What Documents Does OCR Request in a HIPAA Audit? A Complete Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

What Documents Does OCR Request in a HIPAA Audit? A Complete Checklist

Kevin Henry

HIPAA

August 06, 2026

7 minutes read
Share this article
What Documents Does OCR Request in a HIPAA Audit? A Complete Checklist

When the U.S. Department of Health and Human Services Office for Civil Rights (OCR) conducts a HIPAA audit, it asks for specific, verifiable evidence. This guide shows you exactly what documents OCR commonly requests and how to organize them for rapid, confident production.

Use this complete checklist to confirm your files are current, mapped to HIPAA standards, and easy to retrieve. Wherever ePHI is involved, document the control, the process behind it, and the proof that it works.

Risk Assessment Documentation

What OCR looks for

Provide an enterprise-wide risk analysis that identifies where Electronic Protected Health Information (ePHI) is created, received, maintained, or transmitted, along with the threats, vulnerabilities, and residual risk. Show how you prioritized risks and tracked remediation to closure.

Documents to prepare

  • Current enterprise risk analysis covering all systems and workflows handling ePHI, including data flow diagrams and an asset inventory.
  • Risk register detailing likelihood, impact, risk ratings, mitigation plans, owners, due dates, and status updates.
  • Methodology document describing scope, assessment techniques, and evaluation criteria used to score risk.
  • Evidence from scans and assessments (e.g., vulnerability scans, configuration baselines, penetration test summaries) and remediation tickets.
  • Management approvals, sign-offs, and review cadence demonstrating ongoing risk management.
  • Periodic re-assessment schedule and the last two cycles for comparison and trending.

Quality indicators

  • Explicit mapping of each risk to specific HIPAA Security Rule safeguards and your controls.
  • Traceability from risk to remediation task to validation evidence.
  • Inclusion of administrative, physical, and technical risks—not just IT vulnerabilities.

Security Policies and Procedures

What OCR looks for

Written, approved, and implemented policies that match your actual practices. Materials should be version-controlled, date-stamped, and readily accessible to your workforce.

Documents to prepare

  • Written Information Security Program (WISP) that organizes the full policy set and names executive sponsors and review intervals.
  • Policies for access management, authentication and MFA, encryption, device and media controls, logging and monitoring, minimum necessary, change management, patching, and secure software practices.
  • Procedures that operationalize each policy (who does what, when, and how) with step-by-step instructions and screenshots or forms.
  • Physical security, facility access, workstation security, and disposal/retention procedures tied to ePHI handling.
  • Sanction policy and documented enforcement examples where applicable.
  • Policy change log with effective dates, approvers, and summaries of revisions.

Practical tips

  • Map each policy to relevant HIPAA standards and implementation specifications to streamline OCR review.
  • Ensure procedures reflect actual tools and workflows—OCR compares words to reality.
  • Centralize policies in a single repository with attestations showing workforce access.

Incident Response Plan

What OCR looks for

A tested plan that defines roles, escalation paths, evidence handling, decision criteria, and notifications. OCR expects clear documentation of Breach Notification Timelines and the process for determining if an incident is a reportable breach.

Documents to prepare

  • Incident response policy and detailed procedures, including triage, containment, eradication, recovery, and post-incident review.
  • Role matrix and on-call escalation chart with phone/email trees and after-hours coverage.
  • Investigation templates: incident intake form, evidence log, chain-of-custody, and root cause analysis worksheet.
  • Decision framework for breach risk assessment and documentation of determinations.
  • Breach Notification Timelines reference (federal and state) and communication playbooks for affected individuals and relevant authorities.
  • Incident log for the last 12–24 months, including lessons learned and corrective actions.
  • Tabletop exercise agendas, scenarios, attendee lists, and improvement plans from recent tests.

Quality indicators

  • Clear linkage from an incident to notifications, if applicable, and to remediation tickets.
  • Evidence that lessons learned resulted in policy/procedure updates and control enhancements.

Business Associate Agreements

What OCR looks for

A complete, current inventory of all vendors and partners that create, receive, maintain, or transmit ePHI, supported by executed Business Associate Agreements (BAAs) that meet HIPAA requirements.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Documents to prepare

  • Vendor inventory identifying which vendors are business associates and which are not.
  • Executed Business Associate Agreements (BAAs), including any addenda and security exhibits.
  • Subcontractor flow-down documentation showing how BA obligations extend to downstream entities.
  • Due diligence artifacts: security questionnaires, SOC reports summaries, and risk reviews.
  • Termination checklists confirming return or destruction of ePHI and access revocation.

Quality indicators

  • Dates align: contract effective dates, BAA execution dates, and service go-live dates are logically ordered.
  • Reporting and breach cooperation clauses are explicit and operationalized in incident procedures.

Staff Security Awareness Training Records

What OCR looks for

Proof that your workforce receives initial and ongoing Security Awareness Training tailored to ePHI risks and your environment, with completion tracking and accountability.

Documents to prepare

  • Training curriculum, learning objectives, and schedules for new hires and annual refreshers.
  • Completion records: attendance logs, LMS reports, certificates, and signed acknowledgments of key policies.
  • Assessment results: quizzes, phishing simulation metrics, and remediation plans for low scorers.
  • Targeted training for privileged users, developers, help desk, and incident responders.
  • Evidence of ad-hoc communications (alerts, tips, reminders) responding to emerging threats.

Quality indicators

  • Role-based content that reflects actual job functions and system access.
  • Trend reports showing improvement over time and actions taken after simulations.

Access Control Documentation

What OCR looks for

Structured, least-privilege access to ePHI with strong authentication, rapid deprovisioning, and periodic access reviews. Documentation must tie users and roles to specific systems and permissions.

Documents to prepare

  • Access Control Matrices listing applications, roles, permissions, and assigned users or groups.
  • Provisioning and deprovisioning procedures with approvals, identity verification, and SLAs.
  • Evidence of periodic access recertifications and privileged account reviews.
  • MFA enforcement records, SSO configurations, and emergency “break-glass” access procedures with audit logs.
  • Joiner/mover/leaver tickets, including last day worked and access removal timestamps.
  • Remote access and vendor access controls, including time-bound accounts and monitoring.

Quality indicators

  • End-to-end traceability from HR events to access changes to log verification.
  • Logged and reviewed administrative activities on critical ePHI systems.

Contingency and Disaster Recovery Plans

What OCR looks for

Plans and test evidence proving you can sustain or quickly restore ePHI availability, integrity, and confidentiality during disruptions. OCR expects documented backups, emergency mode operations, and resilient recovery objectives.

Documents to prepare

  • Data backup plan with schedules, scope of systems and datasets containing ePHI, and offsite protections.
  • Disaster recovery plan detailing Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for critical services.
  • Emergency mode operations plan describing prioritized processes, roles, and communication channels.
  • Disaster Recovery Testing artifacts: restore test logs, failover exercises, results, issues found, and corrective actions.
  • Inventory of dependencies (e.g., cloud providers, power, network) with contingency procedures.
  • Contact lists for internal leaders, vendors, and regulators aligned to incident and outage scenarios.

Quality indicators

  • Successful test evidence for both file-level restores and system-level recovery, with post-test improvements.
  • Alignment among business continuity, disaster recovery, and incident response documentation.

Conclusion

OCR audits move quickly, so prepare a single, current repository containing your risk analysis, policies, incident response artifacts, BAAs, training records, access control evidence, and contingency testing results. Keep each item approved, date-stamped, and mapped to HIPAA safeguards to answer, with proof, what documents OCR requests in a HIPAA audit.

FAQs.

What types of risk assessments does OCR require?

OCR expects an enterprise-wide risk analysis that inventories where ePHI resides, evaluates threats and vulnerabilities across administrative, physical, and technical safeguards, and documents risk ratings, mitigation plans, and validation of fixes. Methodology, scope, sign-offs, and periodic updates are essential parts of the package.

How often must security policies be updated?

Update policies on a defined cadence (at least annually is common) and whenever technology, regulations, systems, or business processes change. OCR also looks for version control, approval records, and procedures that reflect how the policy is actually implemented.

What details are needed in an incident response plan?

Include roles and responsibilities, escalation criteria, investigation and evidence handling steps, containment and recovery actions, breach risk assessment criteria, Breach Notification Timelines, communication templates, and post-incident reviews. Provide logs of recent incidents and results from tabletop exercises.

Are business associate agreements mandatory for all vendors?

No. BAAs are required for vendors that create, receive, maintain, or transmit ePHI on your behalf. Maintain an up-to-date vendor inventory, executed BAAs for all business associates and relevant subcontractors, and documentation of due diligence and ongoing oversight.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles