HIPAA Tip: HIPAA Checklist – Volume 1
The following HIPAA Checklists (more to come!) are intended to serve as reminders and quick references. Additionally, these lists are HIPAA requirements and not to be ignored.
- Audit active users in all systems and applications containing ePHI
- Review users’ roles and privileges in systems and applications to ensure least privileged access/minimum necessary
- Check to see who has administrative rights and escalated privileges for systems and applications (domain/global administrator) and whether this is necessary or no longer needed
- Build recovery and breach resilience plan and add to the existing Disaster Recovery Plan
- Conduct Cybersecurity Awareness training right away for all staff, doctors, temps and per diems, even if they insist they have completed this already. Training needs to be ongoing (and documented): three or four times per year
- If the organization is using a new solution or device that will contain ePHI or interface with the EMR/PM software, ensure a Business Associate Agreement (BAA) has been signed by both parties. Store all BAAs in one location/folder that is part of the daily backups for the business.
Do the work and check off the boxes – Volume 2 is coming soon.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.