR's HIPAA Audit Program

The Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH) requires HHS to periodically audit covered entities and business associates for their compliance with the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules.

The HHS Office for Civil Rights (OCR)'s HIPAA Audit Program is an important part of OCR’s overall health information privacy, security, and breach notification compliance activities. OCR uses the audit program to assess the HIPAA compliance efforts of a range of entities covered by HIPAA regulations. The audits present an opportunity to examine mechanisms for compliance, identify best practices, discover risks and vulnerabilities that may not have come to light through OCR’s ongoing complaint investigations and compliance reviews, and enable us to get out in front of problems before they result in breaches. OCR will broadly identify best practices gleaned through the audit process and will provide guidance targeted to identified compliance challenges.

On this page:

  • 2024-2025 HIPAA Audits Initiated
  • HIPAA Audit Participant Survey Information
  • 2016 – 2017 HIPAA Audits Industry Report
  • HIPAA Audit Program Protocol

2024-2025 HIPAA Audits Initiated

OCR has initiated it’s 2024-2025 HIPAA Audits. Ransomware, destructive malware, and other forms of malicious hacking present a growing and ongoing threat to the U.S. health care and public health sector and the privacy and security of electronic protected health information. In recent years, HIPAA covered entities (health plans, health care clearinghouses, and most health care providers) and business associates have experienced significant cyberattacks, which have impacted hospital operations, patient care, access to patient records and have had massive financial ramifications. Substantial increases in large breaches involving hacking and ransomware reported to OCR and the number of individuals affected by large breaches demonstrates the need for HIPAA covered entities and their business associates to ensure that they are complying with the HIPAA Security Rule.

The 2024-2025 HIPAA Audits will review 50 covered entities’ and business associates’ compliance with selected provisions of the HIPAA Security Rule most relevant to hacking and ransomware attacks. These Audits will give OCR an opportunity to examine mechanisms for compliance, identify promising practices for protecting the privacy and security of health information, and discover risks and vulnerabilities that may not have been revealed by OCR’s enforcement activities. The Audits will benefit the selected covered entities and business associates by providing them with OCR’s assessment of their Security Rule compliance in the selected provisions and information on how to improve their cybersecurity of electronic protected health information.

OCR will publish an industry report summarizing OCR’s findings after the 2024-2025 HIPAA Audits are completed.

HIPAA Audit Survey to be sent to 2016-2017 HIPAA Audit participants

OCR is issuing an electronic “HIPAA Audit Participant Survey” to the HIPAA covered entities and business associates that participated in the 2016-2017 HIPAA Audits. The survey seeks information to evaluate the effectiveness of the 2016-2017 HIPAA Audits and identify areas of improvement for OCR’s HIPAA Audit Program, as recommended by the Government Accountability Office. This information collection request was published in the federal register on February 12, 2024, and June 3, 2024.

The survey consists of 41 questions and will assist OCR in gathering information relating to the effect of the 2016-2017 HIPAA Audits on the audited entities and the entities' opinions about the Audit process including:

  • Measuring the effect of the 2016-2017 HIPAA Audits on covered entities' and business associates' subsequent actions to comply with the HIPAA Rules;
  • Providing entities with an opportunity to give feedback on the 2016-2017 HIPAA Audits, such as the helpfulness of HHS' guidance materials and communications, the utility of the online submission portal, whether the Audit helped improve entity compliance, and the entities' responses to the Audit findings and recommendations;
  • Providing OCR with information on the burden imposed on entities to collect Audit-related documents and to respond to Audit-related requests; and
  • Seeking feedback on the effect of the 2016-2017 HIPAA Audits on the entities' day-to-day business operations.

The information, opinions, and comments collected using the online survey will be used to improve OCR’s HIPAA Audit Program. The responses received will not be used by OCR in connection with any enforcement activities. The survey will close sixty (60) days from receipt of the survey.

2016-2017 HIPAA Audits Industry Report on health care industry compliance with the HIPAA rules

OCR released its 2016-2017 HIPAA Audits Industry Report that reviewed selected health care entities and business associates for compliance with certain provisions of the HIPAA Privacy, Security, and Breach Notification Rules.

OCR conducted audits of 166 covered entities and 41 business associates and notified these organizations of OCR’s findings.  OCR published this Industry Report to share the overall findings on compliance with the audited provisions of the HIPAA Rules.

  • 2016-2017 HIPAA Audits Industry Report
  • Press Release

Audit Program Protocol

OCR’s HIPAA Audit Program uses a comprehensive audit protocol to review covered entities' and business associates' compliance with the HIPAA Privacy, Security, and Breach Notification Rules.

Read the full Audit Program Protocol.

Content last reviewed December 31, 2024
Back to top
Secretary Robert F. Kennedy Jr.

Follow @SecKennedy

HHS icon

Follow @HHSGov

HHS Email updates

Receive email updates from HHS.

Subscribe

HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​

  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • Press Room
  • HHS Archive
  • Accessibility Statement
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy