Loading...
Please wait while we prepare your content
Please wait while we prepare your content
Use this checklist to assess your healthcare facility's physical security compliance with HIPAA requirements.
Physical access to areas containing PHI is restricted
Access control system logs all entry/exit events with timestamps
Unique credentials assigned to each authorized individual
Terminated employee access revoked immediately
Visitor access is logged and escorted in PHI areas
After-hours access restricted and monitored
Emergency access procedures documented
Access logs retained for minimum 6 years
Workstations positioned to prevent unauthorized viewing
Privacy screens installed on monitors in public areas
Automatic screen lock enabled (15 min or less)
Physical access to workstations restricted
Portable devices secured when not in use
Clean desk policy implemented
Cameras cover all entry points to PHI areas
No cameras in patient treatment areas or restrooms
Video footage access restricted to authorized personnel
Retention period meets state requirements (typically 30-90 days)
Signage notifies visitors of video surveillance
Video system has backup power capability
Inventory of all hardware containing PHI maintained
Media disposal procedures documented (shredding, degaussing)
Data backup media stored securely offsite
Movement of hardware with PHI is tracked
USB and removable media policies enforced
Mobile device management (MDM) implemented
Emergency access procedures documented
Contingency plan for facility access during outages
Backup power for security systems
Emergency contact list maintained and updated
Annual testing of emergency procedures
Recovery procedures for compromised access credentials
Disclaimer: This checklist is provided for informational purposes only and does not constitute legal advice. HIPAA compliance requirements may vary based on your specific situation. Consult with a qualified HIPAA compliance professional for a comprehensive assessment.
We specialize in security systems for healthcare facilities with built-in HIPAA compliance features.