A working checklist organised by rule and safeguard category, with the required-versus-addressable distinction made explicit.
How to use this checklist
Two ground rules before the list. First, required versus addressable: the Security Rule marks each implementation specification one way or the other, and addressable does not mean optional — it means implement it, implement a documented equivalent, or document why neither is reasonable and appropriate. Second, a ticked box is a claim, and claims need evidence. For every item below, the working question is not “do we do this?” but “could we show a stranger that we do this?” If the answer requires finding a person rather than a document, count the item as open.
Work top to bottom. The administrative items come first deliberately — they generate the decisions the physical and technical items implement.
Administrative safeguards
Security management process, assigned security responsibility, workforce security, information access management, security awareness and training, security incident procedures, contingency plan, evaluation, and business associate contracts.
Expanded, from §164.308:
- A current, documented risk analysis covering all systems that touch ePHI — not just the EHR
- A risk management plan showing what you are doing about the identified risks, with owners and dates
- A written sanction policy, applied and recorded when applied
- Regular review of system activity — audit logs, access reports, incident records
- A named Security Officer, designated in writing
- Joiner, mover, and leaver procedures, with same-day termination of access and periodic access reviews
- Workforce security training at hire and annually, with completion records
- A security incident procedure and an incident log, covering incidents that never become breaches
- A tested contingency plan: data backup, disaster recovery, emergency mode operation — with a restore test on record
- A periodic evaluation of the whole programme, at least annual
- A signed business associate agreement for every vendor touching PHI, held in a register
Physical safeguards
Facility access controls, workstation use, workstation security, and device and media controls — including disposal and re-use.
From §164.310, and yes, these apply to remote-first companies too — a home office is a facility in the rule’s sense:
- Documented facility access controls: who can enter spaces where ePHI is accessible, and how visitors are handled
- Workstation use and positioning rules — screens not visible to the public, automatic locking
- An inventory of devices and media that store ePHI, including laptops and phones
- Media disposal and re-use procedures: wiped or destroyed before leaving your control, with a record
- Movement tracking for hardware carrying ePHI
Technical safeguards
Access control, audit controls, integrity, person or entity authentication, and transmission security.
From §164.312:
- Unique user identification for every person — no shared accounts, anywhere
- Emergency access procedure for obtaining ePHI when normal access fails
- Automatic logoff and encryption at rest (addressable, and in 2026 hard to justify skipping)
- Audit controls: logging of activity in systems containing ePHI, and someone actually reviewing it
- Integrity controls protecting ePHI from improper alteration or destruction
- Authentication strong enough to trust — in practice, multi-factor on anything reachable from the internet
- Transmission security: encryption in transit for ePHI crossing open networks
Privacy Rule items
Notice of Privacy Practices, minimum necessary, patient rights (access, amendment, restriction, accounting), authorisations, and designated record set definition.
The operational versions: a current Notice, posted and distributed as required. A minimum-necessary standard applied to internal access and routine disclosures. A process to fulfil access requests within 30 days, and workflows for amendment, restriction, and accounting-of-disclosures requests. Valid authorisation forms for uses beyond treatment, payment, and operations. And a written definition of your designated record set, because you cannot fulfil access requests against an undefined scope.
Breach Notification items
Four-factor risk assessment procedure, individual notification within 60 days, HHS reporting, media notification threshold, and business associate notification terms.
Check that you have: a documented four-factor assessment procedure for deciding whether an impermissible use or disclosure is a reportable breach; a notification workflow that can hit the 60-day individual deadline; the HHS reporting paths for both large (500+, within 60 days) and small (annual log) breaches; awareness of the media notification requirement for breaches affecting 500+ in a state or jurisdiction; and BAA clauses that get you vendor breach reports fast enough to meet your own clock.
Documentation
Six-year retention for policies, procedures, actions, activities, and assessments required by the rule.
This is §164.316 and it is the quiet multiplier on everything above: policies must be written, kept current, available to the workforce, and retained — along with the records of actions and assessments — for six years from creation or last effective date. Version your documents, date your reviews, and store acknowledgements against version numbers.
Organisational and vendor items
Two categories that fall outside the safeguard headings and get missed for it. Organisational: a named Security Officer and Privacy Officer, designated in writing (one person can hold both hats in a small organisation); a signed business associate agreement for every vendor that creates, receives, maintains, or transmits PHI on your behalf, held in a register with renewal dates; and, if you are a business associate yourself, the subcontractor agreements flowing your obligations downstream. Workforce: sanction policy applied and recorded, acknowledgements collected against policy version numbers, and training coverage reconciled against the full roster including contractors.
After the checklist
A checklist finds gaps; it does not close them. Two habits convert the exercise into a programme. First, date this pass and diary the next one — the checklist run annually with archived results is itself evidence for the §164.308(a)(8) evaluation, whereas a single undated pass proves only that you once read a web page. Second, for every unticked box, write three things next to it: the owner, the date, and the reason if you are deliberately deferring it. A documented, prioritised backlog of known gaps is a defensible position under the penalty structure’s culpability tiers; the same gaps undocumented are the definition of the tier you want to avoid. And keep the completed checklist itself — dated, with owner initials — in the same six-year archive as everything else, because the exercise of checking is evidence of the evaluation standard running. Sequence the fixes by exposure — risk analysis and BAAs first, since they are the items OCR requests first and the ones you cannot backfill. If you want the scored version of this exercise, the free readiness assessment turns the same questions into a prioritised report, and the template library covers the documents most teams are missing.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.