Templates
Healthcare
HIPAA Privacy Risk Assessment Checklist

HIPAA Privacy Risk Assessment Checklist

Run this checklist to conduct a comprehensive evaluation of your compliance with the HIPAA Privacy Rule
1
Introduction:
2
Enter basic details
3
Check-in procedures:
4
Ensure assistance is provided for new patient form completion
5
Ensure patient insurance is verified
6
Ensure patients sign the Notice of Privacy Practices Acknowledgement
7
Evaluate process for sending appointment reminders
8
Evaluate identity verification procedure upon patient arrival
9
Approval: Check-in procedures
10
Clinical areas:
11
Evaluate if staff discuss patient information in clinical areas
12
Assess if phone calls are made mentioning patient information
13
Ensure exam room doors are shut during patient encounters
14
Ensure lab and X-ray logs are covered to protect PHI
15
Ensure no PHI is visible in clinical workstations while unattended
16
Ensure PHI shred bins are emptied and not overfilled
17
Approval: Clinical areas
18
Medical records:
19
Verify only appropriate staff can access medical records
20
Assess physical security of medical records
21
Ensure patient authorization is received before release of PHI
22
Ensure authorizations are filed in patients medical record
23
Ensure PHI can be destroyed after the retention period
24
Approval: Medical records
25
General security:
26
Ensure computer monitors are positioned appropriately
27
Ensure unattended computers are properly secured
28
Ensure paper records are stored appropriately
29
Approval: General security
30
Personnel policies:
31
Ensure HIPAA privacy policies are in the employee handbook
32
Ensure employees receive privacy training
33
Ensure training is documented
34
Approval: Personnel policies
35
Final evaluation:
36
Summarize the privacy risk analysis
37
Approval: General risk analysis completed
38
Sources:
39
Related checklists: