The OCR complaints process protects individuals against possible violations of their patient data. This helps build public confidence in the healthcare system by demonstrating that there are mechanisms in place to address these privacy concerns assuring individuals that their complaints will be taken seriously and investigated thoroughly.
A wide variety of potential HIPAA violations or breaches can lead to an infringement of the privacy and security of an individual's data, and a broad array of these violations can result in an OCR complaint. These include:
Related: Understanding HIPAA violations and breaches
The Office for Civil Rights (OCR) is responsible for ensuring compliance with HIPAA's Privacy, Security, and Breach Notification Rules. It investigates complaints and conducts compliance reviews to determine if covered entities (such as healthcare providers, health plans, and healthcare clearinghouses) and their business associates are meeting their obligations under HIPAA.
Amongst their jurisdiction is receiving and investigating complaints from individuals, organizations, and advocacy groups who believe that their rights under HIPAA have been violated. They review the complaints, gather evidence, and determine if any HIPAA violations have occurred.
Related: What is the OCR, and what does it do?
The OCR offers several methods of laying a complaint for any of the above reasons. These include making use of their online complaint portal and making use of mail or fax. This complaint should include details of the violation, the covered entity that committed the violation, and any applicable reporting documents.
The OCR considers the nature and extent of the alleged violation. Violations that involve intentional misconduct, repeated offenses, or large-scale breaches of PHI are typically deemed more severe. The process involves the following steps:
The healthcare organization may be required to comply with the OCR investigation after the complaint has been logged. The OCR can employ several methods of resolution if a violation is found to exist. If it determines that the violations are significant or the entity has a history of non-compliance, it has the authority to impose civil monetary penalties (CMPs) on the covered entity or business associate. This ultimately can drive the covered entity or business associate to improve their compliance with HIPAA regulations.
The OCR may assess monetary fines on covered entities found to violate HIPAA. The penalty amount depends on the severity of the violation, with penalties ranging from thousands to millions of dollars.
The OCR can require covered entities to implement specific corrective actions to address the identified violations. This may involve developing and implementing policies and procedures, providing additional staff training, or implementing technical safeguards to protect PHI.
In some cases, the OCR may enter into resolution agreements with covered entities to address the violations and ensure future compliance. These agreements typically outline the actions the entity must take to rectify the violation and prevent further non-compliance.
Related: HIPAA Compliant Email: The Definitive Guide