Healthcare IT Security Compliance Assessment
Evaluate your organization's adherence to key healthcare IT security standards with this comprehensive checklist.
Organization Name
*
Department or Unit Assessed
*
Assessor's Full Name
*
First Name
Last Name
Assessor's Email Address
*
example@example.com
Date of Assessment
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Access Control Compliance
*
Rows
Fully Implemented
Partially Implemented
Not Implemented
Not Applicable
Unique user logins required for all systems
1
2
3
4
Regular review of user access rights
5
6
7
8
Automatic logoff after inactivity
9
10
11
12
Data Protection & Encryption Compliance
*
Rows
Fully Implemented
Partially Implemented
Not Implemented
Not Applicable
Sensitive data is encrypted at rest
13
14
15
16
Sensitive data is encrypted in transit
17
18
19
20
Regular data backups are performed and tested
21
22
23
24
Staff Training & Awareness
*
Not at all
1
2
3
4
Completely
5
1 is Not at all, 5 is Completely
Incident Response Procedures
*
Documented and regularly tested
Documented but not tested
Not documented
Other
Physical Security Controls (e.g., secure server rooms, access badges)
*
Server rooms are access-controlled
Visitor logs are maintained
Workstations are locked when unattended
Other
Additional Comments or Notes
Submit Assessment
Should be Empty: