Skip to main content
SSALVUS CYBERCybersecurity for Professional Firms

Resource

Medical & dental security checklist

A practical starting list for small medical admin offices handling ePHI. Not legal advice.

Use this checklist as a conversation starter with leadership. Salvus Cyber can help close gaps through assessment and scoping. See also our HIPAA readiness checklist.

Core controls

  • Business Associate Agreements signed for all ePHI-handling vendors
  • Network segmented between clinical systems and guest Wi-Fi
  • Workstation encryption and auto-lock policy enforced
  • Backup tested monthly and restore verified quarterly
  • MFA on EHR and email accounts for all staff
  • Annual HIPAA risk assessment documented
  • Incident response contact list and runbook in place
  • Workforce awareness training completed and logged
  • Physical access controls reviewed for server room and records storage

© Salvus Cyber · Houston, Texas · For informational use only

Take the full assessment