@Dashrender said:
Although I don't believe you are completely out of the woods just because you have a business Agreement (BA) with a provider you use that is housing Personal Health Information (PHI) - in fact I'm pretty sure that I'm suppose to request a result of their own audit to ensure they are doing what they are suppose to be doing.. only after collecting that yearly (though how I'm suppose to know it's valid is beyond me) would I be close to be indemnified.
That's possible, back when I was doing HIPAA all the time that was not the case but it does get updated regularly.
Knowing that it is valid is likely none of your concern. You can't know that audits are valid more or less by definition. You'd need the auditor to be audited and that auditor audited and so on and so forth.