HIPAA Security Rule Checklist: How to Protect Patient Information

HIPAA Security Rule Checklist: How to Protect Patient Information

Introduction: HIPAA Compliance Does Not End With Privacy 

The Privacy Rule tells you who can see patient information and when. The Security Rule tells you how to protect it once it's stored electronically. Those are two separate problems, and a practice that's solid on one can still be exposed on the other. 

Part 1 of this series covered the Privacy Rule: Patient rights, minimum necessary disclosures, who's responsible for policy. This post covers what comes after that. Limiting who's allowed to see a patient's record does nothing to stop that record from being accessed by someone who was never supposed to have it in the first place. This can mean a stolen laptop, a weak password, or a vendor system nobody thought to check. 

The Security Rule exists to set standards for protecting electronic protected health information (ePHI) from unauthorized access, loss, theft, and breaches. For a small practice, that means specific, practical safeguards, not just a policy on paper. 

What Is the HIPAA Security Rule? 

Unlike the Privacy Rule, which applies to PHI in any form, the Security Rule only applies once that information touches a computer, a server, an EHR, or any electronic system. For most practices today, that's nearly everything. Paper charts are rare enough that the Security Rule ends up governing the bulk of daily operations, even if it doesn't feel that way. (HHS.gov, Security Rule Summary

Physical Safeguards 

Physical safeguards cover the tangible side of protecting ePHI: the building, the devices, and who can get near either one. 

This includes limiting physical access to areas where ePHI is stored, keeping workstations secured, so screens aren't left exposed, and controlling what happens to hardware and media containing ePHI, from receiving new devices to disposing of old ones. Data must also be wiped from any device before it's reused. 

Technical Safeguards 

Access control means only authorized users reach ePHI, each with a unique login. Authentication checks that whoever is logging in is that person. Audit controls track who accessed what, and when. Integrity measures confirm data hasn't been altered or destroyed. Transmission security covers encryption while data moves across a network. 

Access Management: Who Can Access Your EHR? 

Every login should map to one person, doing one job, with access limited to that job. The front desk doesn't need clinical notes. Billing doesn't need full chart access. 

The most common failure point here is stale access: logins that stay active after someone's role changes or their employment ends. A quick check: pull your user list and see if everyone still needs the access they have. 

HIPAA Hosting, Vendors, and Business Associates 

Protecting ePHI doesn't stop at your practice's own systems. Many practices rely on third-party vendors for EHR hosting, cloud storage, billing, IT support, backups, and communication tools, all of which may access or store patient information. 

Under HIPAA, these vendors may be considered business associates if they handle ePHI on your behalf. Before allowing a vendor to access, practices should have a signed Business Associate Agreement (BAA) that defines how the data will be protected, what security responsibilities the vendor has, and how potential breaches will be handled. 

A vendor claiming to be "HIPAA compliant" isn't enough by itself. Jeremy Shiner has pointed out that once PHI leaves the EHR, it can pass through centralized databases, vendors that aren't covered by entities, or technology partners with no BAA in place at all. This risk has grown with AI tools added as plug-ins or API connections outside the EHR, some of which rely on models accessed via API in ways that bypass BAA requirements entirely. His advice: ask for a full data flow diagram, identify every system that touches PHI, and confirm a BAA exists at each level, not just at the top. 

Regular vendor reviews should be part of your practice security process. Questions that you should ask before: 

  • Does this vendor still need access to ePHI? 

  • Is there a current BAA in place? 

  • What security measures does the vendor use to protect patient data? 

  • Are access permissions limited to only what is necessary? 

Common HIPAA Security Mistakes and Violations 

Beyond shared logins and stale access, a few other mistakes show up often: 

Not using multi-factor authentication (MFA). A password alone may not be enough. MFA adds a verification step and helps prevent unauthorized access if credentials are compromised. 

Storing ePHI on unsecured devices. Laptops, phones, and tablets containing patient information need encryption, strong passwords, and remote-wipe capability where available. 

Skipping regular risk assessments. HIPAA compliance isn't a one-time checklist. Practices need to regularly review where ePHI is stored, who can access it, and what new risks have appeared as technology and workflows change. 

Ignoring software updates and security patches. Outdated systems can carry known vulnerabilities attackers already know how to exploit. 

Failing to train staff properly. Employees are often the first line of defense. Without regular training, staff may unintentionally expose patient information through phishing emails, improper sharing, or weak security habits. 

What to Do After a Potential PHI Breach 

Even with strong safeguards, a practice may still face a potential breach. The key is responding quickly and following a documented process. 

First, identify and contain the incident. This may include disabling compromised accounts, recovering lost devices, removing unauthorized access, or working with vendors to stop further exposure. 

Next, document and investigate. Determine what information was involved, whose data may have been affected, when the incident occurred, and whether it's a reportable breach under HIPAA. 

Involve the right people early: your Security Official, privacy officer, IT team, or legal counsel. If a breach is confirmed, HIPAA may require notifying affected individuals, HHS, and in some cases, the media. 

Don't treat the incident as solved once it's handled. Use it to review what caused the breach and update policies, training, access controls, or security measures to prevent it from happening again. 

The complete HIPAA Security Rule checklist 

Administrative safeguards 

  • Designate a Security Official responsible for HIPAA security policies 

  • Complete regular risk assessments to identify potential threats to ePHI 

  • Create policies for access management, incident response, and data recovery 

  • Train employees on HIPAA security responsibilities 

  • Maintain a process for reporting and responding to security incidents 

  • Review business associates and confirm BAAs are in place where required 

  • Maintain backups and recovery processes for critical systems 

Physical safeguards 

  •  Limit physical access to areas where ePHI is stored 

  •  Secure workstations and prevent unauthorized screen access 

  •  Protect laptops, tablets, and other devices containing patient information 

  •  Have procedures for securely disposing of devices and electronic media 

  •  Ensure data is removed before equipment is reused or discarded 

Technical safeguards 

  • Give each user a unique login and avoid shared accounts 

  • Use strong authentication methods, including multi-factor authentication where possible 

  • Limit EHR access based on each employee’s role 

  • Monitor system activity through audit controls 

  • Protect ePHI during transmission with appropriate security measures 

Vendor and access management 

  •  Review every vendor that stores, processes, or accesses ePHI 

  •  Confirm vendors have appropriate security practices in place 

  •  Remove access when employees or contractors no longer need it 

  •  Regularly review user permissions to ensure access remains appropriate 

How to perform a HIPAA gap analysis 

A HIPAA gap analysis helps practices understand where their current security practices stand, where they need improvement, and what steps are needed to strengthen compliance. It compares your existing policies, procedures, and safeguards against HIPAA requirements to identify areas of risk. 

A HIPAA gap analysis can be completed in four steps: 

1. Review your current operations  

Start by understanding how your practice currently handles ePHI. Review your policies, procedures, systems, and workflows. Are your security policies up to date? Are employees following the procedures that are already in place? 

2. Compare your practices against HIPAA requirements  

Evaluate your current operations against the standards outlined in the HIPAA Privacy and Security Rules. Review areas such as access controls, employee training, risk assessments, vendor management, and technical safeguards to determine whether your current practices meet requirements. 

3. Identify security gaps  

Document where your HIPAA program falls short. This could include outdated policies, excessive user access, missing documentation, weak security controls, or vendors without proper agreements in place. Be specific so each issue can be addressed effectively. 

4. Create and implement an improvement plan  

Develop a clear action plan to close the identified gaps. Assign responsibilities, set realistic deadlines, and prioritize improvements based on risk. A successful gap analysis should result in measurable steps that strengthen your practice’s HIPAA compliance over time. 

HIPAA Compliance Requirements for Ongoing Security

Maintaining HIPAA Security Rule compliance can feel complex, but the right systems and processes make it manageable. Regularly reviewing your safeguards and closing gaps as they show up reduces risk and builds real trust with patients. 

Risk assessments, access logs, and training records all need to be tracked consistently, and that's a lot to manage by hand on top of running a practice. None of this has to run on manual tracking. Myriad Systems takes tracking off your plate, protecting patient data without the extra workload. Schedule a walkthrough to see how it works for your practice. 

FAQ 

  • What does NPP stand for in HIPAA 

NPP stands for Notice of Privacy Practices. It explains how a healthcare provider may use and disclose a patient’s protected health information (PHI) and describes the patient’s privacy rights. 

  • What is a HIPAA breach? 

A HIPAA breach is an unauthorized access, use, disclosure, or acquisition of PHI that compromises the security or privacy of patient information. 

  • What are examples of HIPAA violations? 

Examples include accessing patient records without permission, sharing PHI with unauthorized individuals, using unsecured devices, failing to protect passwords, or not having proper agreements with business associates. 

  • Is ChatGPT HIPAA compliant? 

ChatGPT isn't automatically HIPAA compliant. Healthcare organizations should only use AI tools with appropriate safeguards in place, including a signed BAA, and should avoid entering PHI into tools not approved for HIPAA use. ( HHS.gov, Business AssociatesHIPAA Journal, HIPAA, Healthcare Data, and Artificial Intelligence

  • How long does HIPAA certification last? 

HIPAA does not provide an official certification that expires. Organizations may complete HIPAA training or compliance programs, but maintaining compliance requires ongoing reviews, updates, and risk assessments. 

Proud Partners

Proud Partners

To embed a website or widget, add it to the properties panel.
To embed a website or widget, add it to the properties panel.
 (edited)