Open a section
The checklist.
Bring what already exists. Open any section to see the evidence we need to complete it.
01People & accountability
Who is responsible for privacy, security, and response.People
People & accountability
Who is responsible for privacy, security, and response.- Practice locations, services, and workforceProof: current organization and service list
- Covered entity / business associate roleProof: entity and relationship details
- Privacy, security, and incident-response ownersProof: named owner and escalation path
- IT/MSP, vendors, and escalation contactsProof: current contact list
02PHI, systems & devices
Where information enters, moves, is stored, and leaves.Systems
PHI, systems & devices
Where information enters, moves, is stored, and leaves.- Where PHI enters, moves, is stored, and leavesProof: workflow or data-flow view
- EHR, practice management, imaging, telehealth, email, and formsProof: system list and use case
- Devices, shared workstations, mobile devices, and removable mediaProof: device or endpoint list
- Cloud services, backups, and disaster recoveryProof: provider, backup, and recovery evidence
03Access & safeguards
How access, devices, facilities, and technical controls are protected.Controls
Access & safeguards
How access, devices, facilities, and technical controls are protected.- Unique user accountsProof: account and access settings
- MFA and authentication controlsProof: configuration or policy evidence
- Role-based access / minimum necessaryProof: role matrix or access standard
- New-hire, transfer, and termination access changesProof: access request and removal records
- Periodic access reviewProof: completed review with owner sign-off
- Workstation placement and screen privacyProof: walkthrough notes or photos
- Facility and visitor accessProof: access process and responsibility
- Paper and media storage, disposal, and destructionProof: storage, transport, and destruction evidence
- Encryption at rest and in transitProof: settings, provider documentation, or scope
- Patching and endpoint protectionProof: current status or managed-service report
- Logging, audit controls, network, Wi-Fi, and remote accessProof: enabled logs and configuration evidence
- Backup and restore testingProof: test result and date
04Vendors & business associates
Which outside parties touch PHI and what agreements support that work.Vendors
Vendors & business associates
Which outside parties touch PHI and what agreements support that work.- Complete vendor inventoryProof: PHI-touching vendor list
- Signed BAA for each PHI-touching vendorProof: executed agreement and date
- Subcontractors and downstream accessProof: vendor dependency or subprocessor record
- Renewal, termination, and data return/deletion processProof: contract and offboarding evidence
05Workforce & Texas requirements
What staff are trained to do, and what the records need to show.Training
Workforce & Texas requirements
What staff are trained to do, and what the records need to show.- Role-specific HIPAA / Texas privacy trainingProof: training content and audience
- New-hire training timingProof: hire date, training date, and completion
- Recurring training and signed attendance proofProof: dated roster or signed statement
- Secure messaging, email, remote work, and verbal handlingProof: policy plus observed workflow
- Sanctions / acknowledgment processProof: policy and acknowledgment record
- HB 300 training scope and proofProof: audience, content, and completion record
- 60-day new-hire training checkProof: hire date and completion date
- Two-year recurring training checkProof: current training cycle
- Signed attendance statement retainedProof: dated signature or equivalent record
- Electronic-record request workflowProof: intake, routing, and response tracking where applicable
- Electronic-disclosure notice and authorization pathProof: notice, authorization, or documented exception
06Incident response
How the team reports, assesses, responds to, and learns from an incident.Response
Incident response
How the team reports, assesses, responds to, and learns from an incident.- How staff report an incidentProof: reporting channel and instructions
- Named response ownersProof: response roles and contacts
- Breach assessment and notification workflowProof: decision path and templates
- Tested response plan / tabletopProof: exercise record and lessons learned
- Corrective action trackingProof: open items, owners, and dates
07What you receive
A usable record of what is supportable, what is missing, and what happens next.Output
What you receive
A usable record of what is supportable, what is missing, and what happens next.- Verified evidenceWhat is complete and supportable now
- Missing evidenceWhat cannot yet be proven
- Owner for each gapWho is responsible for closing it
- System or location of proofWhere the evidence should live
- Priority and next actionWhat to do first and why
- Target date and follow-upHow open items stay visible
Framework references: HHS Audit Protocol and Texas HB 300. This is an evidence-review framework, not a legal opinion or certification; applicability depends on the organization.