The Department of Health and Human Services (HHS) through its Office for Civil Rights (OCR) has begun a pilot audit program aimed at covered entities (and soon, business associates) regarding compliance with the HIPAA privacy / security / breach notification requirements.