Advanced engineering expertise for organizations where downtime is expensive.
Healthcare Cybersecurity & HIPAA

HIPAA Readiness Checklist.

Healthcare practices are among the most targeted organizations for ransomware and data theft. Ten questions that reveal whether yours is adequately protected — and HIPAA compliant.

0 / 10
Check each item that applies to your practice. Any "No" or "Not Sure" answers represent gaps — in patient data protection, HIPAA compliance, or cybersecurity readiness. Each gap carries real risk.
📋

HIPAA Foundation

A signed Business Associate Agreement exists with your IT provider.
If your IT provider accesses, maintains, or stores Protected Health Information, they are a Business Associate under HIPAA and must sign a BAA. This is a legal requirement — not a technicality. Practicing without a signed BAA is a compliance violation regardless of every other safeguard your practice has in place. Most small healthcare practices have never been offered one.
A HIPAA Security Risk Analysis has been completed and documented within the last 12 months.
HIPAA requires covered entities to conduct and document a thorough Security Risk Analysis of their environment — not once, but on an ongoing basis and whenever the environment changes significantly. OCR cites failure to conduct an adequate risk analysis as the most common finding in enforcement actions. This is not an internal assessment — it requires documentation of identified risks and remediation decisions.
All staff have received HIPAA security awareness training within the last 12 months.
Phishing and social engineering remain the most common entry points for healthcare data breaches — not technical vulnerabilities. Staff training that covers phishing recognition, password hygiene, device security, and proper PHI handling is required under HIPAA and is your strongest single control against credential compromise. Training must be documented.
🔑

Access Control

Multi-factor authentication is enabled on all systems that access patient records.
MFA is now a standard requirement for cyber insurance policies and is considered a baseline security control by HHS. It should be active on your EHR, practice management system, Microsoft 365 or Google Workspace, remote access solutions, and any cloud platform handling PHI. A single account without MFA is a potential entry point for credential-based attacks — the most common cause of healthcare breaches.
Access to patient records is restricted to staff who need it for their specific role.
HIPAA's Minimum Necessary standard requires that access to PHI be limited to the amount necessary for each employee's role. A front desk coordinator does not need access to clinical notes. A billing specialist does not need access to records outside their assigned patients. Role-based access controls limit the impact of a compromised account and reduce the scope of any potential breach.
☁️

Data Security

Patient data is encrypted at rest on all workstations, servers, and portable devices.
A lost or stolen unencrypted laptop containing PHI is an automatic HIPAA breach requiring patient notification — regardless of whether the data was ever accessed. Encryption at rest means that a lost device is not a reportable incident. It is an addressable specification under HIPAA — but in practice, encryption is expected on all devices that store PHI, with documented justification required if it is not implemented.
EHR, patient records, and critical systems are backed up automatically and verified regularly.
Backups that have never been tested are a liability, not an asset. Verify that your EHR, practice management system, and patient files are backed up automatically, that backups are completing successfully, and that you have tested a restoration from them — not just assumed it would work. A backup that cannot be restored is no backup at all.
Backups are stored in a location that would survive a ransomware attack.
Ransomware routinely attempts to encrypt or delete accessible backups before triggering the encryption of primary data. An effective backup strategy for a healthcare practice requires at least one copy that is off-network, immutable, or both — so that a ransomware attack does not simultaneously destroy your patient data and your only path to recovery. Cloud backup alone is not sufficient if it is writable from a compromised workstation.
🚨

Incident Response

A documented HIPAA breach notification and incident response plan exists.
HIPAA requires covered entities to notify affected patients within 60 days of discovering a breach — and to notify HHS. If the breach affects more than 500 individuals in a state, local media notification may also be required. When an incident occurs, the first hours determine your compliance posture. A documented plan ensures the right steps happen immediately: containment, forensic preservation, scope assessment, and notification timelines — not a scramble to figure out what to do next.
Your cyber insurance requirements are documented and verifiably met.
Healthcare practices are increasingly required to carry cyber liability insurance. Most policies have specific technical requirements — MFA, endpoint protection, backup architecture, staff training, incident response procedures. Insurers are actively disputing claims from practices that represented having controls they cannot verify were in place. Know exactly what your policy requires, confirm it is implemented, and document the evidence before you need to make a claim.

What Your Score Means

9 – 10 Yes

Strong HIPAA & Cybersecurity Posture

Your practice has the core HIPAA and cybersecurity controls in place. A technology assessment can verify that your controls are properly implemented — not just present on paper — and confirm your compliance documentation is complete and current.

6 – 8 Yes

Significant Gaps Exist

Your practice has some protections in place, but the gaps you identified create real exposure — to patient data, HIPAA enforcement, cyber insurance disputes, and ransomware impact. A focused assessment will help you prioritize what to address first and what your greatest risks are.

5 or Fewer Yes

Your Practice and Your Patients Are at Significant Risk

Healthcare practices with multiple cybersecurity and compliance gaps are high-value targets for ransomware and are potentially exposed to regulatory enforcement. A technology assessment will identify your most critical exposures, help you establish a defensible compliance posture, and give you a practical remediation plan.