| R-001 |
____ |
User Access Management |
Cybersecurity / Compliance |
Former employee accounts may still access systems containing ePHI. |
Termination process is not connected to IT account removal. |
Unauthorized access, HIPAA violation, reputation damage. |
Manual account review, password policy. |
4 |
5 |
20 |
Weak |
16 |
High |
IT Manager |
Create formal offboarding checklist and disable accounts immediately after termination. |
IT / HR |
____ |
Open |
____ |
Review all active users quarterly. |
| R-002 |
____ |
Email Security |
Cybersecurity |
Employees may send or receive ePHI through unsecured email. |
Lack of secure email system or unclear email policy. |
ePHI exposure, breach notification, regulatory investigation. |
Basic spam filtering. |
4 |
5 |
20 |
Weak |
15 |
High |
Compliance Officer |
Implement secure email encryption and train employees on approved communication methods. |
IT Manager |
____ |
Open |
____ |
Confirm whether current email provider supports encryption. |
| R-003 |
____ |
Workstations / Laptops |
Cybersecurity / Operational |
Lost or stolen laptops may expose ePHI. |
Devices may not be encrypted or centrally managed. |
Data breach, patient notification, legal and compliance risk. |
Password login required. |
3 |
5 |
15 |
Moderate |
10 |
Medium |
IT Manager |
Enable full-disk encryption, endpoint management, and remote wipe capability. |
IT Team |
____ |
In Progress |
____ |
Prioritize laptops used outside the office. |
| R-004 |
____ |
Backup and Disaster Recovery |
Operational / Cybersecurity |
Backups may not be available or recoverable after ransomware or system failure. |
Backups are not tested regularly. |
Extended downtime, data loss, patient care disruption, financial loss. |
Daily backup configured. |
3 |
5 |
15 |
Moderate |
12 |
High |
Operations Manager |
Test backups regularly and document recovery results. Add offline or immutable backup protection. |
IT Manager |
____ |
Open |
____ |
Include EHR, file server, and billing system backups. |
| R-005 |
____ |
Employee Training |
Compliance / Cybersecurity |
Employees may mishandle ePHI or fall for phishing attacks. |
HIPAA and cybersecurity training is not completed regularly. |
Breach, unauthorized disclosure, ransomware infection, compliance failure. |
New-hire training only. |
4 |
4 |
16 |
Weak |
12 |
High |
Compliance Officer |
Provide annual HIPAA and security awareness training with phishing examples. |
HR / Compliance |
____ |
Open |
____ |
Track completion records. |
| R-006 |
____ |
Remote Access |
Cybersecurity |
Remote access may allow unauthorized users into internal systems. |
VPN or remote desktop access does not require MFA. |
System compromise, ransomware, unauthorized ePHI access. |
Username and password required. |
4 |
5 |
20 |
Weak |
16 |
High |
IT Manager |
Require MFA for all remote access and review remote access permissions. |
IT Team |
____ |
Open |
____ |
Disable unused remote accounts. |
| R-007 |
____ |
Vendor Management |
Compliance / Legal |
Vendors may access ePHI without proper agreements or security review. |
Business associate agreements may be missing or outdated. |
HIPAA compliance violation, third-party breach exposure, legal risk. |
Vendor list maintained informally. |
3 |
5 |
15 |
Weak |
12 |
High |
Business Owner / Compliance Officer |
Review vendors, confirm business associate agreements, and document vendor responsibilities. |
Compliance Officer |
____ |
Open |
____ |
Include IT, billing, cloud, software, and consulting vendors. |
| R-008 |
____ |
Patch Management |
Cybersecurity / Operational |
Systems may be vulnerable because security updates are missing. |
No formal patch management schedule. |
Malware infection, ransomware, system compromise, downtime. |
Updates installed manually. |
4 |
4 |
16 |
Moderate |
10 |
Medium |
IT Manager |
Create monthly patch review process and prioritize critical updates. |
IT Team |
____ |
In Progress |
____ |
Include servers, workstations, firewall, and network devices. |
| R-009 |
____ |
Physical Security |
Physical / Compliance |
Unauthorized visitors may access areas where ePHI is visible or stored. |
Visitor access is not controlled or documented. |
Unauthorized disclosure, theft, compliance issue. |
Locked front entrance. |
3 |
4 |
12 |
Moderate |
8 |
Medium |
Office Manager |
Implement visitor sign-in process and restrict access to records and workstations. |
Office Manager |
____ |
Open |
____ |
Review screen privacy and paper record storage. |
| R-010 |
____ |
Incident Response |
Operational / Compliance |
Staff may not know what to do during a suspected breach or ransomware incident. |
No documented incident response plan. |
Delayed response, increased damage, missed reporting obligations. |
Informal escalation to management. |
3 |
5 |
15 |
Weak |
12 |
High |
Business Owner / IT Manager |
Create incident response plan with roles, contacts, reporting steps, and tabletop exercises. |
IT Manager / Compliance Officer |
____ |
Open |
____ |
Include cyber insurance and legal contact information. |