• Section 1: Foundational & Corporate Compliance
  • Section 2: HIPAA Security & Privacy
  • Section 3: OSHA & Staff Safety
  • Section 4: Staff Training & Credentialing
  • Section 5: Technical Security Controls
Section 1: Foundational & Corporate Compliance
1. What is the current status of your Medical Practice's formal compliance program?
2. How are your key operational policies and procedures (P&Ps) stored?
3. Do you have signed Business Associate Agreements (BAAs) with all third-party vendors who handle patient data?
Section 2: HIPAA Security & Privacy
1. When was your last formal HIPAA Security Risk Analysis (SRA) completed?
2. How do you manage staff access to electronic patient health information (ePHI)
3. Are all devices that store or access ePHI (laptops, servers, mobile devices) encrypted?
Section 3: OSHA & Staff Safety
1. Is your OSHA Exposure Control Plan (for bloodborne pathogens) reviewed and updated annually?
2. How do you maintain your log of workplace injuries and illnesses (OSHA 300 Log)?
3. How do you manage Safety Data Sheets (SDS) for hazardous chemicals used in your facility?
Section 4: Staff Training & Credentialing
1. How do you prove that a staff member has read and understood a new or updated policy?
2. How do you track the expiration dates of staff licenses and certifications?
3. Do you perform primary source verification for all clinical licenses upon hiring?
Section 5: Technical Security Controls
1. Have you performed an external network vulnerability scan in the last 90 days?
2. How frequently do you conduct phishing awareness training or simulations for your staff?
3. Are all critical systems containing patient data backed up daily, with backups stored securely off-site or in the cloud?
4. Is the use of administrative (IT) privileges on computers and servers restricted to only those who require it?