
{"id":2143,"date":"2012-11-16T00:00:00","date_gmt":"2012-11-16T00:00:00","guid":{"rendered":"http:\/\/otava.test\/the-hipaa-police-are-on-their-way-2\/"},"modified":"2012-11-16T00:00:00","modified_gmt":"2012-11-16T00:00:00","slug":"the-hipaa-police-are-on-their-way-2","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/","title":{"rendered":"The HIPAA Police Are On Their Way!"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft\" title=\"Mike Klein\" src=\"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg\" alt=\"Mike Klein\" width=\"120\" height=\"160\" \/>One of the lesser known requirements of the <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#Health Information Technology for Economic and Clinical Health\">Health Information Technology for Economic and Clinical Health (HITECH) Act<\/a> requires the U.S. Department of Health and Human Services (HHS) to conduct periodic audits to ensure that healthcare organizations and their business associates are complying with <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#Healthcare Insurance\">HIPAA laws<\/a>.<\/p>\n<p>Running from November 2011 to December 2012, the HHS Office for Civil Rights (OCR) launched a pilot program by selecting 115 organizations across the country to undergo the scrutiny of privacy, security and breach notification audits conducted by KPMG, one of the largest auditor organizations in the world.<\/p>\n<p>The OCR does not plan to penalize targets for pilots unless they uncover \u201cserious compliance issues.\u201d The HITECH Act has civil penalties for <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/what-is-a-hipaa-violation\">HIPAA violations<\/a> that can reach $50,000 per violation and up to $1.5 million for identical violations across multiple records in a single calendar year. As the OCR audit program moves from pilot to a fully enforced program in 2013, the number of surprise audits and fines are expected to skyrocket.<\/p>\n<p>In June 2012, the OCR released a copy of the protocol it is using to audit organizations against <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">HIPAA compliance<\/a> in their pilot program. The protocol provides a breakdown of specific audit criteria they are currently using for the latest HIPAA audits. The protocol includes 169 specific performance criteria organized around compliance in three areas: the HIPAA Privacy Rule, Security Rule and Breach Notification Rule.<\/p>\n<figure id=\"attachment_8807\" aria-describedby=\"caption-attachment-8807\" style=\"width: 594px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-8807 \" title=\"OCR HIPAA Audit Protocol\" src=\"\/wp-content\/uploads\/OCR-HIPAA-Audit-Protocol1.png\" alt=\"OCR HIPAA Audit Protocol\" width=\"594\" height=\"536\" \/><figcaption id=\"caption-attachment-8807\" class=\"wp-caption-text\">OCR HIPAA Audit Protocol (Source: HHS.gov)<\/figcaption><\/figure>\n<p>The initial audit is targeted toward <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#Covered Entities\">covered entities<\/a> (such as healthcare providers, health plans, and healthcare clearinghouses) during the 2012 pilot program. Business associates such as <a href=\"https:\/\/otavawebsite.wpengine.com\/\">data center operators<\/a> and <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/\">cloud computing<\/a> providers were not included in the pilot program, but are expected to be included in audits starting next year.<\/p>\n<p>Data center operators and cloud providers that host <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#Electronic Protected Health Information\">Electronic Protected Health Information (ePHI)<\/a> in their data centers are considered <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">business associates<\/a> under HIPAA law. As such, any company hosting ePHI can be subject to future audits and potential seven-figure fines by the OCR.<\/p>\n<p>Multi-tenant data center and cloud operators must protect themselves and their healthcare clients from violating HIPAA laws. Most healthcare providers and health IT companies require HIPAA compliance from their hosting provider.<\/p>\n<p>HIPAA compliance is no small investment. Data center operators must not only deliver the technology to meet the administrative, physical and technical safeguards required by the <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#Security Rule\">HIPAA security rule<\/a>, they must also invest in <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/administrative-security\/policies\">policies<\/a>, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">training<\/a>, breach notification processes, legal support for business associates agreements, and HIPAA breach insurance.\u00a0 In addition, the organization must commit to consistently monitoring the safeguards and processes to ensure the security of ePHI.<\/p>\n<p>One of the best assurances healthcare clients can get that the appropriate technology, processes and policies are in place is by reviewing the data center\u2019s annual <a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/100-hipaa-compliant\">HIPAA audit report on compliance<\/a>. The HIPAA audit should be conducted by a reputable third-party auditor and cover all 169 requirements of the HIPAA law.<\/p>\n<p>Up through early 2012, there was no standard for third-party auditors to conduct a HIPAA audit. There have been a number of audit approaches used to help ensure compliance with the HIPAA laws. With the publication of the new OCR audit program protocol auditors are able to gain a more consistent direction on how the OCR will conduct HIPAA audits in the future. The new protocol should guide independent auditors to adjust their auditing standards against the federal governing body of HIPAA.<\/p>\n<p>While no one enjoys the threat of a government-sponsored audit program, and even worse, the possibility of multi-million dollar fines, the U.S. government is demonstrating that they are taking HIPAA law enforcement seriously \u2013 and so should data center operators, as well as the healthcare organizations that use the services of data center operators.<\/p>\n<p>Since healthcare clients are facing multi-million dollar fines for violations of HIPAA law by their business associates, these companies are requiring <a href=\"https:\/\/otavawebsite.wpengine.com\/operations\/locations\/michigan-cloud-and-data-centers\/\">data centers<\/a> and cloud providers to provide an annual third-party independent HIPAA report on compliance.<\/p>\n<p>With audit guidance in place from the OCR, it won\u2019t be long before the healthcare industry raises the bar on third-party audit requirements to include adherence to the new OCR HIPAA Audit Program Protocol.<\/p>\n<p>View the complete OCR HIPAA Audit Protocol program, including all 169 criteria and respective audit procedures at <a href=\"https:\/\/www.hhs.gov\/ocr\/privacy\/hipaa\/enforcement\/audit\/protocol.html\">HHS.gov<\/a>.<\/p>\n<p><em>This article was published in DataCenterKnowledge.com&#8217;s <a href=\"https:\/\/www.datacenterknowledge.com\/archives\/2012\/11\/15\/the-hipaa-police-are-on-their-way\/?utm-source=feedburner&amp;utm-medium=feed&amp;utm-campaign=Feed%3A+DataCenterKnowledge+%28Data+Center+Knowledge%29\">Industry Perspectives<\/a> column on November 15, 2012.<\/em><\/p>\n<p>Related Links:<br \/>\n<em><strong><a href=\"https:\/\/onlinetech.com\/resources\/e-tips\/hipaa-compliance\/five-questions-to-ask-your-hipaa-hosting-provider\">Five Questions to Ask Your HIPAA Hosting Provider<\/a><\/strong><\/em><br \/>\n<em><strong> <a href=\"https:\/\/onlinetech.com\/resources\/e-tips\/hipaa-compliance\/ocr-audit-requirements-following-a-self-reported-hipaa-breach\">OCR Audit Requirements Following a Self-Reported HIPAA Breach<\/a><\/strong><\/em><br \/>\n<em><strong><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance\/\">2011-2012 HIPAA Audits Have Begun: Are You Ready to Prove HIPAA Compliance?<\/a><\/strong><\/em><br \/>\n<em><strong><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/2011-hipaa-violations-and-audits\/\">2011 HIPAA Violations and Audits<\/a><\/strong><\/em><br \/>\n<em><strong><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/2012-hipaa-violations-and-audits\/\">2012 HIPAA Violations and Audits<\/a><\/strong><\/em><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Upcoming_Webinar_Applying_OCR_Audit_Standards_to_HIPAA_Risk_Assessments\"><\/span>Upcoming Webinar: Applying OCR Audit Standards to HIPAA Risk Assessments<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft\" title=\"David Barton\" src=\"https:\/\/www.uhyadvisors-us.com\/respics\/DavidBarton.jpg\" alt=\"David Barton\" width=\"73\" height=\"96\" \/>Learn more about how the new OCR Audit standards apply to HIPAA risk assessments against the standards and safeguards of the HIPAA Security Act.<\/p>\n<p>Sign up for a <a href=\"https:\/\/www.onlinetech.com\/events\/applying-ocr-audit-standards-to-hipaa-risk-assessments\">free webinar<\/a> with David Barton, CRISC, Principal of UHY Advisors on Tuesday, November 20 @2 P.M. ET.<\/p>\n<hr \/>\n<p><a href=\"https:\/\/www.onlinetech.com\/resources\/white-papers\/hipaa-compliant-data-centers\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft\" src=\"\/wp-content\/uploads\/hipaa-white-paper.gif\" alt=\"HIPAA Compliant Data Centers\" width=\"150\" height=\"110\" \/><\/a>Learn about the specific HIPAA requirements for HIPAA hosting with IT vendors with our\u00a0<a href=\"https:\/\/www.onlinetech.com\/resources\/white-papers\/hipaa-compliant-data-centers\">HIPAA Compliant Hosting white paper<\/a>. With 36 pages of statistics, diagrams and researched information sourced from engineers and a CHSS (Certified HIPAA Security Specialist), this white paper is your complete guide to HIPAA hosting.<\/p>\n<p>Still have questions?\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/contact\/\">Contact<\/a>\u00a0us or\u00a0<a href=\"https:\/\/hostedusa6.whoson.com\/chat\/chatstart.htm?domain=www.onlinetech.com\">chat\u00a0<\/a>now. Learn more about our\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">HIPAA hosting solutions<\/a>, including\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/\">cloud<\/a>,\u00a0<a href=\"https:\/\/www.onlinetech.com\/colocation\/overview\">colocation<\/a>,\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/private-cloud\/\">managed servers<\/a>\u00a0and\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/data-protection\/disaster-recovery-as-a-service\">disaster recovery<\/a>, or\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">submit a quote request<\/a>\u00a0today.<\/p>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>One of the lesser known requirements of the Health Information Technology for Economic and Clinical Health (HITECH) Act requires the U.S. Department of Health and Human Services (HHS) to conduct periodic audits to ensure that healthcare organizations and their business associates are complying with HIPAA laws. Running from November 2011 to December 2012, the HHS Office for Civil Rights (OCR) launched a pilot program by selecting 115 organizations across the country to undergo the scrutiny of privacy, security and breach notification audits conducted by KPMG, one of the largest auditor organizations in the world. The OCR does not plan to penalize targets for pilots unless they uncover \u201cserious compliance issues.\u201d The HITECH Act has civil penalties for HIPAA violations that can reach $50,000 per violation and up to $1.5 million for identical violations across multiple records in a single calendar year. As the OCR audit program moves from pilot to a fully enforced program in 2013, the number of surprise audits and fines are expected to skyrocket. In June 2012, the OCR released a copy of the protocol it is using to audit organizations against HIPAA compliance in their pilot program. The protocol provides a breakdown of specific audit criteria&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-2143","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The HIPAA Police Are On Their Way! | OTAVA<\/title>\n<meta name=\"description\" content=\"HIPAA requires covered entities and business associates to conduct regular HIPAA audits. Do you have you what you need to meet HIPAA compliance?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The HIPAA Police Are On Their Way!\" \/>\n<meta property=\"og:description\" content=\"HIPAA requires covered entities and business associates to conduct regular HIPAA audits. Do you have you what you need to meet HIPAA compliance?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2012-11-16T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"The HIPAA Police Are On Their Way!\",\"datePublished\":\"2012-11-16T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\"},\"wordCount\":894,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\",\"url\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\",\"name\":\"The HIPAA Police Are On Their Way! | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg\",\"datePublished\":\"2012-11-16T00:00:00+00:00\",\"description\":\"HIPAA requires covered entities and business associates to conduct regular HIPAA audits. Do you have you what you need to meet HIPAA compliance?\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage\",\"url\":\"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg\",\"contentUrl\":\"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The HIPAA Police Are On Their Way!\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The HIPAA Police Are On Their Way! | OTAVA","description":"HIPAA requires covered entities and business associates to conduct regular HIPAA audits. Do you have you what you need to meet HIPAA compliance?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/","og_locale":"en_US","og_type":"article","og_title":"The HIPAA Police Are On Their Way!","og_description":"HIPAA requires covered entities and business associates to conduct regular HIPAA audits. Do you have you what you need to meet HIPAA compliance?","og_url":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/","og_site_name":"OTAVA","article_published_time":"2012-11-16T00:00:00+00:00","og_image":[{"url":"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg","type":"","width":"","height":""}],"author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"The HIPAA Police Are On Their Way!","datePublished":"2012-11-16T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/"},"wordCount":894,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"image":{"@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage"},"thumbnailUrl":"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg","inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/","url":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/","name":"The HIPAA Police Are On Their Way! | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage"},"image":{"@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage"},"thumbnailUrl":"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg","datePublished":"2012-11-16T00:00:00+00:00","description":"HIPAA requires covered entities and business associates to conduct regular HIPAA audits. Do you have you what you need to meet HIPAA compliance?","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#primaryimage","url":"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg","contentUrl":"https:\/\/otavawebsite.wpengine.com\/wp-content\/uploads\/images\/stories\/people\/mike-klein-150.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/the-hipaa-police-are-on-their-way-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"The HIPAA Police Are On Their Way!"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=2143"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2143\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=2143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=2143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=2143"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=2143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}