RRA Tech Zone
Skip to content
Resource Vault
RRA

Healthcare Cybersecurity

HIPAA Security Rule Compliance Checklist

A practical starting checklist for reviewing administrative, physical and technical safeguards that protect electronic protected health information.

Designed for: Healthcare providers, practice managers, compliance officers and IT teams

RRA Tech Zone LLC · Proprietary educational resource · Version 1.0 · September 2026

Administrative safeguards

  • Assign a named security official and document responsibilities.
  • Complete and document an accurate, thorough risk analysis.
  • Create a risk-management plan with owners, priorities and target dates.
  • Review workforce access when roles change and when employment ends.
  • Train personnel on security responsibilities and incident reporting.
  • Maintain tested contingency, backup and emergency-operation procedures.

Physical safeguards

  • Control and document physical access to systems and facilities.
  • Define workstation-use and workstation-security expectations.
  • Track devices and media that create, receive, maintain or transmit ePHI.
  • Use secure disposal and media-reuse procedures.
  • Maintain an inventory of systems, devices and storage media.

Technical safeguards

  • Use unique user identification and appropriate authentication.
  • Apply least-privilege access based on job responsibilities.
  • Enable audit logging and review security-relevant activity.
  • Protect ePHI integrity in storage and transmission.
  • Use encryption when reasonable and appropriate, documenting decisions.
  • Establish procedures for emergency access and automatic logoff.

Evidence to retain

  • Risk analysis and risk-treatment records
  • Policies, procedures and approval history
  • Training, access-review and termination records
  • Incident, breach and corrective-action documentation
  • Backup, restoration and contingency-test evidence
  • Business associate agreements and vendor reviews

Recommended next steps

  1. 1Identify the person accountable for the review.
  2. 2Mark each checklist item Complete, Partial, Not Started or Not Applicable.
  3. 3Attach evidence instead of relying on verbal confirmation.
  4. 4Prioritize high-impact gaps involving access, backups, vulnerabilities and incident response.
  5. 5Review progress at least quarterly and after material changes.