<img height="1" width="1" style="display:none;" alt="" src="https://dc.ads.linkedin.com/collect/?pid=118459&amp;fmt=gif">
Show all

HIPAA Audit Program Resumes

audit icons on city background

1 minute read

The U.S. Department of Health and Human Services (HHS) has updated its HIPAA enforcement website to announce the start of the 2024-25 HIPAA audit program. The program has been dormant since 2016-17 due to funding issues.

The 2024-25 HIPAA audits will review 50 covered entities, focusing on compliance with key Security Rule provisions to combat hacking and ransomware. HIPAA audits focus on compliance improvement, but serious issues may lead to a compliance review.

 

HIPAA Security Rule

The HIPAA Security Rule mandates the protection of electronic protected health information (ePHI) by requiring covered entities to assess risks and implement safeguards to ensure confidentiality, integrity, and availability.

 

HIPAA Audit Program

HHS must regularly audit entities for HIPAA compliance. The last audits were in 2016-17, covering 166 entities and 41 associates.

A November 25, 2024, report by HHS’ Office of Inspector General (OIG) found the HIPAA audit program ineffective in boosting cybersecurity at regulated entities. OIG suggested expanding their audit scope to better assess compliance with Security Rule safeguards.

In December 2024, it was announced that HIPAA audits would resume, focusing on cybersecurity-related compliance. An industry report will summarize the 2024-25 HIPAA audits once they are completed.

Employers with health plans accessing ePHI should regularly check HIPAA Security Rule compliance, ensuring their risk analysis is current and safeguards are in place. Download the bulletin for more details.

New call-to-action

National Insurance Services is not a law firm and no opinion, suggestion, or recommendation of the firm or its employees shall constitute legal advice. Readers are advised to consult with their own attorney for a determination of their legal rights, responsibilities and liabilities, including the interpretation of any statute or regulation, or its application to the readers’ business activities.

large letters that spell out FAQ
FAQs Provide New Guidance on Gag Clause Attestation Requirement
January 24, 2025
Family Medical Leave Act Speech Bubble Note
Opinion Letter Issued Regarding FMLA and State PFML Programs
January 24, 2025
Nicole Miller

Nicole Miller

When it comes to employee benefits, Nicole Miller is a good person to have on your side. She’s worked in the insurance industry since 2004 and has experience working on both the insurance carrier/agency side. Her customers find her to be dependable, detail-oriented, and highly skilled at simplifying the complex. As an Account Manager, Nicole works with Michigan public sector organizations on their employee benefits, benefit communication, and wellness plans. She helps employees and employers answer policy-related questions, resolve employee claim issues with carriers, and assists with employee or insurance committee meetings.