Checklist: Documents HHS OCR Commonly Requests in a Random HIPAA Compliance Review
A surprise HIPAA review can arrive with little warning. Use this checklist to assemble the documents HHS’s Office for Civil Rights (OCR) most often requests so you can demonstrate HIPAA Privacy Rule Compliance and strong Security Rule practices without delay.
The goal is rapid production of clear, current evidence. Gather finalized policies, traceable records, and objective artifacts that show your controls are implemented, monitored, and improved.
Policies and Procedures Documentation
What OCR typically asks for
- Complete, current policy set covering Privacy, Security, and Breach Notification rules, including minimum necessary, authorizations, sanctions, complaint handling, and individual rights.
- Administrative, physical, and technical safeguards (access controls, authentication, encryption, device/media controls, facility security, transmission security).
- Operational procedures for identity and access management, change management, contingency/backup, disaster recovery, and vendor/third-party oversight.
- Document control evidence: approval signatures, effective dates, version history, review cadence, and distribution/attestation logs.
- Retention procedures confirming records are preserved as required and readily retrievable during audits.
Evidence that strengthens your position
- A policy index mapping each document to HIPAA citations and internal owners.
- Gap assessments or internal audits verifying policy-to-practice alignment.
- Role-based quick-reference guides used by frontline staff.
Common pitfalls to avoid
- Policies that are “adopted” but not implemented in daily workflows.
- Stale templates with missing approvals or outdated scope statements.
- One-off exceptions that contradict written procedures without risk sign-off.
Security Risk Analysis Reports
What OCR expects in a Security Risk Assessment
- Defined scope covering all systems, locations, vendors, and data flows where ePHI resides or transits.
- Threat and vulnerability identification with likelihood/impact scoring and a documented methodology.
- A prioritized risk register linking findings to specific assets, owners, and remediation targets.
- Evidence of management review, resource allocation, and scheduled follow-ups.
- Triggers for updates (e.g., new EHR modules, mergers, cloud migrations) and the most recent reassessment.
Artifacts OCR may request
- Latest Security Risk Analysis report and interim updates.
- Vulnerability scan summaries, penetration test executive reports, and remediation tracking.
- Data flow diagrams and asset inventories for systems containing ePHI.
Common pitfalls to avoid
- Treating the assessment as an IT-only exercise that omits paper workflows or human processes.
- Listing risks without time-bound remediation or acceptance rationale.
- Allowing the analysis to become outdated after significant environment changes.
Business Associate Agreements
What OCR typically requests
- A complete inventory of business associates with services, contact details, and ePHI access rationale.
- Fully executed Business Associate Agreements (BAAs) for each vendor handling PHI/ePHI, including subcontractor flow-downs.
- Vendor due diligence files and risk-tiering decisions supporting onboarding and renewals.
Key Business Associate Contractual Obligations to show
- Permitted uses/disclosures, safeguard requirements, and breach/incident reporting timelines.
- Subcontractor oversight, right to audit, and termination with return or destruction of PHI.
- Minimum necessary standards and cooperation in investigations and notifications.
Maintenance practices that help
- A central repository with version control, renewal dates, and ownership assignments.
- Periodic reviews verifying services have not outgrown BAA scope.
- Playbooks for escalating vendor issues and documenting corrective actions.
Workforce HIPAA Training Records
What OCR wants to see
- Workforce Privacy Training Documentation: curricula, schedules, and completion records for new hires, annual refreshers, and role-based modules.
- Evidence of targeted training after incidents or system changes.
- Attestations acknowledging policies, sanctions, and acceptable use.
Supporting artifacts
- LMS reports or rosters with dates, scores, and instructor details.
- Content outlines for Privacy Rule, Security Rule, and Breach Notification topics tailored by role.
- Communications announcing mandatory sessions and completion deadlines.
Common pitfalls to avoid
- “One-size-fits-all” modules that omit high-risk roles (e.g., IT admins, billing, telehealth).
- Inadequate tracking for temps, students, volunteers, and contractors.
- Training that covers policy titles but not practical, real-world scenarios.
Security Incident and Breach Logs
What to provide
- Centralized logs capturing ePHI Security Incident Reporting, including date/time, systems affected, scope, and status.
- For confirmed breaches: risk-of-compromise analysis, notification decisions, timelines, and mitigation steps.
- Root-cause analyses with lessons learned and links to corrective actions.
Evidence OCR often requests
- Incident tickets, forensic summaries, and containment/eradication documentation.
- Executive communications and approvals for notification strategies.
- Metrics showing mean time to detect/respond and closure criteria.
Common pitfalls to avoid
- Logging only reportable breaches while ignoring near-misses or policy violations.
- Missing chain-of-custody details for forensic evidence.
- Incomplete timelines that cannot substantiate notification decisions.
Notice of Privacy Practices
What OCR reviews
- The current Notice of Privacy Practices (NPP) with effective date and distribution methods.
- Notice of Privacy Practices Verification: proof of posting at points of service and on web portals, plus patient acknowledgment processes.
- Translation availability and processes for limited English proficiency and accessibility needs.
Artifacts to prepare
- Final NPP copy, revision history, and approval records.
- Screenshots or photos of posted notices and patient-facing displays.
- EHR or intake logs showing distribution and receipt acknowledgments.
Common pitfalls to avoid
- Generic NPP language that does not reflect your actual practices.
- Failing to update the NPP after material changes to uses/disclosures or rights.
- Inconsistent acknowledgment capture across clinics or service lines.
Risk Management and Corrective Action Plans
What OCR expects
- A living risk management plan that links Security Risk Assessment findings to remediation tasks with owners and dates.
- Corrective Action Plan Implementation evidence for incidents, audit findings, and vendor gaps.
- Defined success criteria, verification testing, and management sign-off for closure.
Artifacts to assemble
- Risk register with status, dependencies, and budget/resource allocations.
- Change records showing when controls were implemented and validated.
- Dashboards or summaries used in governance meetings.
Common pitfalls to avoid
- Open high-risk items without interim compensating controls.
- Accepting risk without documenting business justification and review cadence.
- Closing actions without evidence that controls are effective in practice.
When your documentation is current, consistent, and traceable from policy to practice, you can produce proof quickly and guide OCR through a clear story of compliance and continuous improvement.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
FAQs
What types of documents does OCR request during a HIPAA audit?
OCR commonly asks for policies and procedures, Security Risk Analysis reports and updates, Business Associate Agreements and vendor inventories, workforce training records, security incident and breach logs, the current Notice of Privacy Practices with posting and acknowledgment evidence, and risk management or corrective action plans that show remediation progress.
How often does HHS OCR conduct random HIPAA compliance reviews?
There is no fixed public schedule. OCR conducts periodic desk and on-site reviews based on program priorities, funding, and risk signals. Because selection can occur at any time, you should maintain audit-ready documentation year-round and refresh key evidence after major operational or technology changes.
What is required in a valid Security Risk Analysis?
A valid analysis scopes all locations and systems with ePHI, identifies threats and vulnerabilities, rates likelihood and impact, produces a prioritized risk register, and documents the methodology, approvals, and remediation plans. It must be reviewed and updated regularly and whenever significant environmental changes occur.
How should entities maintain Business Associate Agreements?
Keep a centralized, version-controlled repository of executed BAAs mapped to each service, with renewal dates, responsible owners, and due diligence files. Ensure Business Associate Contractual Obligations cover safeguards, permitted uses, subcontractor flow-downs, breach reporting timelines, termination, and return or destruction of PHI. Review BAAs when services or legal requirements change and before sharing any PHI.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.