Cybersecurity GRC 15 items
HIPAA Security Rule Compliance Checklist
Evaluates administrative, physical, and technical safeguards required to protect electronic protected health information (ePHI) under the HIPAA Security Rule.
HIPAA Security Rule45 CFR Part 164
Free PDF · enter your email to download.
Administrative Safeguards
- Is an accurate and thorough risk analysis of ePHI conducted and documented? *
- Is a risk management process in place to reduce risks to a reasonable level? *
- Is a designated security official responsible for the security program? *
- Is a security awareness and training program provided to the workforce? *
- Are security incident response and reporting procedures established? *
Physical Safeguards
- Are facility access controls implemented to limit physical access to systems housing ePHI? *
- Are workstation use and security policies defined? *
- Are device and media controls in place for disposal, reuse, and movement of ePHI media? *
Technical Safeguards
- Are access controls implemented with unique user identification for ePHI systems? *
- Are audit controls implemented to record and examine activity in ePHI systems? *
- Are integrity controls in place to protect ePHI from improper alteration or destruction? *
- Is encryption implemented for ePHI at rest and in transit (addressable)? *
Organizational & Documentation
- Are Business Associate Agreements (BAAs) executed with all applicable vendors? *
- Are policies and procedures documented and retained for six years? *
- Is a breach notification process defined per the Breach Notification Rule? *
Download the full HIPAA Security Rule Compliance Checklist checklist
Get it as a clean, printable PDF — free.
