Which kind of audit you are facing
The HHS Office for Civil Rights has run an audit program, but far more organizations hear from it through a compliance review or investigation that follows a complaint or a breach report. Those inquiries usually focus on the specific events involved, although they can widen once documents start arriving. Customers and business partners also audit vendors under the terms of their contracts, sometimes with little notice. An internal audit, done before anyone outside asks, is a separate route and often the most useful one. Knowing which of these is underway determines the deadlines, the audience, and how much you are expected to produce.
What auditors usually want to see
Requests commonly center on the most recent risk analysis and on what the organization did about the risks it identified. Auditors also tend to ask for policies carrying dates that show when they were adopted and revised, training records, business associate agreements, and incident files. HIPAA expects certain documentation to be retained for a set period, so older versions of a policy matter as much as the current one. Producing a policy written last week to answer a question about past practice usually causes more problems than it solves. It is better to show what existed at the time and explain what has changed since.
Preparing without overreaching
Before responding to a regulator, we review the request line by line and agree with you on what falls within its scope. We gather documents centrally so that the organization speaks with one voice and nothing goes out twice in different versions. When an internal HIPAA compliance audit is planned, we discuss whether to run it under counsel's direction, which may help protect the analysis in some circumstances but does not shield the underlying facts. Findings that turn up a reportable breach have to be handled on their own timeline, separately from the audit schedule. Our aim is a response that is accurate, complete for what was asked, and consistent with the documents.