Resource
HIPAA readiness checklist
A practical starting list for small medical and dental admin offices. Not legal advice.
Use this as a conversation starter with your leadership team. Salvus Cyber can help close gaps found here through assessment and scoping.
Core controls
- Business Associate Agreements in place for vendors handling ePHI
- MFA enforced on email and admin accounts
- Workstation encryption and screen-lock policy
- Tested backup and documented restore procedure
- Network segmentation between clinical and guest Wi-Fi
- Annual workforce security awareness training
- Incident response contact list and runbook
- Risk assessment documented within the last 12 months
© Salvus Cyber · Houston, Texas · For informational use only