24 Questions: The HIPAA world is abuzz today (sorry, I was on a plane today, so I'm just now getting to it) with rumors of a leaked document from the government in the Piedmont Hospital case in Georgia. Allegedly, the document contains 24 questions from the government addressed to Piedmont, making up the central core of OCR's audit. It would be a very, very good idea to look at these questions, which primarily involve requests for proof of policies and procedures in place for some pretty standard HIPAA security matters. If your organization wouldn't be able to quickly and fully respond to these questions, you got some work to do. Not just for HIPAA purposes; some of these are good general information security requirements.

