No Scroll News

OIG Report Highlights Gaps in HIPAA Audit Program

A recent HHS Office of Inspector General report reveals that the current HIPAA audit program covers only a small fraction of requirements and lacks prompt corrective actions, prompting calls for a broader and more effective audit process.
Published on April 9, 2025

The HHS Office of Inspector General released a report on November 21, 2024, that criticizes the Office for Civil Rights' current HIPAA audit program. The report reveals that only a small fraction of HIPAA requirements are being audited—assessing just 8 of 180 requirements—and that the program lacks effective corrective actions, particularly in addressing physical and technical safeguards for electronic protected health information.

The findings call for an expansion of audit scopes, the implementation of timely remediation measures, and the establishment of clear criteria for compliance reviews. Additional commentary from sources like Axios and Healthcare Innovation supports these recommendations, emphasizing the urgent need for stronger enforcement mechanisms to better protect patient data against rising cybersecurity threats.


Sources
HHS Office of Inspector GeneralAxiosHealthcare InnovationHomeland Security TodayNational Law Review