164.530(d)
Complaints.
All covered entities must provide a process for individuals to complain about its compliance with the Breach Notification Rule.

Audit Inquiry

164.530(d) – Complaints to the covered entity
Does the covered entity have a process in place for individuals to complain about its compliance with the Breach Notification Rule? Obtain the covered entity’s policies and procedures for individual complaints. Evaluate whether they are consistent with the requirement to provide a process for individuals to complain about the covered entity’s compliance with the Breach Notification Rule.

Has the covered entity received any such complaints? If yes, obtain and review a list of complaints received in the specified period and the disposition of such complaints. Obtain and assess additional documentation of actions taken by the covered entity to investigate and resolve the complaints. Assess whether the actions were completed in accordance with these requirements and the entity’s policies and procedures.