The American Recovery and Reinvestment Act of 2009 (ARRA), in Section 13411 of the Health Information Technology for Economic and Clinical Health Act (HITECH), requires the U.S. Health and Human Services (HHS) to provide for periodic audits to ensure covered entities and business associates are complying with the HIPAA Privacy and Security Rules and Breach Notification standards. To implement this mandate, the Office for Civil Rights (OCR) piloted a program to perform 115 audits of covered entities to assess privacy and security compliance. Audits conducted during the pilot phase began in November 2011 and will conclude in December 2012.
Recent Posts
- How to Deny PTO Requests Fairly—Without Hurting Morale or Violating the Law
- Is Earned Wage Access Right for Your Business? 5 Questions to Ask
- Is It Time to Leave Your PEO? When Growing SMBs Should Switch to an HCM/ASO Model
- Why Payroll Tax Reconciliation Should Be a Year-Round Effort
- The Aftermath of HR Misconduct—And Why an Outside Expert Can Help