Burke, VA September 22, 2026 --(PR.com)-- Colington Consulting, a Virginia-based firm specializing in HIPAA compliance, today announced the launch of its OCR Audit Protocol Readiness Assessment, a good way to pressure test an existing HIPAA compliance program by measuring it against the U.S. Department of Health and Human Services Office for Civil Rights' (OCR) own published HIPAA Audit Program Protocol.
Most healthcare organizations can point to a Security Risk Assessment, a set of policies, and a training log, satisfying the letter of HIPAA's requirements. But OCR doesn't audit against an organization's own policies. It audits against its own protocol: a provision-by-provision standard covering the Privacy, Security, and Breach Notification Rules, complete with the specific evidence auditors are trained to request and the criteria they use to judge it. Until a compliance program has been measured against that standard, an organization knows its program exists; not whether it would hold up.
“There's a real difference between ‘we believe we're compliant’ and ‘an independent reviewer verified it against the federal standard, with the documentation to show it,’” said Jay Hodes, President & Founder of Colington Consulting. “Our assessment is built from OCR's actual protocol, the same CFR citations, performance criteria, and audit inquiries OCR auditors are trained to apply. It's not a third-party interpretation, and it's not self-scored.”
How the Assessment Works
The OCR Audit Protocol Readiness Assessment follows a three-step process:
● Evidence Request, in which the organization receives a structured list of the specific documents OCR itself would request, organized to match the protocol.
● Evaluator Review, in which a named, credentialed evaluator reviews the submitted evidence against OCR's established performance criteria for each provision and makes a compliance determination.
● Documented Findings, in which every determination is recorded with supporting narrative, producing a report structured closely enough to OCR's own protocol to serve as evidence of a good faith readiness review.
The result is a defensible record rather than a marketing claim. Colington Consulting notes there is no such thing as an official “HIPAA certification,” and the assessment is not positioned as one; it instead provides documented, evidence-backed proof of where an organization's program stood against the federal standard at a given point in time.
Who Benefits Most
Colington Consulting designed the assessment for organizations where the cost of an OCR finding, financial, reputational, or contractual, makes “probably fine” an insufficient standard, including:
● Health systems and larger provider groups with multiple locations and higher breach exposure
● Self-insured health plans, an area of current OCR enforcement focus on risk analysis rigor and Business Associate oversight
● Hybrid entities, where the line between covered and noncovered functions creates structural risk
● Organizations entering a renewal cycle, an M&A transaction, or a payer credentialing review
● Any organization that has completed a Security Risk Assessment and wants to know what the next level of readiness looks like
About Colington Consulting
Colington Consulting helps organizations achieve HIPAA compliance through evidence-based assessments built directly from federal audit standards. The firm's OCR Audit Protocol Readiness Assessment evaluates covered entities and business associates against OCR's own HIPAA Audit Program Protocol, producing a documented, defensible record of where a compliance program stands.
Media Contact:
Jay Hodes
President & Founder
Colington Consulting
844-740-7100
info@cchipaa.com
cchipaa.com
Contact Information:
Colington Consulting
Jay Hodes
844-740-7100
Contact via Email
cchipaa.com
Read the full story here: https://www.pr.com/press-release/979691
Press Release Distributed by PR.com
