Identify and list all systems where PHI is stored, processed, or transmitted
Conduct an initial risk assessment to identify vulnerabilities and risks
Design and implement a set of security measures to protect PHI
Document guidelines for data access and user authentications
Create a contingency plan detailing how data restoration will be handled in the case of an emergency
Develop a training program for employees regarding HIPAA regulations and procedures
Restrict the use and disclosure of PHI to the minimum necessary to accomplish the intended purpose
Install updates and patches on all systems handling PHI
Review internal communication procedures to ensure they are secure
Approval: Risk Management Plan
Deploy encryption for electronic PHI both at rest and in transit
Establish firewall protections to safeguard PHI
Implement an audit controls system that records activity in systems containing PHI
Review third-party vendors for compliance
Approval: Third-Party Vendor Compliance
Test backup procedures and periodically test data restoration
Identify a privacy officer who will be responsible for ensuring compliance
Approval: Privacy Officer Assignment
Review and revise the compliance program annually or as needed