HIPAA & Mandatory Risk Analyses
The results are in from the early HIPAA audits by Health and Human Services (HHS). Want to know what was the major weakness found by the government’s auditors? The compliance deficiency all-to-common among healthcare practices? It was, according to HHS, “the lack of a thorough risk analysis.” Time after time, auditors would ask to see evidence that the covered entity had performed a risk analysis. And time after time, much to their dismay, the answer they heard was, “A what?”