Back to BlogHIPAA Updates

How to prepare for a HIPAA OCR Audit.

August 25, 2026
Darren Speed, MS, CHC
How to prepare for a HIPAA OCR Audit.

What will OCR request in a HIPAA audit?

OCR audits are document-driven. While requests vary by entity type and audit scope, covered entities and business associates should expect OCR to ask for core compliance materials tied to the HIPAA Rules in 45 CFR Parts 160 and 164.

  • Enterprise-wide risk analysis and related risk management documentation under 45 CFR 164.308(a)(1)(ii)(A)-(B).
  • Written HIPAA policies and procedures required by 45 CFR 164.316(a) and retained under 45 CFR 164.316(b).
  • Workforce training records under 45 CFR 164.530(b) for Privacy Rule training, and evidence of Security Rule awareness and training under 45 CFR 164.308(a)(5).
  • Business associate agreements and vendor oversight documentation required by 45 CFR 164.308(b), 164.314(a), and 164.502(e).
  • Notice of Privacy Practices and acknowledgment process, where applicable, under 45 CFR 164.520.
  • Patient rights procedures for access, amendment, restrictions, confidential communications, and accounting of disclosures under 45 CFR 164.522, 164.524, 164.526, and 164.528.
  • Administrative, physical, and technical safeguard documentation under the Security Rule, including access controls, audit controls, contingency planning, workstation safeguards, and device/media controls in 45 CFR 164.308, 164.310, and 164.312.
  • Breach response policies and incident documentation under the Breach Notification Rule at 45 CFR 164.400-414.
  • Sanction policy and evidence of enforcement under 45 CFR 164.308(a)(1)(ii)(C) and 164.530(e).
  • Complaint process and complaint records under 45 CFR 164.530(d) and documentation retention requirements.

Why is documentation so important in an OCR audit?

OCR evaluates whether the organization can demonstrate compliance, not whether it believes it is compliant. HIPAA expressly requires documentation of policies and procedures, and retention of required documentation for six years from the date of creation or the date last in effect, whichever is later. That requirement appears in 45 CFR 164.316(b)(2) for Security Rule documentation and 45 CFR 164.530(j)(2) for Privacy Rule documentation.

If a policy exists only in practice, or if a risk analysis was discussed but never finalized, OCR may treat that as noncompliance. In prior OCR enforcement activity, failure to conduct an accurate and thorough risk analysis has been a recurring issue because it is a foundational Security Rule requirement.

How should an organization prepare before an audit notice arrives?

1. Maintain a current, enterprise-wide risk analysis

The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). See 45 CFR 164.308(a)(1)(ii)(A). OCR expects this analysis to be organization-wide, not limited to a single application or department.

Your risk analysis should identify where ePHI is created, received, maintained, or transmitted, including cloud systems, EHRs, billing systems, email, mobile devices, backups, and third-party platforms. It should be reviewed and updated as operations, systems, or threats change.

2. Document risk management activities

Risk analysis alone is not enough. Under 45 CFR 164.308(a)(1)(ii)(B), organizations must implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Keep a written risk management plan showing assigned responsibility, mitigation steps, target dates, and status updates.

3. Review policies and procedures for accuracy

HIPAA requires reasonable and appropriate written policies and procedures. See 45 CFR 164.316(a) and 45 CFR 164.530(i). Audit preparation should include confirming that policies match actual operations. OCR will often compare written policy language to how the workforce actually handles access requests, minimum necessary decisions, security incidents, and vendor onboarding.

4. Organize training and sanction records

Covered entities must train workforce members on Privacy Rule policies and procedures as necessary and appropriate for them to carry out their functions. See 45 CFR 164.530(b). The Security Rule also requires a security awareness and training program at 45 CFR 164.308(a)(5). Keep rosters, dates, training materials, attestations, and records of remedial training or sanctions.

5. Verify business associate compliance documentation

Before disclosing PHI to a business associate, a covered entity generally must obtain satisfactory assurances through a compliant contract or other arrangement. See 45 CFR 164.502(e) and 164.504(e). Business associates also have direct compliance obligations under the Security Rule and certain Privacy and Breach Notification Rule provisions. Maintain an inventory of vendors, signed agreements, services performed, and any security review notes.

What should be in your OCR audit response file?

A practical approach is to keep a centralized audit file or compliance repository so records can be produced quickly. OCR audit requests may have short turnaround times, so delay caused by disorganized files creates unnecessary risk.

  • Current HIPAA policies and procedures with approval dates and revision history.
  • Six years of retained documentation where applicable.
  • Most recent risk analysis and risk management plan.
  • Asset inventory or data flow mapping showing where PHI and ePHI reside.
  • Training logs, attendance records, and training content.
  • Incident response and breach notification policies, plus incident logs.
  • Business associate inventory and executed agreements.
  • Patient rights request logs for access, amendments, restrictions, and accountings.
  • Technical safeguard evidence such as access control standards, audit logging practices, encryption decisions, and contingency planning records.
  • Complaint records, sanctions, and internal investigation files.

How quickly must you respond to OCR?

The timeline depends on the specific OCR request. In audits and investigations, OCR commonly sets a firm due date in its written correspondence. The important point is that HIPAA requires documentation to exist already; organizations should not rely on being able to create policies or reconstruct records after receiving notice.

If more time is needed, the organization should communicate promptly, respectfully, and in writing, but extensions are discretionary. A late or incomplete response can undermine credibility and may expand OCR scrutiny.

What are common weaknesses OCR looks for?

  • Outdated or missing risk analysis.
  • Policies that do not reflect actual practices.
  • No evidence of workforce training or sanctions.
  • Missing or unsigned business associate agreements.
  • Inadequate access request procedures, especially failure to meet the Privacy Rule timelines in 45 CFR 164.524.
  • Poor breach assessment documentation under 45 CFR 164.402 and notification procedures under 45 CFR 164.404-410.
  • Failure to retain required documentation for six years.

HIPAA OCR audit preparation Q&A

Do covered entities and business associates both get audited?

Yes. OCR has authority to audit both covered entities and business associates for compliance with applicable HIPAA requirements. The statutory audit authority comes from the HITECH Act, and OCR uses that authority to review compliance with the Privacy, Security, and Breach Notification Rules.

Does HIPAA require a specific risk analysis format?

No. HIPAA is flexible and does not mandate a single form or methodology. However, 45 CFR 164.308(a)(1)(ii)(A) requires the analysis to be accurate and thorough, and OCR expects it to cover all relevant systems, locations, and workflows involving ePHI.

How long must HIPAA documentation be kept?

Generally, six years. Security Rule documentation must be retained for six years under 45 CFR 164.316(b)(2)(i), and Privacy Rule documentation must be retained for six years under 45 CFR 164.530(j)(2).

What is the deadline for responding to a patient access request?

Under 45 CFR 164.524(b)(2), a covered entity generally must act on a request for access no later than 30 days after receipt. One 30-day extension is permitted if the entity provides the individual a written statement of the reasons for delay and the date by which it will complete the action.

When must breach notifications be sent?

For breaches of unsecured PHI, covered entities must provide notice to affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery. See 45 CFR 164.404(b). Notice to HHS timing depends on the number of affected individuals, under 45 CFR 164.408.

What is the best way to stay audit-ready year-round?

The most effective method is to treat HIPAA compliance as an ongoing governance process rather than a binder on a shelf. Assign responsibility, schedule regular policy review, update the risk analysis when systems or workflows change, test incident response, and periodically verify that documentation can be produced quickly. Audit readiness improves when compliance records are centralized, current, and tied to day-to-day operations.

In short, preparing for a HIPAA OCR audit means being ready to prove compliance with current documentation, not merely describe it. Organizations that maintain accurate risk analysis, current policies, training records, vendor documentation, and breach procedures are in a far stronger position if OCR asks questions.

#HIPAA#Privacy#Regulatory#Security#Healthcare

Frequently Asked Questions

What documents does OCR usually request in a HIPAA audit?

OCR commonly requests the organization’s risk analysis, risk management plan, HIPAA policies and procedures, training records, business associate agreements, breach response documentation, and records related to patient rights and complaints.

How long must HIPAA compliance documents be retained?

HIPAA generally requires documentation to be retained for six years from the date it was created or the date it was last in effect, whichever is later.

Does HIPAA require a specific risk analysis template?

No. HIPAA does not require a specific template, but the risk analysis must be accurate, thorough, and cover all systems and locations where ePHI is created, received, maintained, or transmitted.

How fast must a covered entity respond to a patient access request?

A covered entity generally must act on a request for access within 30 days of receipt, with one additional 30-day extension allowed if the individual is notified in writing.

What is a common reason organizations struggle in OCR audits?

A frequent problem is missing or outdated documentation, especially an incomplete enterprise-wide risk analysis, unsigned business associate agreements, or policies that do not match actual operations.

Ready to Strengthen Your Compliance Program?

Schedule a free consultation with our compliance experts and discover how we can help protect your healthcare organization.