Practice checklist · Field note
A practical security and HIPAA checklist for radiology organizations
A leadership view of the program areas that should stay visible across imaging systems, remote access, staff, vendors, facilities, and day-to-day operations.
A radiology organization’s security and HIPAA program should connect an accurate risk analysis to documented safeguards, accountable people, workforce practices, access control, vendor oversight, incident readiness, continuity, and evidence of ongoing review. The program should reflect the organization’s real systems and workflows, including PACS, RIS, modalities, image exchange, remote reading, cloud storage, billing, and support access.
Radiology creates a demanding environment for security and compliance: large clinical data sets, time-sensitive access, complex integrations, remote workflows, specialized equipment, long retention needs, and many organizations exchanging information. A generic policy binder cannot describe all of that by itself.
Leadership review
Seven program areas to keep in view
01Risk analysis and risk management
Confirm that the analysis identifies where electronic protected health information is created, received, maintained, or transmitted—and evaluates threats, vulnerabilities, current controls, likelihood, and impact across the actual environment.
- PACS, RIS, modalities, workstations, archives, interfaces, portals, and image exchange
- Remote reading, support access, mobile devices, and home networks where relevant
- Cloud, data center, billing, teleradiology, and other business associate relationships
- A documented plan for treating identified risks and tracking work to completion
02Governance, policies, and accountability
Assign clear security and privacy responsibilities. Policies and procedures should match current systems, roles, and decisions; approvals, exceptions, reviews, and updates should be documented.
03Identity and access
Review how access is requested, approved, authenticated, changed, periodically reviewed, and removed. Include privileged accounts, vendor support, service accounts, shared reading areas, emergency access, and termination workflows.
04Workforce readiness
Use role-appropriate security and HIPAA training, onboarding, reminders, and sanctions. Make it easy for staff to recognize and report suspicious messages, misdirected information, inappropriate access, lost devices, and other concerns.
05Vendors and business associates
Maintain an inventory of vendors that handle protected health information, appropriate agreements, due-diligence records, identified subcontractors, risk decisions, and a repeatable reassessment process. Use the PACS and image-storage vendor questions for technology evaluations.
06Detection and incident response
Define who receives alerts and reports, how the organization investigates, when specialists or counsel are involved, how evidence is preserved, and how the incident team communicates. Exercise the plan before a real event.
07Continuity and recovery
Document critical imaging workflows, dependencies, downtime procedures, backups, restoration priorities, alternate communication, and recovery roles. Test whether the organization can restore what it believes it can restore.
Keep it current
Use a cadence, not a one-time project
The HIPAA Security Rule is built around ongoing administrative, physical, and technical safeguards. NIST’s implementation guide also frames risk management as a continuing process. A useful operating cadence may include:
The exact timing should be risk-based and appropriate to the organization. What matters is that reviews are assigned, performed, documented, and tied to action.
ExpRad’s specialist referral
When the work needs a dedicated compliance team
Greg helps radiology leaders understand the operational and technology context. For the hands-on HIPAA compliance program—risk assessment, policies, training, vendor tracking, ongoing evidence, and security tools—Experienced Radiology Consulting refers clients to Live Compliance.
Primary sources
- U.S. Department of Health and Human Services: Summary of the HIPAA Security Rule
- U.S. Department of Health and Human Services: Guidance on Risk Analysis
- NIST Special Publication 800-66 Rev. 2: Implementing the HIPAA Security Rule
Educational information only. This checklist is not exhaustive, does not establish compliance, and is not legal, cybersecurity, or compliance advice. Requirements and appropriate safeguards depend on each organization’s circumstances.
