Buying Guides

Beyond OCR: The Other Auditors Who Will Ask About Your EMR

The short answer

A hospital's EMR is reviewed by more than one authority, and they do not ask the same questions. The Office for Civil Rights asks whether you analyzed risk to electronic protected health information and addressed it. The Centers for Medicare and Medicaid Services asks whether the medical record is complete, accurate, and authenticated. An accrediting organization asks whether your information management practices work as documented. A state agency may add licensure and breach-notification requirements on top of all of it.

Buying an EMR against only one of these produces a system that satisfies one reviewer and creates work for the others.

Who asks

Four bodies commonly review some aspect of how a hospital runs its electronic record.

The Office for Civil Rights (OCR), within the U.S. Department of Health and Human Services, enforces the HIPAA Privacy, Security, and Breach Notification Rules.

The Centers for Medicare and Medicaid Services (CMS) enforces the conditions of participation that a hospital must meet to bill Medicare, which include requirements about medical records.

An accrediting organization, most often The Joint Commission, DNV, or the Accreditation Commission for Health Care, surveys hospitals that use accreditation to demonstrate compliance with CMS requirements.

State health departments and state attorneys general, which license facilities and in many states impose privacy and breach requirements beyond the federal floor.

OCR and the Security Rule

OCR's core question is documented at 45 CFR §164.308(a)(1)(ii)(A). A covered entity must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information it holds.

Two things about that sentence get missed by EMR buyers.

It says electronic protected health information the organization holds, not the EMR. The assessment covers every system that creates, receives, maintains, or transmits ePHI.

It sets no calendar frequency. HHS does not publish a required interval. Annual review is the widely accepted practice, and it is what the Merit-based Incentive Payment System asks eligible clinicians to attest to, so most organizations work on an annual cycle. That is practice and attestation, not a stated rule in the regulation text.

The proposed 2026 update to the Security Rule would tighten several requirements. It is a proposed rule and has not been finalized. Treat any vendor claim that new requirements are already in force with care.

CMS conditions of participation

CMS approaches the same record from a different direction. The medical records condition of participation at 42 CFR §482.24 requires a hospital to maintain a medical record for every patient, keep records complete and accurately documented, and have entries authenticated by the person responsible for them.

This is a records-integrity question rather than a security question. Whether your EMR can produce a legible, complete, authenticated record for a specific encounter on request is a CMS matter, and a system that handles access control well can still make this difficult if authorship, amendment history, and late entries are not cleanly recorded.

Accreditation surveys

A hospital accredited by an approved organization is surveyed against that organization's standards, which cover information management, record content and timeliness, and downtime procedures.

Accreditation surveys are periodic and scheduled differently from any HIPAA review, and they tend to test practice rather than documentation. A surveyor may ask a unit clerk to demonstrate the downtime procedure. The question is not whether a policy exists. The question is whether the person on the floor can carry it out.

State and specialty regulators

Several categories sit on top of the federal requirements.

State breach-notification law frequently sets shorter deadlines or broader definitions of personal information than the federal Breach Notification Rule.

Part 2 records. Substance use disorder treatment records from federally assisted programs carry additional protections at 42 CFR Part 2, with consent and redisclosure rules distinct from HIPAA.

42 CFR Part 2 and HIPAA were more closely aligned by rulemaking following the CARES Act, but the alignment is not identity, and an EMR that treats Part 2 records like any other chart can create a disclosure problem.

State licensure and retention schedules set how long records must be kept, and these vary considerably.

One system, four questions

ReviewerThe question they askWhat in the EMR answers it
OCRDid you assess risk to ePHI across the organization and act on it?Access controls, audit logs, encryption status, and the risk analysis documentation covering the EMR and everything around it
CMSIs the medical record complete, accurate, and authenticated?Authorship and cosignature, amendment and addendum history, timeliness of entries, legible output
AccreditorDo your information management practices work in operation?Downtime procedures staff can perform, record content standards, retention behavior
StateDo you meet requirements above the federal floor?Breach-notification timing, retention schedules, special handling for protected record categories

What to ask a vendor

Ask these before the contract, because each one is expensive to retrofit.

  1. Can the system produce a complete, authenticated record for a single encounter, including amendments and late entries, as a document a reviewer can read?
  2. What does the audit log capture, how long is it retained, and can we export it without a support ticket?
  3. How are records covered by 42 CFR Part 2 segmented, and what happens on redisclosure?
  4. What is the documented downtime procedure, and what does read-only access look like during an outage?
  5. Are retention rules configurable by record type and by state?
  6. What documentation does the vendor provide for our risk analysis, and what remains our responsibility?

Question six matters more than it looks. A vendor's own security documentation describes the vendor's environment. The assessment obligation at §164.308(a)(1)(ii)(A) belongs to the covered entity and covers the whole organization.

FAQ

Does HIPAA require a risk analysis every year?

The regulation requires an accurate and thorough assessment and requires review and updates as needed. It does not state a calendar frequency. Annual review is the common practice and is what MIPS attestation asks clinicians to confirm.

Is the 2026 Security Rule in effect?

No. The updated Security Rule is a proposed rule and has not been finalized. Requirements described in the proposal are not current law.

If our EMR vendor is certified, are we compliant?

No. Health IT certification under the ONC program tests the product against defined criteria. It does not assess how your organization configures, uses, or secures the system, and it does not satisfy your risk analysis obligation.

Does an accreditation survey replace a CMS review?

Accreditation by an organization with CMS-approved deeming authority can substitute for routine state survey for the accredited services, but CMS retains authority and can conduct its own review, including complaint investigations.

Do we need to worry about state law if we meet HIPAA?

Usually yes. HIPAA sets a floor. State law that is more protective of individual privacy generally applies in addition.