A Mid-Year Security Review Checklist for Senior Living

The end of June marks the halfway point of the year, which makes it a convenient moment to check whether the security promises you made in January are still being kept. Staff turn over, systems change and good intentions slip. A brief, structured review now can catch problems while there is still time to fix them within this year's budget.

This checklist is written for senior-living and long-term care operators. Assign each section to an owner, set a date, and record the results.

Accounts and access

Compare active user accounts against the current staff list, and disable anyone who has left

Review administrator accounts and remove those no longer needed

Check that every account is unique to one person, with no shared logins

Confirm that multi-factor authentication is enforced on email, remote access and your clinical systems

Review permissions in the EHR by role, and look for people with more access than their job requires

Review temporary, agency and vendor accounts, and remove expired ones

Devices and software

Update your device inventory, including computers, tablets, phones, printers and connected medical devices

Identify equipment that is at or near end of support, including operating systems

Check patch reports for devices that are behind, and follow up on exceptions

Confirm endpoint protection is installed, running and reporting on every device

Verify that laptops and portable devices use disk encryption

Look for any software installed outside the approved list

Backups and recovery

Confirm that backups ran successfully, and check for any recurring failures

Perform a test restore of a few files, and note the time

Verify that at least one backup copy is offline or immutable and offsite

Review the recovery order and contact list, and update them

Check that downtime forms and printouts for clinical staff are current and easy to find

Network and remote access

Review firewall rules and remove those that are obsolete

Confirm that no systems are exposed directly to the internet through remote desktop or similar tools

Check that resident and guest Wi-Fi remains separate from staff and clinical networks

Review vendor remote access, and confirm each vendor still needs it

Confirm that default passwords on network equipment have been replaced

Test the backup internet connection, if you have one

Email and phishing

Review your email filtering results and any phishing messages staff reported

Check SPF, DKIM and DMARC settings for your domain

Verify that forwarding rules to outside addresses are blocked or reviewed

Run a practice phishing exercise or short refresher, and note reporting rates

Policies, training and documentation

Confirm that all new hires since January completed security and HIPAA training

Review your policies for anything that no longer matches how work is done, such as messaging, mobile devices and remote work

Update your HIPAA risk analysis for any significant changes, such as new systems, new vendors or incidents

Check that your risk management plan shows progress, with owners and dates

Confirm that business associate agreements are in place for each vendor handling PHI

Incident readiness

Review the incident response plan and its contact list

Confirm after-hours contacts for IT support, leadership and the privacy officer

Schedule a tabletop exercise for the second half of the year if you have not done one

Check your cyber insurance coverage, its requirements and renewal date

Physical safeguards

Walk the building and check that network closets and server rooms are locked

Look for workstations in public areas with screens visible to visitors

Check that paper records, shred bins and printers are handled properly

Verify that visitor and vendor sign-in procedures are followed

Turn findings into a plan

When the review is complete, sort your findings into three groups: fix now, schedule this quarter and plan for next year's budget. Assign each an owner and a date, and record them in your risk management plan. Share a short summary with leadership, because decisions about budget and staffing depend on a clear picture.

Do not be discouraged by a long list. Every organization finds items on a review like this, and the value is in seeing them and acting. Resources such as the HHS 405(d) Health Industry Cybersecurity Practices and the NIST Cybersecurity Framework can help you prioritize.

UnityCare IT can conduct a mid-year assessment for your community, deliver a prioritized action list and help carry it out. If you would rather start on your own, use this checklist and let us know where you would like a second opinion.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172