Security Evidence Checklist

See exactly what we review.

Each item is organized by owner, system, evidence, and next action.

Open a section

The checklist.

Bring what already exists. Open any section to see the evidence we need to complete it.

01

People & accountability

Who is responsible for privacy, security, and response.
People
  • Practice locations, services, and workforceProof: current organization and service list
  • Covered entity / business associate roleProof: entity and relationship details
  • Privacy, security, and incident-response ownersProof: named owner and escalation path
  • IT/MSP, vendors, and escalation contactsProof: current contact list
02

PHI, systems & devices

Where information enters, moves, is stored, and leaves.
Systems
  • Where PHI enters, moves, is stored, and leavesProof: workflow or data-flow view
  • EHR, practice management, imaging, telehealth, email, and formsProof: system list and use case
  • Devices, shared workstations, mobile devices, and removable mediaProof: device or endpoint list
  • Cloud services, backups, and disaster recoveryProof: provider, backup, and recovery evidence
03

Access & safeguards

How access, devices, facilities, and technical controls are protected.
Controls
  • Unique user accountsProof: account and access settings
  • MFA and authentication controlsProof: configuration or policy evidence
  • Role-based access / minimum necessaryProof: role matrix or access standard
  • New-hire, transfer, and termination access changesProof: access request and removal records
  • Periodic access reviewProof: completed review with owner sign-off
  • Workstation placement and screen privacyProof: walkthrough notes or photos
  • Facility and visitor accessProof: access process and responsibility
  • Paper and media storage, disposal, and destructionProof: storage, transport, and destruction evidence
  • Encryption at rest and in transitProof: settings, provider documentation, or scope
  • Patching and endpoint protectionProof: current status or managed-service report
  • Logging, audit controls, network, Wi-Fi, and remote accessProof: enabled logs and configuration evidence
  • Backup and restore testingProof: test result and date
04

Vendors & business associates

Which outside parties touch PHI and what agreements support that work.
Vendors
  • Complete vendor inventoryProof: PHI-touching vendor list
  • Signed BAA for each PHI-touching vendorProof: executed agreement and date
  • Subcontractors and downstream accessProof: vendor dependency or subprocessor record
  • Renewal, termination, and data return/deletion processProof: contract and offboarding evidence
05

Workforce & Texas requirements

What staff are trained to do, and what the records need to show.
Training
  • Role-specific HIPAA / Texas privacy trainingProof: training content and audience
  • New-hire training timingProof: hire date, training date, and completion
  • Recurring training and signed attendance proofProof: dated roster or signed statement
  • Secure messaging, email, remote work, and verbal handlingProof: policy plus observed workflow
  • Sanctions / acknowledgment processProof: policy and acknowledgment record
  • HB 300 training scope and proofProof: audience, content, and completion record
  • 60-day new-hire training checkProof: hire date and completion date
  • Two-year recurring training checkProof: current training cycle
  • Signed attendance statement retainedProof: dated signature or equivalent record
  • Electronic-record request workflowProof: intake, routing, and response tracking where applicable
  • Electronic-disclosure notice and authorization pathProof: notice, authorization, or documented exception
06

Incident response

How the team reports, assesses, responds to, and learns from an incident.
Response
  • How staff report an incidentProof: reporting channel and instructions
  • Named response ownersProof: response roles and contacts
  • Breach assessment and notification workflowProof: decision path and templates
  • Tested response plan / tabletopProof: exercise record and lessons learned
  • Corrective action trackingProof: open items, owners, and dates
07

What you receive

A usable record of what is supportable, what is missing, and what happens next.
Output
  • Verified evidenceWhat is complete and supportable now
  • Missing evidenceWhat cannot yet be proven
  • Owner for each gapWho is responsible for closing it
  • System or location of proofWhere the evidence should live
  • Priority and next actionWhat to do first and why
  • Target date and follow-upHow open items stay visible

Framework references: HHS Audit Protocol and Texas HB 300. This is an evidence-review framework, not a legal opinion or certification; applicability depends on the organization.