Generate a HIPAA Security Rule technical safeguards audit checklist with PHI protection controls and risk analysis.
You are a HIPAA compliance specialist. Generate a technical safeguards audit for a healthcare application. ## Application Details - **System**: [SYSTEM e.g. EHR portal / telehealth platform / patient scheduling / claims processing] - **Architecture**: [ARCH e.g. web app + API + database / mobile app / SaaS] - **Cloud**: [CLOUD e.g. AWS GovCloud / Azure Healthcare / GCP with BAA] - **PHI Types**: [PHI e.g. patient name, DOB, SSN, medical records, lab results, imaging] ## Technical Safeguards (45 CFR 164.312) ### Access Control (§164.312(a)) - [ ] Unique user identification for all users accessing PHI - [ ] Emergency access procedure for PHI in emergencies - [ ] Automatic logoff after [TIMEOUT e.g. 15] minutes inactivity - [ ] Encryption and decryption of PHI at rest - [ ] Role-based access with minimum necessary principle - [ ] Workforce access review process (quarterly) - [ ] Access provisioning and deprovisioning workflow - [ ] Break-glass procedures with audit trail - **Evidence**: Access control matrix, user provisioning logs, timeout configuration ### Audit Controls (§164.312(b)) - [ ] Audit logging for all PHI access, creation, modification, deletion - [ ] Log fields: user ID, timestamp, action, resource, source IP, outcome - [ ] Audit logs tamper-proof and centralized - [ ] Log retention: minimum 6 years (HIPAA requirement) - [ ] Regular audit log review process (defined frequency) - [ ] Automated alerting for suspicious access patterns - [ ] Audit trail for system admin activities - **Evidence**: Sample audit logs, review procedures, alert configurations ### Integrity (§164.312(c)) - [ ] Mechanism to authenticate PHI integrity (checksums/signatures) - [ ] Protect PHI from improper alteration or destruction - [ ] Database integrity constraints on PHI fields - [ ] Backup integrity verification procedures - [ ] Version control for PHI modifications - **Evidence**: Integrity check procedures, backup verification logs ### Person or Entity Authentication (§164.312(d)) - [ ] Multi-factor authentication for all PHI access - [ ] Strong password policy (12+ chars, complexity, 90-day rotation) - [ ] Certificate-based authentication for system-to-system - [ ] Biometric or token-based options for clinical workstations - [ ] Account lockout after failed attempts - **Evidence**: MFA configuration, password policy, authentication logs ### Transmission Security (§164.312(e)) - [ ] TLS 1.2+ for all PHI in transit - [ ] Encryption for email containing PHI (TLS or S/MIME) - [ ] VPN or private connectivity for remote access - [ ] HL7 FHIR API secured with OAuth2+TLS - [ ] No PHI in unencrypted messages or SMS - **Evidence**: TLS configuration, network diagrams, encryption certificates ### Risk Analysis - Threat identification for each PHI type - Vulnerability assessment of technical controls - Risk rating: likelihood x impact matrix - Remediation priorities with timelines - Residual risk acceptance documentation Generate the complete audit checklist with gap analysis and remediation roadmap.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro.
Describe your healthcare application and PHI types handled. Work through each safeguard section. Document evidence for each control. Create remediation tickets for gaps with responsible owners.
Initial release
Sign in and download this prompt to leave a review.