• Platform
    • Why Caspio
      • Platform Overview
      • What is Low Code
      • Visual App Builder
      • Database
      • Identity Management
      • Automations
      • AI Capabilities
      • Integrations
      • Customer Stories
    • Security & Compliance
      • HIPAA Compliance
      • SOC 2 Compliance
      • FERPA Compliance
      • WCAG Compliance
      • Compliance Overview
      • Trust Center
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Solutions
    • By Industry
      • Healthcare
      • Education
      • Government
      • Financial Services
      • Energy and Utilities
      • Nonprofits
      • Media
      • Consulting
    • By Use Case
      • HIPAA Compliant Apps
      • Custom CRM
      • Excel to Web
      • Finance Management
      • Asset Management
      • Patient Portal
      • Web Dashboard
      • MS Access to Cloud
    • App Templates
      • Custom CRM
      • Patient Portal
      • Knowledge Base
      • Project Management
      • Support Ticketing System
      • Contact Management
      • Task Management
      • View All
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Build
    • Build It Yourself
      • Tutorials
      • Starter Apps
      • Caspio Academy
    • Work With Experts
      • Professional Services
      • Managed Application Services
      • Work With a Partner
      • Onboarding
      • Expert Sessions
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Resources
    • Learn
      • Caspio Academy
      • Get Certified
    • Explore
      • Blogs
      • Podcast
      • Events
      • Customer Stories
      • View All
    • Marketplace
      • Starter Apps
      • App Blocks
      • Extensions
      • Customizations
      • Vertical Solutions
      • View All
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Pricing
    • Pricing Plans
      • Standard Plans
      • Caspio HIPAA Edition
    • Getting Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • search
  • Contact Sales
  • Support
    • Online Help
    • Community Forum
    • Contact Support
  • Log in
Get a Demo Try Free
High Contrast
Caspio logo Try Free
  • Platform
    • Why Caspio
      Why Caspio
      • Platform Overview
      • What is Low Code
      • Visual App Builder
      • Database
      • Identity Management
      • Automations
      • AI Capabilities
      • Integrations
      • Customer Stories
    • shield-check
      Security & Compliance
      • HIPAA Compliance
      • SOC 2 Compliance
      • FERPA Compliance
      • WCAG Compliance
      • Compliance Overview
      • Trust Center
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Solutions
    • Industries
      By Industry
      • Healthcare
      • Education
      • Government
      • Financial Services
      • Energy and Utilities
      • Nonprofits
      • Media
      • Consulting
    • Use Case
      By Use Case
      • HIPAA Compliant Apps
      • Custom CRM
      • Excel to Web
      • Finance Management
      • Asset Management
      • Patient Portal
      • Web Dashboard
      • MS Access to Cloud
    • document-generation
      App Templates
      • Custom CRM
      • Patient Portal
      • Knowledge Base
      • Project Management
      • Support Ticketing System
      • Contact Management
      • Task Management
      • View All
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Build
    • mouse-click-icon
      Build It Yourself
      • Tutorials
      • Starter Apps
      • Caspio Academy
    • professional_services_icon
      Work With Experts
      • Professional Services
      • Managed Application Services
      • Work With a Partner
      • Onboarding
      • Expert Sessions
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Resources
    • book
      Learn
      • Caspio Academy
      • Get Certified
    • signed-BAA_icon
      Explore
      • Blogs
      • Podcast
      • Events
      • Customer Stories
      • View All
    • store_icon
      Marketplace
      • Starter Apps
      • App Blocks
      • Extensions
      • Customizations
      • Vertical Solutions
      • View All
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Pricing
    • Money-on-palm-icon
      Pricing Plans
      • Standard Plans
      • Caspio HIPAA Edition
    • Launch-faster-icon
      Getting Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • High Contrast
  • search
  • Contact Sales
  • Support
    • Online Help
    • Community Forum
    • Contact Support
  • Log in
Get a Demo Try Free

Phase 2 HIPAA Audits: What to Expect from Your Business Associates

April 21, 2016

  • Tech Tips
  • Customer Spotlight
  • News Articles
Try Free
  • Home
  • Blog
  • Current Article
10109
April 21, 2016

Last month, the Department of Health and Human Services’ Office for Civil Rights (OCR) launched the phase 2 of HIPAA Audit Program. The second phase of the audit will now focus on whether covered entities and business associates adhere to the HIPAA Privacy, Security, and Breach Notification Rules. If your business associates are handling electronic Protected Health Information (PHI), you must ensure your partners have proper HIPAA safeguards in place.

Ignorance of HIPAA requirements is not an excuse for violating the rules. An annual maximum of $1.5 million per violation can be charged for noncompliance.

In light of the phase 2 audits, here’s a list of important requirements to verify with your business associates:

1. PHI Handling Meets Current Audit Protocol Requirements

Under Section §164.306(a) of the OCR Current Audit Protocol, covered entities and business associates must ensure confidentiality, integrity and availability of PHI; protect against reasonably anticipated threats or hazards to the security or integrity of PHI; protect against reasonably anticipated uses or disclosures of PHI that are not permitted or required by the Privacy Rule; and ensure compliance with Security Rule by its workforce.

Quick Fact: An insurance holding company in Puerto Rico agreed to pay a $3.5 million settlement for multiple breaches and violations involving unsecured PHI.

2. Data is Encrypted in Transit and at Rest

The OCR imposes that PHI data must be unusable, unreadable, or indecipherable by an unauthorized user. The HIPAA Security Rule Data defines data encryption as the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.

Due to the prevailing cases of data breach, Section §164.312(a)(2)(iv) and §164.312(e)(2)(ii) require that PHI data is encrypted to ensure confidentiality and integrity of the data. Two encryption methods should be applied:

  • Data Encryption In Transit:
    “Data in transit” is data being accessed over a wireless network or a cable network. Data in transit moves across untrusted networks such as the internet or through private networks such as corporate Local Area Networks (LANs).
  • Data Encryption At Rest:
    “Data at rest” is inactive data stored on a physical media (e.g. servers, spreadsheets, mobile devices). Data at rest includes but not limited to corporate files stored in a user’s computer hard drive, data stored in secure online database servers, or files on an offsite storage location.

Quick Fact: A medical research firm in New York agreed to pay a $3.9 million settlement after an unencrypted laptop was stolen from an employee’s car.

3. Audit Logs are Tracked and Stored

Audit logs record various activities and events taking place on an end user device or in an information system. Section §164.312(b) requires that audit logs are recorded for all activities accessing PHI, such as the identity of the authenticated user, what information was accessed by the user, what PHI was viewed or changed and by whom. In addition, Section §164.316(b)(2)(i) requires that the audit logs are stored for six years.

Quick Fact: One of the nation’s largest healthcare companies agreed to pay a $1.7 million settlement for the lack of technical safeguards to authorize access to PHI in its online database applications.

4. A Signed Business Associate Agreement is in Place

Section §164.314(a)(1) requires that the entity must have policies and procedures in place regarding its contractual arrangements with vendors or other entities to which it discloses PHI for use on its behalf.

A business associate agreement holds parties liable for failing to safeguard PHI in accordance with the HIPAA Security Rule and is subject to civil penalties. The contract between the entity and its associates defines and limits the permitted use and disclosure of PHI by the business associate. In phase 2 of the HIPAA Audit Program, the OCR is collecting the contact information of covered entities and business associates for inclusion in potential audit pools.

Quick Fact: A hospital in Minnesota agreed to pay a $1.5 million settlement for failure to implement a business associate agreement with its vendor.

Resources for the Phase 2 HIPAA Audit

For more information on the phase 2 of the HIPAA Audit Program, the following resources are available from the U.S. Department of Health and Human Services:

  • Current HIPAA Audit Protocol
  • Audit Pre-Screening Questionnaire
  • Sample Template for Business Associate Listing

Caspio’s HIPAA-Compliant Platform

Since the launch of the Caspio HIPAA Edition in 2014, Caspio continues to serve as a strategic technology partner for healthcare organizations relying on its HIPAA-compliant application platform. Users of the HIPAA Edition include state and local government agencies, large insurance providers, state insurance exchanges, hospitals, research universities, and pharmaceutical companies.

“The healthcare industry is facing increasing pressure and scrutiny, and Caspio is prepared to support our customers as a trusted technology partner,” said Frank Zamani, Founder and CEO of Caspio. “We have invested a substantial amount of time and resources to ensure our platform and operations are HIPAA-compliant and we are proud to be the leading HIPAA-compliant platform meeting this demand across the healthcare industry.”

To learn more about Caspio’s HIPAA Edition, request a free consultation with a product expert.

Call to Action Block Call to Action Block

Share this post:

Previous Post:
New Release: Caspio 9.1
Next Post:
Caspio Named SIIA CODiE Award Finalist for Best Platform-as-a-Service

Recommended Articles

Customer Portal Software: Build a Self-Service Experience

Custom Customer Portal Software for Growing Businesses

READ STORY
Best Microsoft Access Alternatives (2026)

Best MS Access Alternatives in 2026

READ STORY
Which No-Code Platforms Support FERPA Compliance?

No-Code Platforms That Support FERPA Compliance

READ STORY
Introducing AI Solutions: A New Category of AI Agents in the Caspio Marketplace

Introducing AI Solutions in the Caspio Marketplace

READ STORY
Best Quickbase Alternative for No-Code Business Applications (2026)

Best Quickbase Alternative for No-Code Apps in 2026

READ STORY
What Should a Custom CRM Include? The Complete Feature Checklist

10 Must-Have Features Every Custom CRM Should Include

READ STORY
Employee Portal Software for HR and Operations Teams

Modern Employee Portal Software for Enterprise

READ STORY
Member Portal Software for Associations and Organizations

How to Build a Member Portal Using Low Code

READ STORY
The Zoho Creator Alternative That Doesn’t Charge Per User

Best Zoho Creator Alternative Without Per-User Pricing

READ STORY
HIPAA Database Software: How to Choose a Compliant Platform for Healthcare Data

HIPAA Database Software: How to Choose a Compliant Platform

READ STORY
Enterprise Features at Mid-Market Prices: How Low-Code Changed the Game

Enterprise Features at Mid-Market Prices: How Low-Code Changed the Game

READ STORY
Caspio vs. Airtable: Which No-Code Platform Is Right for Your Business?

Caspio vs. Airtable: Which No-Code Platform Is Right for Your Business?

READ STORY
Subscribe for More Updates
  • PRODUCT

  • Platform Overview
  • What Is Low Code?
  • Case Studies
  • Marketplace
  • Pricing
  • Get a Custom Demo
  • Free Trial
  • SOLUTIONS

  • Healthcare
  • Education
  • Government
  • Financial Services
  • Energy and Utilities
  • Nonprofits
  • Media
  • Consulting
  • RESOURCES

  • Resource Center
  • Caspio Academy
  • Online Help
  • Onboarding
  • Get Certified
  • Professional Services
  • Managed Application Services
  • Support Center
  • Legal Center
  • COMPANY

  • Our Story
  • Careers
  • Leadership
  • News
  • Partner Programs
  • Referral Program
  • Academic Program
  • Discount Programs
  • Contact Us
  • TRENDING

  • HIPAA Compliance
  • SOC 2 Type 2 Compliance
  • FERPA Compliance
  • Build Custom CRM
  • Create Web Dashboards
  • Best Online Database
  • Build a Mini CRM SaaS in 1 Hour
  • Go Paperless With Web Forms
  • Launch Patient Portal
Caspio Logo

Caspio is the world’s leading cloud platform for building online database applications without coding.
Start a free trial today and experience the power of no-code.

Footer Partners

© 2026 Caspio, Inc. Sunnyvale, California. All rights reserved.

  • Privacy Statement
  • Terms of Use
  • Report Abuse
  • Sitemap
  • Feedback