Year-End IT Risk Review: A Checklist for Facility Leaders

December is a natural time to review. Budgets are closing, planning for next year is underway, and some departments slow down. A one-day look at your technology risks now can shape your priorities and budget for the coming year. This checklist is written for administrators and compliance leaders, not just technicians, and each item comes with a question you can ask your IT provider.

1. People and accounts

Who has access to what? Ask for a list of all user accounts with their roles. Compare it against your current staff roster.

Are there former employees, agency staff or vendors with active accounts? Disable anything unused.

Do any accounts have administrator rights unnecessarily? Reduce them.

Are there shared logins? Replace them with individual accounts wherever possible.

Is multi-factor authentication on for email, remote access and administrators? Confirm with a report.

2. Devices

Do we have a current inventory of computers, tablets, phones, printers and network equipment?

Which devices are old or no longer supported by the manufacturer? List them for replacement planning.

Are all laptops and portable devices encrypted?

Is endpoint protection installed and reporting on every computer and server?

Are any devices unaccounted for?

3. Patching and updates

What percentage of systems are fully patched?

Are firewalls, switches and access points up to date?

Are there systems we cannot patch, and what protects them in the meantime?

4. Backups and recovery

When did we last restore from backup? If more than six months ago, schedule a test.

Are backups protected from ransomware with offline or immutable copies?

Do we have a written disaster recovery plan, and does it match today's systems?

Are downtime forms printed and current?

5. Vendors and agreements

Do we have a current list of vendors that handle PHI, with business associate agreements on file?

Which vendor contracts renew soon? Use that as leverage for service or security improvements.

Have we asked important vendors about their security practices lately?

Are former vendors' accesses removed?

6. HIPAA documentation

When was our last security risk analysis? Update it if it is more than a year old or if major changes occurred.

Is our remediation plan current, with owners and dates?

Are policies and procedures reviewed this year?

Do we have records of workforce training?

Is our breach response plan up to date, with correct contacts?

Are audit logs being reviewed, and who does it?

7. Staff training and awareness

Has everyone completed this year's training? Follow up on the stragglers.

Did we run phishing tests, and what did we learn?

Do staff know how to report incidents, and do they feel safe doing so?

8. Incident readiness

Do we have a one-page incident response plan with phone numbers?

Have we run a tabletop exercise this year?

Do we know what our cyber insurance requires and whom to call?

Is there an after-hours contact for IT emergencies?

9. Physical security

Are server and network closets locked, and who has keys?

Are screens at nurses' stations positioned to limit viewing by visitors?

Are devices secured or stored safely?

Is media and paper disposal handled properly?

10. Budget and planning

Which hardware reaches end of life next year? Plan purchases across budget periods instead of facing a large surprise.

Which risks from the risk analysis remain unaddressed? Tie them to budget requests.

Are we spending on tools nobody uses? Retire duplicates.

Turning findings into a plan

Do not try to fix everything at once. Sort findings into three groups.

Fix now: Quick, high-impact items such as removing old accounts or enabling MFA.

Plan for the first quarter: Projects like restore tests, policy updates and training.

Budget for the year: Hardware replacement, segmentation, new tools.

Assign an owner and a date to each item, and review progress quarterly.

Share results with leadership

Present the findings in plain terms: what is strong, what is weak, what the plan is and what it will cost. Leadership and boards are expected to take reasonable care of resident information, and a documented review is evidence that you do.

Getting help

UnityCare IT can walk through this checklist with your team, gather the reports and turn the findings into a prioritized plan for the coming year. If you would like a second set of eyes, contact us.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034