HIPAA Compliance Checklist

Trusted by organizations across Buffalo, Rochester & nationwide
⬇ Download Hipaa Compliance Checklist PDF
IDN §162 Description Passed/Failed
§162 401 NPI Issued:

Ensure the confidentiality, integrity, and availability of all electronic protected health information.

§162 410 (a)

NPI Provided (National Provider Identifier)

§162 504

HPID Issued (#######)

§162 605

EIN Issued (##-#######)

§162 930 Compliant HCC

Receive a standard transaction on behalf of the covered entity and translate it into a nonstandard transaction.

Receive a nonstandard transaction from the covered entity and translate it into a standard transaction for transmission on behalf of the covered entity.

§162*

Dedicated Privacy Official

IDN §164 Description Passed/Failed
§164 306 (a) Reasonable Security Precautions

Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.

§164 306 (b) Flexibility of approach

Covered entities and business associates may use any security measures that allow the covered entity or business associate to reasonably and appropriately implement the standards and implementation specifications.

§164 308.1 (a) Risk analysis in the last 12 mo.

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.

§164 308.1 (b) Compliant risk management

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a).

§164 308.1 (c) Sanction Policy

Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate.

§164 308.1 (d) ISMS deployed + sys. review

Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.

§164 308.3 Workforce security

Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information.

§164 308.3 (a) Workforce authorization

Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.

§164 308.3 (b) Workforce clearance

Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.

§164 308.4 Compliant access management

Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part.

§164 308.4 (a) HCC Isolation

If a health care clearinghouse is part of a larger organization, the clearinghouse must implement policies and procedures that protect the electronic protected health information of the clearinghouse from unauthorized access by the larger organization.

§164 308.4 (b) Endpoint access authorization

Implement policies and procedures for granting access to electronic protected health information, for example, through access to a workstation, transaction, program, process, or other mechanism.

§164 308.5 Security awareness/training

Implement a security awareness and training program for all members of its workforce (including management).

§164 308.5 (a) Recurring security reminders

Periodic security updates.

↓ + 52 More Items ↓

Ready to see what we can do for your business?

Schedule a free remote or on-site IT consult. Tell us about your business and the services you need — response times are typically under three hours.

Ready to see what we can do for your business?

Schedule a free remote or on-site IT consult. Tell us about your business and the services you need – response times are typically under three hours.