RRA
Healthcare Cybersecurity
HIPAA Security Rule Compliance Checklist
A practical starting checklist for reviewing administrative, physical and technical safeguards that protect electronic protected health information.
Designed for: Healthcare providers, practice managers, compliance officers and IT teams
RRA Tech Zone LLC · Proprietary educational resource · Version 1.0 · September 2026
Administrative safeguards
- Assign a named security official and document responsibilities.
- Complete and document an accurate, thorough risk analysis.
- Create a risk-management plan with owners, priorities and target dates.
- Review workforce access when roles change and when employment ends.
- Train personnel on security responsibilities and incident reporting.
- Maintain tested contingency, backup and emergency-operation procedures.
Physical safeguards
- Control and document physical access to systems and facilities.
- Define workstation-use and workstation-security expectations.
- Track devices and media that create, receive, maintain or transmit ePHI.
- Use secure disposal and media-reuse procedures.
- Maintain an inventory of systems, devices and storage media.
Technical safeguards
- Use unique user identification and appropriate authentication.
- Apply least-privilege access based on job responsibilities.
- Enable audit logging and review security-relevant activity.
- Protect ePHI integrity in storage and transmission.
- Use encryption when reasonable and appropriate, documenting decisions.
- Establish procedures for emergency access and automatic logoff.
Evidence to retain
- Risk analysis and risk-treatment records
- Policies, procedures and approval history
- Training, access-review and termination records
- Incident, breach and corrective-action documentation
- Backup, restoration and contingency-test evidence
- Business associate agreements and vendor reviews
Recommended next steps
- 1Identify the person accountable for the review.
- 2Mark each checklist item Complete, Partial, Not Started or Not Applicable.
- 3Attach evidence instead of relying on verbal confirmation.
- 4Prioritize high-impact gaps involving access, backups, vulnerabilities and incident response.
- 5Review progress at least quarterly and after material changes.