How do I do a HIPAA Audit?

Conducting internal HIPAA audits in your place of business helps to assure your establishment is HIPAA compliant. HIPAA, or the Health Insurance Portability and Accountability Act of 1996, was designed to protect consumer's privacy of their health information. The U.S. Department of Health and Human Services' Office for Civil Rights enforces the act and investigates any complaints and potential violations. Conducting an audit of your business will show areas that need improvement or where implementations of new procedures are needed.

Instructions

    • 1

      Research HIPAA by visiting the U.S. Department of Health and Human Services' website where you can read about HIPAA, enforcement of the Act, and download training materials. This will prepare you for what to look for during your audit.

    • 2

      Read your company's current written policies and procedures on privacy, personal health information such as medical records and HIPAA-related matters. Identify policies that need modification and edit these or create new policies that follow HIPAA regulations.

    • 3

      Review your computer system to audit how personal health information is accessed. Evaluate if this information is password protected and who has access to it. Meet with your information technology leadership to determine if your software is HIPAA compliant and that any exchange of health information is covered under the appropriate business agreements.

    • 4

      Complete site visits to all of your offices and facilities to assure they are HIPAA compliant. Note where files containing personal health information are kept and investigate sign-in sheets, fax machines, printers and copiers to assure there is no identifying health information exposed.

    • 5

      Complete random checks around your office to assure files are appropriately locked and only accessible to those with a need for them. Audit employee's desks, offices and stations to assure no personal health information is left in the open.

    • 6

      Review your company's internal and client's quarterly and annual reports to assure that any personal health information is de-identified and does not contain any identifiable health information.

Related Searches:

References

Comments

You May Also Like

  • Audit Logging Tools

    Snare Epilog for Windows centralizes and processes Windows text-based log files. This application also keeps track of "date-stamped" log files, such as...

  • How to Comply With HIPAA Rules

    The Health Insurance Portability and Accountability Act was implemented in 1996, during the Clinton administration. HIPAA was initially created to protect individuals...

  • HIPAA Audit Checklist

    HIPAA Audit Checklist. HIPAA is the American act that regulates the exchange of medical information between doctors, health care providers, insurance providers...

  • Desk Audit Procedures

    Desk Audit Procedures. A desk audit is an evaluation of a particular position with the civil service to determine whether duties and...

  • How to Conduct a Process Audit

    A process is simply a way of doing something. Most people have the same process for going to work in the morning....

  • How to Perform a Compliance Audit

    Compliance audits are routinely done as a comprehensive review of a company, business or organization's attention and adherence to specific statutory and...

  • HIPAA Auditing Requirements

    HIPAA Auditing Requirements. According to the U.S. Department of Health and Human Services (HHS), the Health Insurance Portability and Accountability Act (HIPAA)...

  • Internal Audit Checklist for HIPAA

    In 1996, the U.S. Congress passed the Health Insurance Portability and Accountability Act, or HIPAA, to regulate how health care institutions disclose...

  • How to Do an Audit Report

    Companies use audits of their financial performance to identify which of their strategies is driving growth. The audits are prepared by accountants...

Related Ads

Featured