Home / Free checklist
Free resource

Home health IT and HIPAA readiness checklist

47 plain questions that show where your security, backups, vendors and paperwork stand today. Fifteen minutes and a pen. No sign-up, no email address, no tracking.

What it is

A self-check you can finish before lunch

It is written for the administrator, the office manager or the owner of a small California home health agency, and it needs no technical knowledge. Each question is something you could show a surveyor or an auditor today, or you could not.

  1. Answer honestly

    Yes only if you could prove it today. Unsure counts as No.

  2. Count the No and Unsure answers

    The last page explains what the number means, and what it does not.

  3. Fix the starred items first

    13 of the 47 questions are marked as the ones that do the most to reduce risk.

How to read your score

No or UnsureMeaning
0 to 5A strong foundation. Keep the evidence current and test what you have.
6 to 15Some gaps. Work through the starred items first; most are quick to fix.
16 or moreSignificant gaps. A long list is a starting point, not a verdict. Start with the starred items and ask for help.

Not a compliance test. It is general guidance for small agencies. Whether your agency complies with HIPAA, California law or an accreditation standard is for your compliance officer and counsel to decide.

Inside the checklist

Nine sections, in the order trouble usually arrives

7 questions

Sign-in and access

  • Every person has their own sign-in. There are no shared logins or shared passwords.
  • Multi-factor sign-in is on for every account, administrators first.
6 questions

Computers and phones

  • Every laptop and phone that touches PHI is encrypted.
  • Screens lock automatically after a few minutes of inactivity.
5 questions

Email and messages

  • Your email domain has SPF, DKIM and DMARC records, so it is hard to fake your address.
  • Email filtering blocks phishing messages and dangerous attachments.
5 questions

Network and Wi-Fi

  • A business-grade firewall is in place, with current firmware and logging switched on.
  • Guest Wi-Fi is on a separate network from staff devices and systems.
6 questions

Backup and recovery

  • Microsoft 365 mail and files have a separate backup. Microsoft's own retention is not a backup.
  • At least one backup copy cannot be changed or deleted from an ordinary office computer (offline or immutable).
5 questions

Vendors and agreements

  • You keep a list of every vendor that can see PHI: EMR, phones, email, billing, shredding, IT, cloud.
  • A signed Business Associate Agreement is on file for each one.
4 questions

AI and new tools

  • You have a written rule for AI tools: what may and may not be put into them.
  • Staff know never to paste PHI into public AI chat tools.
4 questions

People and training

  • Every new hire gets HIPAA and security training before they can reach PHI.
  • All staff repeat it at least once a year, and you keep a record of who and when.
5 questions

Paperwork you can show a surveyor

  • A written risk analysis exists and was updated in the last 12 months.
  • A risk management plan lists what will be fixed, who owns each item and by when.

Want help with the No answers?

Bring the sheet to a free working session and we will turn it into a ranked fix list.

Book a working session