The §164.308(a)(8) periodic evaluation as a run-book: what to re-test, what to re-document, and what to hand leadership.
What is in the download
- Format: PDF + XLSX
- Length: 8 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the checklist
The Security Rule requires a periodic technical and non-technical evaluation at §164.308(a)(8), and this checklist turns that sentence into a run-book you can execute in a working week. The PDF is the narrative run-book; the XLSX is the working tracker with a row per item, columns for owner, status, evidence link, and finding.
The items are grouped into four passes. Re-test: restore a backup and record the result; walk through the incident response plan on paper; verify a sample of terminated accounts are actually gone; check MFA and encryption settings against what your policies claim. Re-document: refresh the risk assessment against the year’s changes — new systems, new vendors, incidents; review each policy against its next-review date and bump version numbers where anything changed; reconcile the BAA register against the live vendor list; confirm training completions cover the full workforce roster, contractors included. Re-decide: revisit every accepted risk whose review date has arrived, and every addressable-specification rationale that a year of change may have invalidated. Report: the final section is a two-page leadership summary skeleton — programme status, findings, remediation plan with owners and dates — because the evaluation is also your annual chance to get budget attached to the gaps.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
For a checklist rather than a policy, step two means: delete the rows testing controls you have not implemented — they belong in your remediation plan, not your evaluation record — and the completed checklist itself becomes the §164.308(a)(8) evidence, so the retention in step four applies to every year’s copy.
How to customise it
Map each row to your actual systems before the review starts: the backup-restore row should name the backup system, the access rows should name every platform with its own accounts, and the vendor rows should point at your real register. Spread the work rather than compressing it — the checklist is designed to run as one item-owner per area over two to four weeks, not a single heroic weekend, and the owner column exists so the Security Officer coordinates rather than performs everything. Set the annual date somewhere deliberate: many teams anchor it a quarter before their busiest customer-audit season, so the evaluation’s outputs are fresh when questionnaires arrive. And add rows for anything your risk assessment rates high that the generic list does not cover — the checklist is a floor, not a ceiling.
Common mistakes
- Running it as a documentation review only. The standard says technical and non-technical. If nothing was actually tested — no restore, no account sample, no configuration check — it was a filing exercise, not an evaluation.
- Skipping the year nothing changed. “Periodic” is not conditional on drama, and the record of an uneventful review is still evidence the programme runs.
- Finding gaps and filing them. An evaluation that surfaces findings which then appear in no remediation plan is worse than none — it documents knowledge without action, which is the culpability tier you least want.
- One person doing everything. The results skew toward what that person already knows, and the organisation learns nothing.
- No leadership readout. The evaluation is the one scheduled moment compliance gets executive attention. Wasting it keeps the programme unfunded.
Related templates
The review touches every other document in the library: it re-opens the risk assessment, audits the policy set, checks the training records, and exercises the incident response plan. The regulatory context lives in the administrative safeguards guide, and if this is your first evaluation, running the free readiness assessment beforehand gives you a scored baseline to measure the year against.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.