{"id":21528,"date":"2020-02-07T12:46:02","date_gmt":"2020-02-07T12:46:02","guid":{"rendered":"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist\/"},"modified":"2024-02-29T01:19:52","modified_gmt":"2024-02-29T01:19:52","slug":"hipaa-compliance-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist\/","title":{"rendered":"HIPAA Compliance Checklist"},"content":{"rendered":"<section id=\"introduction\">\n<h2>Introduction:<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/tbEnujg-Eob6OVh8x-hC9g.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/tbEnujg-Eob6OVh8x-hC9g.png\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>HIPAA fines cost ten companies&nbsp;<a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/agreements\/2018enforcement\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">$28.7 million in 2018<\/a>, which broke the previous 2016 record for HIPAA fines by 22%!&nbsp;Needless to say, you don't want to have to worry about a HIPAA complaint being filed against your organization, and by going through this straight forward checklist, you can <strong>ensure full compliance<\/strong>.&nbsp;<\/p>\n<p>The <strong>primary purpose<\/strong> of the HIPAA is simply to <strong>keep people's healthcare data private<\/strong>. If your healthcare organization is an entity that uses and has access to Protected Health Information (PHI), then you are classified as a <strong>Covered Entity (CE)<\/strong>&nbsp;and need to make sure you are compliant with HIPAA regulations.&nbsp;<\/p>\n<p>There are <strong>three critical components<\/strong> to PHI security:<\/p>\n<ul>\n<li>Technical safeguards<\/li>\n<li>Physical safeguards<\/li>\n<li>Administrative safeguards<\/li>\n<\/ul>\n<p>Each part is equally important and must be satisfied to ensure HIPAA compliance.&nbsp;<\/p>\n<p class=\"style-info\">You will notice that next to each task there is <strong>either an (R) or an (A).&nbsp;<\/strong>R stands for <strong>\"Required\"<\/strong>, and A is <strong>\"Addressable\"<\/strong>, however, this does not mean that they are optional. Each of the criteria has to be adhered to in order to achieve full HIPAA compliance.<\/p>\n<p class=\"style-warning\">While going through the checklist, bear in mind that the <strong>requirements of HIPAA are intentionally vague<\/strong> so that it can be applied equally to different types of covered entities that come into contact with PHI.<\/p>\n<p class=\"style-info\">For more information on the ins and outs of HIPAA compliance, <a href=\"https:\/\/www.varonis.com\/blog\/hipaa-compliance\/\" rel=\"nofollow noopener\" target=\"_blank\">check out this comprehensive guide<\/a>.&nbsp;You can also <strong>watch the video below<\/strong> for an overview of what is required for HIPAA compliance<\/p>\n<p>In case you're wondering what <a href=\"https:\/\/www.process.st\/\" rel=\"nofollow noopener\" target=\"_blank\">Process Street<\/a> is all about...<\/p>\n<p>Process Street is <strong>superpowered checklists<\/strong>. By using our software to document your processes, you are instantly creating an actionable workflow in which tasks can be assigned to team members, automated, and monitored in real-time to ensure they are being executed as intended, each and every time.<\/p>\n<p>The point is to <strong>minimize human error, increase accountability<\/strong>, and <strong>provide employees with all of the tools and information necessary<\/strong> to complete their tasks as effectively as possible.<\/p>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/s9znUYvVO4A?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"technical-safeguards\">\n<h2>Technical safeguards:<\/h2>\n<\/section>\n<section id=\"implement-a-means-of-access-control-r\">\n<h2>Implement a means of access control (R)<\/h2>\n<div class=\"text-content\">\n<p>Establishing and implementing a means of <strong>access control for each user<\/strong> of company software is an essential technical safeguard.&nbsp;<\/p>\n<p>This not only means assigning a <strong>centrally-controlled unique username and PIN code<\/strong> for each user, but also <strong>establishing procedures to govern the release or disclosure of ePHI<\/strong> during an emergency.<\/p>\n<p>State below whether your organization is compliant with this requirement.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Access control for each user <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-info\"><strong>Restrict access to ePHI via permissions<\/strong> after you have identified the who should have access.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"introduce-activity-logs-and-audit-controls-r\">\n<h2>Introduce activity logs and audit controls (R)<\/h2>\n<div class=\"text-content\">\n<p><strong>All attempts to access ePHI must be registered<\/strong> and whatever is done with that data once it has been accessed must be recorded so that if needs be, it can be reviewed at a later date.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Activity logs and audit controls <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-warning\">In the case of a <strong>data breach<\/strong>, CEs need to provide a <strong>complete audit trail<\/strong> and show exactly how the breach occurred. <strong>A<\/strong><strong>lerts and security analytics should be set up<\/strong> so that you can <strong>prevent breaches<\/strong> in the first place.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"introduce-a-mechanism-to-authenticate-ephi-a\">\n<h2>Introduce a mechanism to authenticate ePHI (A)<\/h2>\n<div class=\"text-content\">\n<p>Introducing a mechanism to authenticate ePHI is an essential component as it <strong>confirms whether ePHI has been altered or destroyed in an unauthorized manner.<\/strong>&nbsp;<\/p>\n<p>To be HIPAA compliant, CEs need to be able to prove that the ePHI they manage is <strong>protected from threats both inside and out.<\/strong> Whether a member of staff accidentally deleted a record or a hacker deleted it intentionally, you <strong>should be able to recover and restore that record<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Mechanism to authenticate ePHI <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"implement-tools-for-encryption-and-decryption-a\">\n<h2>Implement tools for encryption and decryption (A)<\/h2>\n<div class=\"text-content\">\n<p>Any device used by authorized users to access ePHI must have the <strong>functionality to encrypt messages<\/strong> when they are sent beyond an internal firewalled server, and in turn, <strong>decrypt those messages when they are received.&nbsp;<\/strong><\/p>\n<p>In short, you need to be able to <strong>prove that only authorized individuals accessed the ePHI.&nbsp;<\/strong><\/p>\n<p class=\"style-info\">As an example, you can use an <strong>encrypted email with a private key, HTTPS file transfer, or a VPN.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Tools for encryption and decryption <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"facilitate-automatic-logoffs-of-pcs-and-devices-a\">\n<h2>Facilitate automatic log-offs of PCs and devices (A)<\/h2>\n<div class=\"text-content\">\n<p>This simple function&nbsp;<strong>logs authorized personnel off<\/strong> the device they are using to access or communicate ePHI <strong>after a pre-defined period of time. <\/strong><\/p>\n<p>This <strong>prevents unauthorized access of ePHI should the device be left unattended.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Automatic log-offs of PCs and other devices <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"verify-technical-safeguards-are-in-place\">\n<h2>Verify technical safeguards are in place<\/h2>\n<div class=\"text-content\">\n<p>Once this checklist has been completed, it will require <strong>approval<\/strong> from a senior person, such as your<strong> IT Security Officer<\/strong>.&nbsp;<\/p>\n<p>If you have any comments regarding the status of technical safeguards at your organization, state them below so they can be <strong>reviewed during the approval process.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Comments on status of technical safeguards <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"physical-safeguards\">\n<h2>Physical safeguards:<\/h2>\n<\/section>\n<section id=\"implement-policies-for-the-usepositioning-of-workstations-r\">\n<h2>Implement policies for the use\/positioning of workstations (R)<\/h2>\n<div class=\"text-content\">\n<p><strong>Desktops, laptops, and tablets<\/strong> that are used by staff to access ePHI must be <strong>securely managed. <\/strong><em>Every<\/em> computer with access to ePHI must adhere to this policy.<strong><\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Physical safeguards for all computers that access ePHI\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Restricted access to computers that access ePHI\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Remote wipe safeguards on laptops that are frequently moved\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Policies in place for the use\/positioning of workstations <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"implement-policies-and-procedures-for-mobile-devices-r\">\n<h2>Implement policies and procedures for mobile devices (R)<\/h2>\n<div class=\"text-content\">\n<p>If users are allowed to access ePHI from their mobile devices, policies must be devised and implemented to govern <strong>how ePHI is removed from the devices if the user leaves the organization or the device is re-used, sold<\/strong>, <strong>etc.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Policies and procedures for mobile devices <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"implement-facility-access-controls-a\">\n<h2>Implement facility access controls (A)<\/h2>\n<div class=\"text-content\">\n<p>Limit and audit physical access to the computers that store and process ePHI. <\/p>\n<p class=\"style-info\">A simple and easy way to do is <strong>put a lock on the server room door<\/strong>. This will prevent unauthorized physical access, tampering, and theft.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Facility access controls <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"establish-and-maintain-an-inventory-of-hardware-a\">\n<h2>Establish and maintain an inventory of hardware (A)<\/h2>\n<div class=\"text-content\">\n<p>An inventory of all hardware must be maintained, together with a <strong>record of the movements<\/strong> of each item. In addition to computers, this <strong>includes media such as USB drives, tape backups<\/strong> and <strong>removable storage<\/strong>.<\/p>\n<p class=\"style-warning\">A <strong>retrievable exact copy of ePHI must be made<\/strong> before any equipment is moved.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Inventory of hardware <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"verify-physical-safeguards-are-in-place\">\n<h2>Verify physical safeguards are in place<\/h2>\n<div class=\"text-content\">\n<p>If you have any comments regarding the status of physical safeguards at your organization, state them below so they can be <strong>reviewed during the approval process.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Comments on status of physical safeguards <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"administrative-safeguards\">\n<h2>Administrative safeguards:<\/h2>\n<\/section>\n<section id=\"conduct-ephi-risk-assessments-r\">\n<h2>Conduct ePHI risk assessments (R)<\/h2>\n<div class=\"text-content\">\n<p>The Security Officer designated to managing HIPAA compliance is responsible for conducting regular risk assessments to <strong>identify every area in which ePHI is being used<\/strong>, and to <strong>determine all of the ways in which a security breach could occur.<\/strong><\/p>\n<p>Below is a graphic <strong>summarising the process<\/strong> of conducting a comprehensive risk assessment.<\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/pBpcJaTmISh0C3QMsDtHIQ.jpg\" alt=\"Source: https:\/\/www.varonis.com\/blog\/hipaa-compliance\/\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/pBpcJaTmISh0C3QMsDtHIQ.jpg\"> <\/a><figcaption>\n     Source: https:\/\/www.varonis.com\/blog\/hipaa-compliance\/<br \/>\n   <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Conducting ePHI risk assessments <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"introduce-a-risk-management-policy-r\">\n<h2>Introduce a risk management policy (R)<\/h2>\n<div class=\"text-content\">\n<p>CEs must establish policies and procedures to <strong>prevent, detect, contain, and correct security violations.<\/strong> Part of this process is to follow the procedures stated in the Risk Management Policy to assess overall risk in your current processes or when you implement new policies.<\/p>\n<p class=\"style-info\">The <strong>primary purpose<\/strong> of a risk management policy is to periodically <strong>reduce the risks of a security breach<\/strong> by introducing security measures following a risk assessment. This should take place at regular intervals.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Risk management policy <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"restrict-thirdparty-access-to-ephi-r\">\n<h2>Restrict third-party access to ePHI (R)<\/h2>\n<div class=\"text-content\">\n<p>It goes without saying that it is vital to ensure ePHI is<strong> not accessed by unauthorized parent organizations, subcontractors, or other third-parties.<\/strong><\/p>\n<p class=\"style-info\">In the case that a business partner will be granted access to ePHI, a<strong> Business Associate Agreement <\/strong>must be signed.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Restricted third-party access to ePHI <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"develop-a-contingency-plan-r\">\n<h2>Develop a contingency plan (R)<\/h2>\n<div class=\"text-content\">\n<p>In the case of an <strong>emergency<\/strong>, a contingency plan must be ready to <strong>enable the continuation of critical business processes<\/strong> while <strong>protecting the integrity of ePHI.<\/strong><\/p>\n<p>You must have a:<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Data backup plan\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Disaster recovery plan\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Emergency mode operation plan\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Contingency plan in place <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"test-the-contingency-plan-periodically-a\">\n<h2>Test the contingency plan periodically (A)<\/h2>\n<div class=\"text-content\">\n<p>Of course, in the case of an emergency, <strong>effective execution of the contingency plan is paramount.&nbsp;<\/strong><\/p>\n<p>Therefore it is important to test the contingency plan periodically to <strong>assess its effectiveness<\/strong> in various situations.<\/p>\n<p class=\"style-info\">The most important thing to verify during testing is that there are <strong>accessible backups of ePHI<\/strong> and <strong>procedures in place to restore lost data<\/strong> in the event of an emergency<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Contingency plan tested periodically <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"formally-train-employees-to-be-secure-a\">\n<h2>Formally train employees to be secure (A)<\/h2>\n<div class=\"text-content\">\n<p>CEs must provide <strong>workforce training and management for security policies<\/strong> in order to be HIPAA compliant.&nbsp;<\/p>\n<p>Training schedules must be introduced to <strong>raise awareness of the policies and procedures governing access to ePHI<\/strong> and how to <strong>identify malicious software attacks<\/strong> and malware.<\/p>\n<p class=\"style-warning\"><strong>All training must be documented.<\/strong>\u2003<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Employee training <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"develop-a-formal-procedure-to-report-security-incidents-a\">\n<h2>Develop a formal procedure to report security incidents (A)<\/h2>\n<div class=\"text-content\">\n<p>A security <strong>incident<\/strong> does <strong>not<\/strong> necessarily mean a <strong>breach.&nbsp;<\/strong>If there is any indication that ePHI is under security threat, there needs to be a <strong>formal procedure<\/strong> in place to report such incidents and <strong>address the issue as soon as possible<\/strong>.<\/p>\n<p class=\"style-info\">As mentioned earlier, <strong>alerts and security analytics should be set up<\/strong> so that you can prevent breaches in the first place.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Procedure to report security incidents <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"verify-administrative-safeguards-are-in-place\">\n<h2>Verify administrative safeguards are in place<\/h2>\n<div class=\"text-content\">\n<p>If you have any comments regarding the status of administrative safeguards at your organization, state them below so they can be <strong>reviewed during the approval process.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Comments on status of administrative safeguards <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"final-step\">\n<h2>Final step:<\/h2>\n<\/section>\n<section id=\"approval-confirm-standards-for-all-three-safeguards-are-being-met\">\n<h2>Approval: Confirm standards for all three safeguards are being met<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\">\n        <span class=\"title\">Verify technical safeguards are in place<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\">\n        <span class=\"title\">Verify administrative safeguards are in place<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\">\n        <span class=\"title\">Verify physical safeguards are in place<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.varonis.com\/blog\/hipaa-compliance\/\" rel=\"nofollow noopener\" target=\"_blank\">Varonis - What is HIPAA Compliance? Your 2019 Guide + Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.hipaajournal.com\/hipaa-compliance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Journal - HIPAA Compliance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/public-library.safetyculture.io\/products\/hipaa-compliance-checklist?src=sc&amp;amp_dev=3cda9a4d-ee27-49bf-ae59-a39531ac0e3bR\" rel=\"nofollow noopener\" target=\"_blank\">Safety Culture - HIPAA Compliance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/phoenixnap.com\/blog\/hipaa-compliance-checklist\" rel=\"nofollow noopener\" target=\"_blank\">PhoenixNAP - HIPAA Compliance Checklist: How Do I Become Compliant?<\/a><\/li>\n<li><a href=\"https:\/\/www.atlantic.net\/hipaa-compliant-hosting\/hipaa-compliance-guide-what-is-hipaa\/\" rel=\"nofollow noopener\" target=\"_blank\">Atlantic -&nbsp;HIPAA Compliance Guide &amp; Checklist: What Is HIPAA?<\/a><\/li>\n<li><a href=\"https:\/\/compliancy-group.com\/what-is-hipaa-compliance\/\" rel=\"nofollow noopener\" target=\"_blank\">Compliancy Group - What is HIPAA Compliance?<\/a><\/li>\n<li><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/security\/laws-regulations\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">U.S. Department of Health &amp; Human Services - Summary of the HIPAA Security Rule<\/a><\/li>\n<li><a href=\"https:\/\/www.otava.com\/reference\/what-is-hipaa-compliance\/\" rel=\"nofollow noopener\" target=\"_blank\">Otava - What is HIPAA Compliance?<\/a><\/li>\n<li><a href=\"https:\/\/digitalguardian.com\/blog\/what-hipaa-compliance\" rel=\"nofollow noopener\" target=\"_blank\">Digital Guardian - What is HIPAA Compliance?<\/a><\/li>\n<\/ul>\n<\/p><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2>Related checklists:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-housekeeping-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Housekeeping Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/terminal-room-cleaning-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Terminal Room Cleaning Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-safety-inspection-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Safety Inspection Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/patient-satisfaction-survey-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/home-visit-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Home Visit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/mental-health-risk-assessment-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Mental Health Risk Assessment Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/who-surgical-safety-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">WHO Surgical Safety Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/general-infection-control-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">General Infection Control Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/patient-intake-checklist-for-a-medical-clinic\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Medical Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/electrical-inspection-checklist-hospitals-and-health-care\/\" rel=\"nofollow noopener\" target=\"_blank\">Electrical Inspection Checklist for Hospitals<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: HIPAA fines cost ten companies&nbsp;$28.7 million in 2018, which broke the previous 2016 record for HIPAA fines by 22%!&nbsp;Needless to say, you don't want to have to worry about a HIPAA complaint being filed against your organization, and by going through this straight forward checklist, you can ensure full compliance.&nbsp; The primary purpose of [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":21529,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"27","template_description":"Run this checklist to determine how compliant your institution is with HIPAA provisions","template_id":"o2kAgT07dNFO7Q9dYwtPMQ","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Technical safeguards:","task_slug_1":"technical-safeguards","task_2":"Implement a means of access control (R)","task_slug_2":"implement-a-means-of-access-control-r","task_3":"Introduce activity logs and audit controls (R)","task_slug_3":"introduce-activity-logs-and-audit-controls-r","task_4":"Introduce a mechanism to authenticate ePHI (A)","task_slug_4":"introduce-a-mechanism-to-authenticate-ephi-a","task_5":"Implement tools for encryption and decryption (A)","task_slug_5":"implement-tools-for-encryption-and-decryption-a","task_6":"Facilitate automatic log-offs of PCs and devices (A)","task_slug_6":"facilitate-automatic-logoffs-of-pcs-and-devices-a","task_7":"Verify technical safeguards are in place","task_slug_7":"verify-technical-safeguards-are-in-place","task_8":"Physical safeguards:","task_slug_8":"physical-safeguards","task_9":"Implement policies for the use\/positioning of workstations (R)","task_slug_9":"implement-policies-for-the-usepositioning-of-workstations-r","task_10":"Implement policies and procedures for mobile devices (R)","task_slug_10":"implement-policies-and-procedures-for-mobile-devices-r","task_11":"Implement facility access controls (A)","task_slug_11":"implement-facility-access-controls-a","task_12":"Establish and maintain an inventory of hardware (A)","task_slug_12":"establish-and-maintain-an-inventory-of-hardware-a","task_13":"Verify physical safeguards are in place","task_slug_13":"verify-physical-safeguards-are-in-place","task_14":"Administrative safeguards:","task_slug_14":"administrative-safeguards","task_15":"Conduct ePHI risk assessments (R)","task_slug_15":"conduct-ephi-risk-assessments-r","task_16":"Introduce a risk management policy (R)","task_slug_16":"introduce-a-risk-management-policy-r","task_17":"Restrict third-party access to ePHI (R)","task_slug_17":"restrict-thirdparty-access-to-ephi-r","task_18":"Develop a contingency plan (R)","task_slug_18":"develop-a-contingency-plan-r","task_19":"Test the contingency plan periodically (A)","task_slug_19":"test-the-contingency-plan-periodically-a","task_20":"Formally train employees to be secure (A)","task_slug_20":"formally-train-employees-to-be-secure-a","task_21":"Develop a formal procedure to report security incidents (A)","task_slug_21":"develop-a-formal-procedure-to-report-security-incidents-a","task_22":"Verify administrative safeguards are in place","task_slug_22":"verify-administrative-safeguards-are-in-place","task_23":"Final step:","task_slug_23":"final-step","task_24":"Approval: Confirm standards for all three safeguards are being met","task_slug_24":"approval-confirm-standards-for-all-three-safeguards-are-being-met","task_25":"Sources:","task_slug_25":"sources","task_26":"Related checklists:","task_slug_26":"related-checklists","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[55],"tags":[],"class_list":["post-21528","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-corporate-social-responsibility"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/21528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=21528"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/21528\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/21529"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=21528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=21528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=21528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}