Security is not a project with an end date. Staff change, systems are added and threats evolve, so even a well-built environment slowly drifts away from its intended state. One of the simplest ways to prevent drift is a regular review, held on a calendar, with the right people in the room and a consistent agenda.
A quarterly security review does not need to be long. An hour is enough if it is focused. This checklist is designed for administrators, directors of nursing, compliance officers and your IT lead or provider. It also produces documentation that supports the HIPAA Security Rule's requirements for ongoing evaluation and risk management.
Administrator or executive director
Compliance or privacy officer
Director of nursing or clinical representative
IT provider or internal IT lead
Business office or HR representative, when access and training are on the agenda
How many active accounts exist, and do they match the current staff roster?
Were all departures handled the same day?
Which accounts have administrator privileges, and does each person still need them?
Is multi-factor authentication enforced on email, remote access and administrator accounts? Where are the gaps?
Are there shared or generic accounts that should be eliminated?
Do vendors with remote access still need it?
What percentage of devices are fully patched, and which are late?
Are any devices running unsupported operating systems or software?
Have firewall, switch and wireless firmware been updated?
Are there any exceptions or accepted risks, and have they been reviewed?
What upcoming end-of-support dates need budgeting?
Have backups succeeded consistently?
When was the last restore test, and what did it show?
Is at least one backup copy offline or immutable?
Are downtime procedures and kits current, and when was the last drill?
Review incidents or near misses since the last meeting, including phishing reports, lost devices and misdirected messages
Were any reportable breaches identified, and was the assessment documented?
Did email filtering or endpoint protection stop notable threats?
Are there new threats relevant to healthcare that leadership should know about? CISA and HHS publish alerts and advisories that your IT partner can summarize.
What percentage of staff completed security training on time?
Have new hires and agency staff been included?
What were the results of any phishing simulation, including the report rate?
Is there a topic that needs reinforcement, based on incidents or tickets?
Is the vendor inventory current?
Are business associate agreements in place for every vendor that handles PHI?
Are any contracts approaching renewal, and does a security review make sense?
Have any vendors reported incidents?
Which policies are due for review?
Has the risk analysis been updated for recent changes, such as new systems, locations or devices?
Is the incident response plan and contact list current?
Are insurance requirements and renewal dates tracked?
What are the top three risks right now?
What is the plan and budget to address them?
What projects are scheduled for the next quarter, and who owns each?
Write brief minutes: date, attendees, key findings, decisions and action items with owners and due dates. Review last quarter's actions at the start of the next meeting. This simple habit is the difference between talking about security and managing it.
Use a one-page dashboard if your IT provider can supply one. A few numbers, such as patch status, MFA coverage, backup success and training completion, tell most of the story. Do not let the meeting turn into a technical deep dive. If an issue needs more time, assign it to a follow-up.
Once a year, expand the review to include a refreshed risk analysis, a tabletop incident exercise, an access review across all systems and a check of your cyber insurance coverage.
UnityCare IT can prepare the data for your quarterly review, facilitate the discussion and help track action items through to completion. If you do not have a regular review in place, we can help you launch one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034