The end of June marks the halfway point of the year, which makes it a convenient moment to check whether the security promises you made in January are still being kept. Staff turn over, systems change and good intentions slip. A brief, structured review now can catch problems while there is still time to fix them within this year's budget.
This checklist is written for senior-living and long-term care operators. Assign each section to an owner, set a date, and record the results.
Compare active user accounts against the current staff list, and disable anyone who has left
Review administrator accounts and remove those no longer needed
Check that every account is unique to one person, with no shared logins
Confirm that multi-factor authentication is enforced on email, remote access and your clinical systems
Review permissions in the EHR by role, and look for people with more access than their job requires
Review temporary, agency and vendor accounts, and remove expired ones
Update your device inventory, including computers, tablets, phones, printers and connected medical devices
Identify equipment that is at or near end of support, including operating systems
Check patch reports for devices that are behind, and follow up on exceptions
Confirm endpoint protection is installed, running and reporting on every device
Verify that laptops and portable devices use disk encryption
Look for any software installed outside the approved list
Confirm that backups ran successfully, and check for any recurring failures
Perform a test restore of a few files, and note the time
Verify that at least one backup copy is offline or immutable and offsite
Review the recovery order and contact list, and update them
Check that downtime forms and printouts for clinical staff are current and easy to find
Review firewall rules and remove those that are obsolete
Confirm that no systems are exposed directly to the internet through remote desktop or similar tools
Check that resident and guest Wi-Fi remains separate from staff and clinical networks
Review vendor remote access, and confirm each vendor still needs it
Confirm that default passwords on network equipment have been replaced
Test the backup internet connection, if you have one
Review your email filtering results and any phishing messages staff reported
Check SPF, DKIM and DMARC settings for your domain
Verify that forwarding rules to outside addresses are blocked or reviewed
Run a practice phishing exercise or short refresher, and note reporting rates
Confirm that all new hires since January completed security and HIPAA training
Review your policies for anything that no longer matches how work is done, such as messaging, mobile devices and remote work
Update your HIPAA risk analysis for any significant changes, such as new systems, new vendors or incidents
Check that your risk management plan shows progress, with owners and dates
Confirm that business associate agreements are in place for each vendor handling PHI
Review the incident response plan and its contact list
Confirm after-hours contacts for IT support, leadership and the privacy officer
Schedule a tabletop exercise for the second half of the year if you have not done one
Check your cyber insurance coverage, its requirements and renewal date
Walk the building and check that network closets and server rooms are locked
Look for workstations in public areas with screens visible to visitors
Check that paper records, shred bins and printers are handled properly
Verify that visitor and vendor sign-in procedures are followed
When the review is complete, sort your findings into three groups: fix now, schedule this quarter and plan for next year's budget. Assign each an owner and a date, and record them in your risk management plan. Share a short summary with leadership, because decisions about budget and staffing depend on a clear picture.
Do not be discouraged by a long list. Every organization finds items on a review like this, and the value is in seeing them and acting. Resources such as the HHS 405(d) Health Industry Cybersecurity Practices and the NIST Cybersecurity Framework can help you prioritize.
UnityCare IT can conduct a mid-year assessment for your community, deliver a prioritized action list and help carry it out. If you would rather start on your own, use this checklist and let us know where you would like a second opinion.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172