Quarterly Security Review: A Checklist for Administrators

Security is not a project with an end date. Staff change, systems are added and threats evolve, so even a well-built environment slowly drifts away from its intended state. One of the simplest ways to prevent drift is a regular review, held on a calendar, with the right people in the room and a consistent agenda.

A quarterly security review does not need to be long. An hour is enough if it is focused. This checklist is designed for administrators, directors of nursing, compliance officers and your IT lead or provider. It also produces documentation that supports the HIPAA Security Rule's requirements for ongoing evaluation and risk management.

Who should attend

Administrator or executive director

Compliance or privacy officer

Director of nursing or clinical representative

IT provider or internal IT lead

Business office or HR representative, when access and training are on the agenda

Part one: Access and accounts

How many active accounts exist, and do they match the current staff roster?

Were all departures handled the same day?

Which accounts have administrator privileges, and does each person still need them?

Is multi-factor authentication enforced on email, remote access and administrator accounts? Where are the gaps?

Are there shared or generic accounts that should be eliminated?

Do vendors with remote access still need it?

Part two: Systems and patches

What percentage of devices are fully patched, and which are late?

Are any devices running unsupported operating systems or software?

Have firewall, switch and wireless firmware been updated?

Are there any exceptions or accepted risks, and have they been reviewed?

What upcoming end-of-support dates need budgeting?

Part three: Backups and recovery

Have backups succeeded consistently?

When was the last restore test, and what did it show?

Is at least one backup copy offline or immutable?

Are downtime procedures and kits current, and when was the last drill?

Part four: Threats and incidents

Review incidents or near misses since the last meeting, including phishing reports, lost devices and misdirected messages

Were any reportable breaches identified, and was the assessment documented?

Did email filtering or endpoint protection stop notable threats?

Are there new threats relevant to healthcare that leadership should know about? CISA and HHS publish alerts and advisories that your IT partner can summarize.

Part five: People and training

What percentage of staff completed security training on time?

Have new hires and agency staff been included?

What were the results of any phishing simulation, including the report rate?

Is there a topic that needs reinforcement, based on incidents or tickets?

Part six: Vendors and contracts

Is the vendor inventory current?

Are business associate agreements in place for every vendor that handles PHI?

Are any contracts approaching renewal, and does a security review make sense?

Have any vendors reported incidents?

Part seven: Policies and documentation

Which policies are due for review?

Has the risk analysis been updated for recent changes, such as new systems, locations or devices?

Is the incident response plan and contact list current?

Are insurance requirements and renewal dates tracked?

Part eight: Budget and priorities

What are the top three risks right now?

What is the plan and budget to address them?

What projects are scheduled for the next quarter, and who owns each?

Keep a record

Write brief minutes: date, attendees, key findings, decisions and action items with owners and due dates. Review last quarter's actions at the start of the next meeting. This simple habit is the difference between talking about security and managing it.

Keep it practical

Use a one-page dashboard if your IT provider can supply one. A few numbers, such as patch status, MFA coverage, backup success and training completion, tell most of the story. Do not let the meeting turn into a technical deep dive. If an issue needs more time, assign it to a follow-up.

Annual add-ons

Once a year, expand the review to include a refreshed risk analysis, a tabletop incident exercise, an access review across all systems and a check of your cyber insurance coverage.

UnityCare IT can prepare the data for your quarterly review, facilitate the discussion and help track action items through to completion. If you do not have a regular review in place, we can help you launch one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034