HIPAA and HITECH are often discussed as if they were two separate compliance programs. For cybersecurity planning, it is more useful to see how they fit together. The HIPAA Security Rule sets safeguards for electronic protected health information (ePHI); the HITECH Act strengthened enforcement, extended direct responsibility for parts of the HIPAA Rules to business associates, and established breach-notification requirements later implemented in the HIPAA Breach Notification Rule. HHS explains that relationship in its current Security Rule summary.

This checklist helps an independent medical, dental, behavioral-health, or specialty practice organize the cybersecurity portion of that work. It does not address every Privacy Rule requirement, every fact-specific breach decision, or every Tennessee law that could apply.

WTSS brings years of healthcare IT experience and years of hands-on experience implementing privileged access management in healthcare environments to address HITRUST requirements. That background informs the operational focus of this checklist: controls must work in clinical and business workflows, produce useful evidence, and remain supportable after implementation.

This is general cybersecurity guidance, not legal advice or a compliance determination. HIPAA applies only to covered entities and business associates as defined by federal law. Your obligations depend on your role, data, contracts, systems, and the facts of any incident. Use qualified legal counsel for legal conclusions and notification decisions.

What HITECH changes—and what it does not

HITECH did not replace HIPAA. Among other changes, it made business associates directly liable for specified HIPAA requirements and gave HHS authority to enforce Security Rule violations against them. HHS identifies the provisions for which business associates may be directly liable.

HITECH also created the federal breach-notification framework for unsecured PHI. The resulting HIPAA Breach Notification Rule requires notifications to affected individuals and HHS, with additional media notice for breaches affecting more than 500 residents of a state or jurisdiction. Timing, content, exceptions, and risk assessment are fact-specific; HHS maintains the controlling overview and reporting links.

A separate 2021 HITECH amendment requires OCR to consider adequately demonstrated “recognized security practices” that were in place during the prior 12 months in certain Security Rule enforcement and audit activities. HHS does not describe this as a safe harbor or substitute for complying with the HIPAA Rules. OCR provides current educational material on documenting those practices.

An eight-part HIPAA and HITECH cybersecurity checklist

1. Confirm your role and map where ePHI goes

First determine whether the organization is a HIPAA covered entity, a business associate, or both in different relationships. HHS says covered entities include health plans, clearinghouses, and healthcare providers that conduct certain transactions electronically; business associates perform specified functions or services involving PHI on behalf of covered entities. Use HHS’s covered-entity guidance and business-associate guidance as starting points.

  • Inventory EHR, billing, imaging, laboratory, email, file-sharing, backup, telehealth, patient-portal, mobile, and paper-to-digital workflows.
  • Record where ePHI is created, received, maintained, and transmitted.
  • Include outsourced IT, cloud services, support vendors, connected devices, and subcontractors.
  • Assign an owner to each system and data flow.
2. Document an enterprise-wide risk analysis

The Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities to ePHI. OCR says the analysis must cover all ePHI an organization creates, receives, maintains, or transmits, regardless of its medium or location. OCR does not prescribe one universal methodology or a fixed review frequency. Its current risk-analysis guidance explains the required scope and documentation.

  • Identify threats, vulnerabilities, existing safeguards, likelihood, and potential impact.
  • Document risk levels and corrective actions instead of relying on an undocumented conversation or questionnaire.
  • Revisit the analysis after meaningful changes such as a new EHR, acquisition, office move, cloud migration, or incident.
  • Connect each accepted or remediated risk to an accountable owner and review date.
3. Turn risks into a managed security plan

Risk analysis identifies and measures risk; risk management is the process of selecting and implementing reasonable and appropriate measures. The Security Rule is flexible and scalable, but that flexibility requires decisions to be grounded in the regulated entity’s environment. HHS groups the required protections into administrative, physical, and technical safeguards.

  • Prioritize risks to confidentiality, integrity, and availability of ePHI.
  • Document chosen safeguards, responsible people, target dates, and residual risk.
  • Cover contingency planning, backups, emergency operations, and restoration—not only prevention.
  • Evaluate whether safeguards remain effective when technology or operations change.
4. Control workforce, administrator, and vendor access

The Security Rule addresses workforce authorization, access management, termination procedures, access controls, authentication, and audit controls. Its technical safeguards are not a product shopping list; the practice must implement reasonable and appropriate measures based on its risk analysis. HHS summarizes each safeguard and implementation specification.

  • Use unique accounts and give users only the access their work requires.
  • Separate routine accounts from administrator accounts and protect remote and privileged access with MFA where the risk analysis supports it.
  • Approve, record, review, and promptly remove employee and contractor access.
  • Inventory service accounts, shared credentials, emergency accounts, remote-support tools, and vendor access.
  • Enable logs that can help reconstruct access and security-relevant changes.

For a deeper implementation guide, use the WTSS privileged-access checklist for small Tennessee healthcare practices.

5. Harden systems and make encryption decisions deliberately

OCR’s January 2026 guidance connects system hardening with Security Rule areas including access control, encryption, audit controls, and authentication. It recommends enabling and correctly configuring security measures in the context of risk analysis and risk management. The guidance discusses baselines, configuration, unnecessary services, patching, and monitoring.

  • Maintain supported systems, secure configurations, patches, endpoint protection, and tested backups.
  • Disable unnecessary accounts, services, software, and insecure remote-access paths.
  • Evaluate encryption for stored and transmitted ePHI and document the resulting implementation decision.
  • Test recovery and confirm that backup administration cannot be reached through the same compromised account used for daily work.
6. Inventory business associates and verify agreements

When a vendor creates, receives, maintains, or transmits PHI on a regulated entity’s behalf, a business associate relationship may exist. HHS lists cloud providers, EHR and IT support vendors, certain app developers, and some device technicians among its examples. Required written agreements must define permitted uses, safeguards, incident reporting, subcontractor obligations, and other terms. HHS publishes the required elements and sample provisions.

  • Maintain a vendor inventory tied to systems and PHI flows.
  • Confirm the agreement is executed before the vendor handles PHI and that it matches the actual service.
  • Record security and breach-reporting contacts, contractual deadlines, subcontractor use, data return, and termination procedures.
  • Do not assume that encryption or a vendor’s “HIPAA-ready” marketing removes the need for analysis or an agreement. HHS says even a no-view cloud provider maintaining encrypted ePHI is generally a business associate.
7. Build and rehearse an incident and breach process

A security incident is not automatically a reportable breach, and breach decisions should not be improvised. Establish who preserves evidence, contains systems, obtains legal advice, coordinates with business associates and insurers, performs the required assessment, and authorizes notices.

For breaches affecting 500 or more individuals, notice to HHS must be submitted without unreasonable delay and no later than 60 calendar days after discovery. Smaller breaches have a different federal reporting schedule. HHS provides the current reporting instructions and deadlines. Business associates also have notice obligations to covered entities under the rule.

Tennessee has a separate data-breach notification law. The Tennessee Attorney General summarizes it as generally requiring notice to affected Tennessee residents within 45 days when covered personal information was or may have been acquired by an unauthorized person, subject to the statute’s terms and a law-enforcement extension. Review the Attorney General’s summary and obtain counsel to reconcile potentially overlapping federal, Tennessee, contractual, and sector-specific duties.

8. Keep evidence that the program operates

The Security Rule requires regulated entities to maintain required policies, procedures, and documentation for six years after the later of creation or the date the document was last in effect. It also requires periodic review and updates when environmental or operational changes affect ePHI security. HHS details those documentation requirements.

  • Retain risk analyses, risk-management decisions, policies, evaluations, approvals, training records, incident records, vendor agreements, and evidence of corrective work as applicable.
  • Keep proof that safeguards operate: access reviews, backup tests, patch reports, vulnerability remediation, tabletop exercises, and follow-up records.
  • Document recognized security practices consistently if the organization intends to ask OCR to consider them under the HITECH amendment.

Do not implement a proposal as if it were current law

HHS proposed substantial Security Rule changes in January 2025, including more prescriptive cybersecurity requirements. As of September 1, 2026, HHS still identifies these changes as a proposed rule. Track the official NPRM page for status, but distinguish voluntary preparation from obligations under the rule currently in effect.

A manageable starting point

Begin with evidence, not a generic policy binder. Map ePHI and vendors, complete a documented risk analysis, identify the highest-impact gaps, and assign owners and dates. Then test whether access removal, backup restoration, incident escalation, and vendor notification work as written.

A checklist can organize the work, but it cannot guarantee compliance or eliminate cyber risk. The defensible outcome is a repeatable program that connects current legal advice, documented risk decisions, working safeguards, and evidence of follow-through.

Related guidance

Turn the Checklist Into a Working Program

Drawing on years of healthcare IT and healthcare PAM implementation experience, WTSS can help West Tennessee medical practices inventory systems and vendors, organize risk findings, improve privileged access, address HITRUST requirements, and build a practical remediation roadmap. An engagement reduces uncertainty and strengthens evidence; it does not guarantee certification or legal compliance. Legal counsel should review compliance and notification conclusions.

Explore Fractional CISO Services