Not six things. Every part of HIPAA a covered entity has to run, each one composed for your clinic and tracked against your own records. Pick one to see exactly how it works.
Most risk assessment tools hand you a form you fill in once. This is computed from the records you keep about your clinic, with the reasoning shown behind every determination.
Every threat with a decided tier needs a remediation task, the plan needs an attestation within ninety days, and overdue critical items surface rather than sitting quietly.
A graduated sanction ladder composed for your clinic, acknowledgment tracked per person, and open sanction evaluations that cannot quietly stay open.
Both officers appointed with signed designation evidence, a written rationale when one person holds both roles, and a policy that names where complaints actually go.
A composed minimum-necessary policy covering routine and non-routine disclosures, with your clearinghouse determination and consistency attestation tracked and kept current.
A composed authorization policy plus per-member tracking: every active member holds a current authorization record, every active role has a matrix row, and supervisor-required roles have one named.
A composed clearance policy plus per-member tracking: every active member has a clearance record, is fully cleared with a reference check and confidentiality acknowledgment, and rechecks are current.
A composed offboarding policy plus tracking on the paperwork: every terminated member has a termination event, a signed letter, and a completed checklist, with nothing left stale.
Every active member assigned, every assignment completed, and completions aging out on their annual or biennial window instead of counting forever.
A composed facility-access policy shaped by whether you run a premises or work from homes, plus a check that flags a terminated staff member still holding an active access assignment.
A composed workstation policy shaped by your device posture, plus a per-asset check on whether every workstation, tablet, and phone has a current physical-safeguards attestation.
Per-asset disposal tracking: every clinic-owned storage device that reaches retired or disposed needs a sanitization record, every paper disposal needs a certificate, every disposal vendor needs a current BAA.
A policy composed from your clinic's actual facts, a role-by-role access matrix, and a running check on whether every PHI vendor's access attestation is current.
A composed audit-controls policy, plus a running check on whether each PHI vendor's log retention is configured for six years and whether a log review has actually been recorded this quarter.
A composed integrity policy covering record finalization and correction, plus tracking on vendor integrity attestations and your own recorded decision on the addressable mechanism.
A composed authentication policy requiring MFA and per-person credentials, plus a running check on whether every PHI vendor's authentication attestation is current.
A composed transmission-security policy plus a PHI data flow inventory, tracking whether every flow you have mapped is recorded as encrypted in transit.
A dated notice with all sixteen required content elements attested, tied to your current privacy officer, posted where it applies, with client acknowledgment coverage computed from your roster.
Access, amendment, and accounting requests tracked against their recorded deadlines, so a request past its thirty-day clock surfaces as a finding instead of a surprise.
Every PHI-involved incident needs a finalized breach review, every notification obligation carries a deadline, and the annual HHS log for sub-500 breaches has a March 1 date on it.
Every open security incident has an owner, every closed one carries a resolution, closure decision, and mitigation record.
A periodic evaluation assembled within cadence, covering a full period rather than a snapshot, with your risk analysis current underneath it.
Backup and disaster recovery attested by every PHI vendor, platform backup on file, a criticality analysis recorded, and a recovery test within the last twelve months.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.