December is a natural time to review. Budgets are closing, planning for next year is underway, and some departments slow down. A one-day look at your technology risks now can shape your priorities and budget for the coming year. This checklist is written for administrators and compliance leaders, not just technicians, and each item comes with a question you can ask your IT provider.
Who has access to what? Ask for a list of all user accounts with their roles. Compare it against your current staff roster.
Are there former employees, agency staff or vendors with active accounts? Disable anything unused.
Do any accounts have administrator rights unnecessarily? Reduce them.
Are there shared logins? Replace them with individual accounts wherever possible.
Is multi-factor authentication on for email, remote access and administrators? Confirm with a report.
Do we have a current inventory of computers, tablets, phones, printers and network equipment?
Which devices are old or no longer supported by the manufacturer? List them for replacement planning.
Is endpoint protection installed and reporting on every computer and server?
Are there systems we cannot patch, and what protects them in the meantime?
When did we last restore from backup? If more than six months ago, schedule a test.
Are backups protected from ransomware with offline or immutable copies?
Do we have a written disaster recovery plan, and does it match today's systems?
Do we have a current list of vendors that handle PHI, with business associate agreements on file?
Which vendor contracts renew soon? Use that as leverage for service or security improvements.
When was our last security risk analysis? Update it if it is more than a year old or if major changes occurred.
Is our remediation plan current, with owners and dates?
Are audit logs being reviewed, and who does it?
Has everyone completed this year's training? Follow up on the stragglers.
Did we run phishing tests, and what did we learn?
Do staff know how to report incidents, and do they feel safe doing so?
Do we have a one-page incident response plan with phone numbers?
Do we know what our cyber insurance requires and whom to call?
Are server and network closets locked, and who has keys?
Which hardware reaches end of life next year? Plan purchases across budget periods instead of facing a large surprise.
Which risks from the risk analysis remain unaddressed? Tie them to budget requests.
Are we spending on tools nobody uses? Retire duplicates.
Do not try to fix everything at once. Sort findings into three groups.
Fix now: Quick, high-impact items such as removing old accounts or enabling MFA.
Plan for the first quarter: Projects like restore tests, policy updates and training.
Budget for the year: Hardware replacement, segmentation, new tools.
Assign an owner and a date to each item, and review progress quarterly.
Present the findings in plain terms: what is strong, what is weak, what the plan is and what it will cost. Leadership and boards are expected to take reasonable care of resident information, and a documented review is evidence that you do.
UnityCare IT can walk through this checklist with your team, gather the reports and turn the findings into a prioritized plan for the coming year. If you would like a second set of eyes, contact us.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034