What actually triggers a HIPAA audit, and why that is the wrong question
OCR restarted its audit program in December 2024, and fifty organizations were selected. In the same period it received more than thirty thousand complaints. Which of those two numbers should decide how you spend your attention.
Last verified: 2026-07-14
Clinic owners ask this in one of two tones. Either “what makes them come after you,” said quietly, or “what are the odds,” said hopefully. Both are asking the same thing, and the honest answer starts by separating two words that get used interchangeably and mean completely different things.
An audit and an investigation are not the same thing
An audit is proactive. OCR is required by the HITECH Act to periodically audit regulated entities. It picks organizations, tells them they were picked, and reviews their compliance with selected provisions. Nothing you did caused it. There is no trigger, because selection is not a trigger.
An investigation is reactive. Something happened: a complaint arrived, you filed a breach report, a news story ran. OCR opens a file about that specific thing.
Almost everything a clinic owner calls “getting audited” is an investigation. And the distinction matters, because one of them is a lottery you cannot influence and the other one is largely a function of how you run your clinic.
The audit program, factually
OCR’s audit program has run in three rounds since HITECH created the requirement. The first began in 2012, the second in 2016 and 2017, and then it went dormant for years while OCR cited flat funding and workload.
It restarted in December 2024. The current round covers fifty covered entities and business associates, and it is narrower than the previous one: it focuses on the Security Rule provisions most relevant to hacking and ransomware attacks. OCR has said it will publish an industry report of the findings once the round is complete, as it did last time, though that took until December 2020 for the 2016-2017 round.
If you are selected, you are told. It is a desk audit built on document requests, not a raid. And selection has nothing to do with anything you did.
The number that should actually decide where you look
Now put that fifty next to OCR’s own accounting of its year. In its annual report to Congress covering 2024, OCR reported receiving more than thirty thousand new complaints.
Fifty audits. Thirty thousand complaints.
That ratio is the entire practical answer to the question this page is named after. You cannot make yourself less likely to be selected for an audit. You can make yourself far less likely to be complained about, and that is the lever that actually moves.
What genuinely starts an investigation
Five real paths, roughly in order of how often they matter to a small clinic.
“You cannot make yourself less likely to be selected for an audit. You can make yourself far less likely to be complained about, and that is the lever that actually moves”
A complaint. Anyone can file one, generally within 180 days of when they knew or should have known about the problem (45 CFR 160.306). This is the largest single source by an enormous margin.
Your own breach report. Filing is mandatory and failing to file is far worse, but understand what it is: an invitation for OCR to look at you, on a schedule set by the size of the incident (45 CFR 164.408). Reports of 500 or more individuals are posted publicly on HHS’s breach portal, where journalists, plaintiffs’ lawyers, and competitors can read them.
A compliance review OCR opens on its own (45 CFR 160.308). This is where enforcement initiatives live. When OCR decides a requirement is being widely ignored, it goes looking, which is exactly what the risk analysis initiative has been doing since late 2024. The settlements that came out of it are all the same finding.
Someone else’s breach with your name in it. When a business associate is breached, your clinic is named in the notifications. Their incident becomes your correspondence.
A referral or a story. A state attorney general, a payer, a licensing board, or a local news report. Less common, and it happens.
Who actually complains about an ABA clinic
This is where the general advice stops being useful, because the abstract answer is “an individual” and the concrete answer is two specific people.
A parent who feels dismissed. Usually about records. They asked for their child’s session notes and got a form, or a delay, or a no. Right of access is OCR’s most enforced provision and its most common complaint subject, and a parent who is told they cannot see notes about their own child does not shrug. Custody disputes sharpen this considerably: a parent who believes the clinic took the other side has both a motive and a specific grievance.
A former employee. Turnover in this field is high, exits are not always graceful, and a departing RBT knows exactly where the bodies are: the shared login, the tablet nobody wiped, the group chat with client names in it. If they also believe they were disciplined for raising a concern, you now have a retaliation question layered on top (45 CFR 164.530(g)). What the rule actually permits them to do, and why they usually do it, is worth knowing before it happens rather than after.
Neither of those is a compliance failure in the technical sense. They are relationship failures that become compliance events, which is why the most effective complaint prevention in a small clinic is not a control. It is answering the records request in thirty days, and giving your staff somewhere to raise a concern that is not a federal agency.
What you control, and what you do not
You do not control: whether you are selected for an audit, whether a vendor gets breached, whether a parent decides to file.
You do control: how fast you answer a records request, whether a departing employee’s access is actually revoked, whether the person with a concern has an internal path that goes somewhere, whether you retaliate when someone raises one, and whether your risk analysis describes your clinic or somebody else’s.
Notice that four of those five are about people rather than technology. The technical failures cause breaches. The human failures cause complaints, and complaints are six hundred times more likely to be the thing that starts your file.
And then the question that actually decides the outcome
Here is the part that makes the whole trigger question less important than it feels.
Audit or investigation, the opening request is nearly identical: show us the risk analysis, the policies, the training records, the business associate agreements, the incident log. Whether the letter arrives because a computer selected you or because a parent was angry, the folder you reach for is the same folder.
Which means the useful preparation is not guessing at triggers. It is being the clinic that can answer, on any Tuesday, without a scramble. What happens once the letter arrives is a separate and more consequential story, and the single best thing you can do before it does is make sure the answer already exists.
The short version
- An audit and an investigation are different things. OCR audits are proactive and you are selected, not triggered. Investigations are reactive and something sets them off.
- OCR restarted its audit program in December 2024, the first round since 2016-2017. It covers fifty covered entities and business associates, focused on the Security Rule provisions relevant to hacking and ransomware.
- In its 2024 report to Congress, OCR reported receiving more than thirty thousand new complaints. Against fifty audits. Complaints are the realistic path, by a factor of hundreds.
- In an ABA clinic the most likely complainant is a parent who feels dismissed or a former employee who left unhappy. Both are people, not systems.
- Nothing you do changes your odds of being selected for an audit. Almost everything you do changes your odds of being complained about.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- HHS Office for Civil Rights, the HIPAA Audit Program and the 2024-2025 auditsHHS.govhttps://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/index.html
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Compliance, 2024HHS.govhttps://www.hhs.gov/sites/default/files/compliance-report-to-congress-2024.pdf
- Complaints to the Secretary45 CFR 160.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-C/section-160.306
- Compliance reviews45 CFR 160.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-C/section-160.308
- Notification to the Secretary of a breach45 CFR 164.408https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.408
- Refraining from intimidating or retaliatory acts45 CFR 164.530(g)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- HHS Office for Civil Rights, 2016-2017 HIPAA Audits Industry Report, December 2020HHS.govhttps://www.hhs.gov/sites/default/files/hipaa-audits-industry-report.pdf
The file is the same either way.
Selected at random or investigated after a complaint, the request is the same: show us the risk analysis, the policies, the training, the vendors, the incidents. WiseUpHIPAA keeps that current as your clinic runs, so the answer exists before anyone asks the question.