HIPAA safeguards · practice operations

HIPAA cybersecurity checklist for NJ practices

A useful checklist does more than mark controls “done.” It records what changed, which safeguard must be reopened, what evidence exists, and who can make the next decision.

Use the recheck board

Educational IT guidance only—not a security risk analysis, legal opinion, compliance certification, or incident-response instruction. Do not send PHI, passwords, access links, account numbers, screenshots, exports, or secret keys.

The operating ruleA change reopens the checklist.

New staff, vendors, devices, systems, locations, failures, and incidents can change the evidence and ownership behind an earlier answer.

Before adding toolsFive questions the practice should be able to answer
Where could ePHI exist?

Systems, devices, messages, vendors, exports, media, and remote access paths.

What proves the control?

A current configuration, inventory, review, test, exception, or activity record.

Who owns the decision?

Practice leadership, security official, technical provider, vendor, or qualified adviser.

What changed since review?

People, roles, products, locations, workflows, threats, failures, or contracts.

Set the boundary

The checklist supports the program. It is not the program.

HHS describes the current HIPAA Security Rule as requiring reasonable and appropriate administrative, physical, and technical safeguards. A practice-side IT checklist can organize questions and evidence, but it cannot establish the full scope, risk analysis, policy choices, legal conclusions, or compliance status.

Use this guide to make technical unknowns visible and route them to the right owner.

Current-rule note: HHS says its Security Rule summary addresses the rule currently in effect and separately identifies proposed modifications. This page does not treat a proposal as a final requirement.

01 · Scope

Find every place the practice creates, receives, maintains, or transmits ePHI.

Include hosted systems, workstations, mobile devices, email, file storage, imaging, printers, scanners, interfaces, exports, backups, and external vendors. HHS risk-analysis guidance says the scope includes all ePHI, regardless of source or location.

02 · Risk

Connect threats and vulnerabilities to practice impact.

A product list is not a risk analysis. The practice needs qualified ownership of likelihood, impact, reasonable safeguards, accepted exceptions, and follow-up decisions.

03 · Control

Translate the decision into technical and operational work.

Examples include access rules, authentication, audit records, supported devices, backup and recovery procedures, vendor access, training, and incident handling.

04 · Evidence

Retain proof that can be retrieved and understood.

Record what was reviewed, when, by whom, against which system or scope, the result, exceptions, next action, and the event that should trigger another review.

The change-trigger index

Reopen the safeguard when the practice changes.

A dated “complete” answer can become unreliable after one operational change. Use these triggers to restart the relevant questions without pretending every practice has the same calendar or risk score.

HealthDesk working methodThe Recheck Board

Log the trigger, affected safeguard, evidence location, decision owner, technical contributor, next action, and follow-up date.

A person or role changes

Reopen

Named access, job-role approval, privileged roles, shared resources, remote access, onboarding, and offboarding.

Retrieve

User roster, role approval, account status, MFA state, admin list, access review, exception, and completion record.

A vendor or contract changes

Reopen

ePHI involvement, BAA decision, access method, named accounts, MFA, support windows, subcontractors, and offboarding.

Retrieve

Vendor register, contract owner, BAA status, approved route, access log where available, expiry, and removal evidence.

A device or system changes

Reopen

Inventory, support status, encryption, endpoint protection, patching, authentication, logs, backup scope, and disposal.

Retrieve

Asset record, configuration state, assigned owner, exception, protection status, backup inclusion, and reuse or disposal record.

A workflow or location changes

Reopen

Where ePHI moves, workstation use, printing, scanning, remote work, wireless access, physical access, and downtime steps.

Retrieve

Workflow owner, data path, location or room record, approved access, test result, staff instruction, and open gap.

A test or control fails

Reopen

Failure scope, affected data or service, last known success, monitoring, restoration path, exception, and escalation.

Retrieve

Alert or test result, protected-source list, restore evidence, incident or problem record, owner, remediation, and retest.

A suspicious event occurs

Reopen

Incident route, containment authority, affected accounts and systems, evidence preservation, insurer, counsel, and vendor contacts.

Retrieve

Event timeline, safe facts, actions taken, decision log, assigned leads, communication record, and documented outcome.

The recheck rule

Do not overwrite the old answer. Preserve the prior evidence, record the trigger, create the next review, and close it only when the accountable owner accepts the result.

Five safeguard reviews

Ask, retrieve, and assign—one area at a time.

These are operational prompts, not universal compliance requirements or proof. The practice’s risk analysis and qualified advisers determine what is reasonable and appropriate for its environment.

01 · IDENTITY

Accounts and access

Email, EHR, billing, imaging, file storage, remote support, vendor portals, and privileged administration.

Ask

Does each person have named, role-appropriate access? Who approves changes and exceptions? Where is MFA used? Are shared and privileged accounts controlled?

Retrieve

Current user and admin lists, role approvals, MFA coverage, stale-account review, delegated access, forwarding rules, and offboarding records.

Route

Practice leadership owns role decisions. HealthDesk can support technical evidence and remediation. For Microsoft identity and email, use Microsoft 365 management.

02 · DAILY SYSTEMS

Devices and data paths

Workstations, laptops, mobile devices, printers, scanners, EHR portals, imaging workstations, and network access.

Ask

Which assets can reach ePHI? Are they supported, assigned, protected, patched, and physically controlled? What leaves the practice or enters through remote work?

Retrieve

Asset inventory, support and patch state, encryption and endpoint status, local-admin exceptions, device ownership, disposal, and network records.

Route

Device and network findings can enter healthcare cybersecurity, network infrastructure, or recurring managed support.

03 · CONTINUITY

Backup and recovery

Hosted systems, file storage, Microsoft 365, imaging, exports, configurations, vendor recovery, and downtime access.

Ask

What is protected, by whom, how often, for how long, and in what order? What does the vendor retain? Who can restore? When was a representative restore tested?

Retrieve

Protected-source list, job results, retention settings, restore-test record, failed jobs, exceptions, recovery order, and responsible contacts.

Route

Use backup and disaster recovery for scoped recovery evidence. Vendor-hosted data and proprietary recovery remain vendor-owned.

04 · THIRD PARTIES

Vendors and remote support

EHR, billing, imaging, labs, portals, phones, printers, cloud services, contractors, and technical support.

Ask

Which vendor creates, receives, maintains, or transmits ePHI? What access exists? Who approved it? Is a BAA decision recorded? How is access reviewed and removed?

Retrieve

Vendor register, data and contract owner, BAA status, access method, named accounts, MFA, approval, expiry, escalation, and offboarding evidence.

Route

Contract, regulatory, and BAA conclusions belong with qualified owners. HealthDesk can clarify technical access and evidence within scope through compliance support.

05 · RESPONSE

Detection and incidents

Suspicious email, account compromise, malware, device loss, unauthorized access, outage, data exposure, or vendor notification.

Ask

How does staff report an event? Who can disable access or isolate systems? Who contacts leadership, counsel, insurer, vendors, or forensics? Where is the record kept?

Retrieve

Contact tree, exercise record, alert source, event timeline, containment authority, safe evidence location, communications, remediation, and closeout.

Route

Routine preparedness belongs in the safeguard plan. A suspected active compromise should use the practice's current provider, insurer, or approved incident-response path, not a routine web checklist.

Keep the ownership boundary visible.

Practice decides

Risk acceptance, workforce action, policy, clinical priorities, vendor approval, and remediation timing.

HealthDesk supports

Technical inventory, settings evidence, gap clarification, remediation records, and scoped vendor coordination.

Vendors supply

Product behavior, hosted controls, proprietary access, retention, recovery, contract facts, and product-side changes.

Advisers interpret

Regulatory applicability, legal duties, breach analysis, contracts, cyber insurance, and formal risk conclusions.

Priority without a fake score

Prioritize the real exposure and practice impact.

A universal red-yellow-green score can hide context. Start with safe facts: what is happening now, which systems or workflows are affected, what evidence exists, and who has authority to act.

Do not infer compliance from completion percentage. Ten easy checks do not cancel one material unknown. Document the basis for each priority and retain the practice decision.

Act now

Possible active exposure or failing critical control

Use an incident or urgent technical route when there is a suspected compromise, unauthorized access, malware, device loss with material concern, critical restore failure, or vendor notice that may affect the practice.

  • Preserve safe facts and the event timeline.
  • Use pre-authorized containment and escalation paths.
  • Do not post PHI, credentials, access links, or sensitive evidence into this form.
First wave

Broad, avoidable exposure with a clear owner

Examples can include stale accounts, incomplete MFA on targeted systems, unclear privileged access, unsupported devices, unknown endpoint coverage, unowned remote tools, or backups without recent representative restore evidence.

  • Confirm scope before changing production systems.
  • Record owner, change approval, result, exception, and retest.
  • Coordinate with product vendors where their system is authoritative.
Plan next

Program improvements that require coordination

Examples can include refreshed risk analysis, policy updates, vendor-contract work, network redesign, device replacement, staff exercises, improved logging, continuity testing, and recurring evidence review.

  • Sequence dependencies and practice decisions.
  • Give every deferred item an owner and recheck trigger.
  • Keep compliance, legal, vendor, and technical scopes distinct.
Choose the correct owner

Route the finding instead of stretching one checklist.

The same observation can require several owners. Keep the practice decision, technical task, vendor fact, and formal interpretation separate.

Technical safeguards and remediationIdentity, endpoints, email, logging, remote access, protection, and technical evidence.Cybersecurity review
Risk, policy, BAA, and readiness processAdministrative ownership, evidence organization, qualified review, and compliance-readiness coordination.Compliance support
Microsoft 365 identity and emailAccounts, MFA, admin roles, forwarding, delegated access, device identity, and tenant operations.Microsoft 365
Backup and recovery evidenceProtected sources, retention, job status, restore testing, recovery order, and vendor boundaries.Backup and recovery
Recurring operationsLifecycle reviews, patching, access changes, monitoring, ticket evidence, vendor coordination, and maintenance.Managed IT services
Visible answers

Answers to common safeguard questions.

Does completing this checklist make a practice HIPAA compliant?

No. It is an educational IT review aid. Compliance depends on the full applicable administrative, physical, technical, organizational, policy, documentation, and risk-management requirements, interpreted for the practice by qualified owners.

What should the practice review first?

Start with the current scope of ePHI, possible active exposure, access to high-impact systems, unsupported or unowned assets, recovery assumptions, and vendors with unclear access. Priorities should follow the practice’s actual risk and operating impact.

How often should safeguards be reviewed?

There is no universal page-level schedule here. HHS says security measures and risks must be reevaluated and documentation updated as needed. Use periodic review plus change triggers such as staff, vendor, device, system, workflow, location, test, or incident changes.

What counts as useful evidence?

Evidence should identify the system and scope, date, reviewer, method, result, exceptions, approvals, owner, next action, and recheck trigger. A screenshot without context or a policy that no longer matches the environment is weak operational evidence.

Is MFA alone enough for HIPAA security?

No. MFA can reduce account risk, but it does not replace access management, risk analysis, device and network controls, audit records, training, vendor oversight, backups, response planning, physical safeguards, or other applicable responsibilities.

Should every vendor have remote access?

No default answer fits every product. Record the business need, product requirement, approved access method, named account where feasible, MFA, timing, monitoring or logging available, decision owner, BAA status where applicable, and removal process.

Primary sources used for this review

Source and freshness boundary

This page was reviewed against the linked primary sources on August 30, 2026. HHS distinguishes the Security Rule currently in effect from separately proposed modifications. HHS risk-analysis guidance also says it does not prescribe a single method for every organization.

The sources do not endorse HealthDesk IT, establish this checklist as a compliance standard, set a universal priority score, authorize access or remediation, or replace current law, contracts, insurer instructions, product requirements, or practice-specific professional advice.

HIPAA IT safeguard review

Turn technical unknowns into owned next actions.

HealthDesk IT can help an NJ medical practice inventory technical safeguards, retrieve practical evidence, clarify vendor boundaries, and sequence remediation around daily systems.

  • Call: 732-362-4949
  • Useful context: practice location count, staff size, core systems, Microsoft 365, broad device and vendor types, backup scope, and the decision currently blocked
  • Do not send: PHI, patient details, passwords, account numbers, access links, credentials, network diagrams, screenshots, configuration exports, or secret keys

Email or phone is required. Submission does not create a client relationship, establish compliance, guarantee outcomes, or authorize access, investigation, containment, configuration changes, or contact with third parties.