Healthcare Facility Compliance 15 items
HIPAA Privacy & Security Rule Compliance Audit
Compliance audit of protected health information (PHI) privacy and security safeguards for a covered entity under the HIPAA Privacy, Security, and Breach Notification Rules.
HIPAA Privacy Rule 45 CFR 164 Subpart EHIPAA Security Rule 45 CFR 164 Subpart CHITECH Breach Notification
Free PDF · enter your email to download.
Privacy Rule - Notice & Uses
- Is a Notice of Privacy Practices provided to patients and posted/available? *
- Are uses and disclosures of PHI limited to the minimum necessary for the purpose? *
- Are authorizations obtained for uses/disclosures not otherwise permitted (e.g., marketing, sale of PHI)? *
- Are patients able to exercise access, amendment, and accounting-of-disclosures rights? *
Administrative Safeguards
- Has a security risk analysis of ePHI been conducted and documented, and is it periodically updated? *
- Is a designated Privacy Officer and Security Official assigned? *
- Is workforce security awareness and HIPAA training conducted and documented? *
- Are Business Associate Agreements in place with vendors that handle PHI? *
Technical & Physical Safeguards
- Is access to ePHI controlled with unique user IDs and role-based access? *
- Is ePHI encrypted at rest and in transit where reasonable and appropriate? *
- Are audit controls in place to record and examine access to systems containing ePHI? *
- Are physical safeguards (facility access, workstation security, device/media controls) implemented? *
Breach Notification & Incident Response
- Is there a documented process to identify, respond to, and mitigate security incidents? *
- Are breaches of unsecured PHI assessed and reported to individuals and HHS within required timeframes? *
- Is a contingency plan (data backup, disaster recovery, emergency mode operation) established and tested? *
Download the full HIPAA Privacy & Security Rule Compliance Audit checklist
Get it as a clean, printable PDF — free.
