Resource
Medical & dental security checklist
A practical starting list for small medical admin offices handling ePHI. Not legal advice.
Use this checklist as a conversation starter with leadership. Salvus Cyber can help close gaps through assessment and scoping. See also our HIPAA readiness checklist.
Core controls
- Business Associate Agreements signed for all ePHI-handling vendors
- Network segmented between clinical systems and guest Wi-Fi
- Workstation encryption and auto-lock policy enforced
- Backup tested monthly and restore verified quarterly
- MFA on EHR and email accounts for all staff
- Annual HIPAA risk assessment documented
- Incident response contact list and runbook in place
- Workforce awareness training completed and logged
- Physical access controls reviewed for server room and records storage
© Salvus Cyber · Houston, Texas · For informational use only