Most employers have become accustomed to the IRS and Department of Labor periodically auditing their qualified retirement plans. Now, employers must also be ready for HIPAA audits.
Most employers were required to comply with the HIPAA privacy rules in 2003 and 2004. These compliance efforts involved preparing and issuing a Notice of Privacy Practices. As part of this process, employers followed the flow of protected health information through their organization, including the manner in which health information was shared with outside vendors. They executed business associate agreements with vendors, including insurance brokers, third-party administrators, flex plan administrators and legal counsel. Most employers undertake detailed efforts to ensure employees’ PHI is safeguarded to comply with the HIPAA privacy rules.