← Back to Blog

9 Things OCR Auditors Actually Ask For (And How to Have Them Ready)

The Audit Is a Document Request, Not a Conversation

Practices imagine an OCR audit as an inspector walking the halls. It is almost never that. It is a letter — a data request — giving you a short window to produce specific records that prove your HIPAA program exists and operates. The organizations that struggle are not the ones with weak security; they are the ones who have controls but cannot produce the paperwork proving it within the deadline. "We do that, we just never wrote it down" is not an acceptable answer to OCR. Here are the nine things auditors ask for most, and what "ready" looks like for each.

1. Your Current Risk Analysis

This is the first document OCR requests and the most common one found missing or inadequate. Under the Security Rule, an accurate, organization-wide risk analysis is mandatory — and it must be current, not a one-time exercise from three years ago. Auditors look for evidence that you identified where ePHI lives, the threats to it, and the likelihood and impact of each. Ready looks like: a dated risk analysis covering all systems that touch ePHI, updated within the last year or after any major change. If you don't have one, start this week — it is the foundation everything else rests on.

2. Your Risk Management Plan

A risk analysis that identifies gaps but shows no action taken is arguably worse than none — it proves you knew and didn't act. OCR asks for the risk management plan: the documented remediation of the risks the analysis found, with owners and dates. Ready looks like: a tracked list of findings, each with a mitigation, a responsible person, and a completion date or documented acceptance of the residual risk.

3. Policies and Procedures — With Version History

OCR asks for your written HIPAA policies and procedures, and increasingly wants to see when they were adopted and revised. A policy dated the week the audit letter arrived tells its own story. Ready looks like: a complete policy set covering the Security, Privacy, and Breach Notification Rules, each with an effective date and a revision history showing it is a living document, not a binder assembled in a panic.

4. Proof of Workforce Security Training

Every practice claims it trains staff. OCR asks you to prove it — with names, dates, and completion records. Verbal "we go over it at the staff meeting" does not survive an audit. Ready looks like: per-employee training completion records with dates, ideally showing both onboarding training and periodic refreshers. The point is a defensible roster that maps every current staff member to a completed, dated course.

5. Your Business Associate Agreements

For every vendor that creates, receives, maintains, or transmits PHI on your behalf, OCR expects a signed BAA on file. Missing BAAs are a perennial enforcement finding because they are easy to overlook and easy for auditors to check. Ready looks like: a current vendor inventory, and a signed, in-force BAA for each vendor on it. Before you sign the next one, run through the questions every BAA should answer.

6. Access Control and Audit Log Evidence

OCR wants to see that access to ePHI is limited to those who need it, and that system activity is recorded and reviewed. This means both the configuration (who can see what) and the practice (someone actually reviews the logs). Ready looks like: a current list of user accounts and their access levels, evidence of periodic access reviews, and documentation that audit logs are not just collected but reviewed on a schedule. Unreviewed logs are how insider snooping goes undetected for years.

7. Your Contingency and Backup Plan

The Security Rule requires a contingency plan: data backup, disaster recovery, and emergency-mode operations. OCR asks not only whether you have backups but whether you have tested that they restore. Ready looks like: a written contingency plan plus evidence of at least one successful restore test. A backup you have never restored is a hope, not a control — and hope is not documentable.

8. Breach Notification Records

If you have had any breaches — even small ones affecting a handful of individuals — OCR asks for your risk-assessment documentation for each and proof you notified the affected parties within the required timelines. Practices often mishandle the small ones, assuming they didn't count. Ready looks like: a log of every incident evaluated, the four-factor breach determination for each, and notification records where required. If you don't have a defined process, build the first-24-hours playbook before you need it.

9. Evidence of Sanctions Actually Applied

You are required to have a sanction policy for workforce members who violate HIPAA — and OCR may ask whether you have ever enforced it. A policy that has never been applied, in an organization that has clearly had violations, reads as a paper control. Ready looks like: your written sanction policy plus documented examples of it being applied consistently when warranted. Consistency matters: selective enforcement is its own liability.

The Pattern Behind All Nine

Notice what OCR is really testing: not whether you are perfectly secure, but whether your program is real, current, and documented. Every item on this list is something a practice with a functioning HIPAA program already does — the failure is almost always in the proof, not the practice. The fix is to treat documentation as a byproduct of your compliance work rather than a separate project you do when the letter arrives. If each of these nine is maintained continuously, an audit request becomes an export, not an emergency.

Related Reading

Call to Action

Want all nine of these maintained and exportable on demand, so an audit letter is a five-minute task instead of a five-week scramble? Schedule a walkthrough of HIPAA Security Suite, or take the 3-minute readiness quiz to see which of these you'd struggle to produce today.

Ready to simplify your HIPAA compliance?

See how HIPAA Security Suite can protect your organization.

Request a Demo