Blog · Compliance

What OCR looks for in communication audit trails

Audits are less about perfect software and more about whether you can show who did what, with which patient packet, and why.

People imagine an audit as a technical penetration test. Many reviews start with policies, training records, and a request for activity logs on a specific date range. If your email and forms cannot produce that, the rest of the conversation is uphill.

Have these ready

  • Current user list with roles and last access.
  • BAA for every vendor that touches PHI, including fax and forms.
  • Sample exports of email, fax, and form activity.
  • The incident log, even if it is short.

Build the habit before the letter

HIPAA Companion keeps email, fax, and form activity in one compliance model so a privacy officer can export without opening three vendor portals. Pair the product with a quarterly "pull a sample log" task. That task is the control. The software is the evidence source.

If you still have consumer channels in parallel, say so in the risk analysis and set a retirement date. Hidden channels are what turn a routine review into a findings letter.