Documentation8 min read

HIPAA Technical Safeguards: An IT Checklist for Healthcare

The administrative, physical, and technical safeguards HIPAA requires — mapped to the real tools and configurations that satisfy them, with a practical IT checklist for healthcare organizations.

Published August 5, 2026Updated August 25, 2026
HIPAAComplianceHealthcare ITePHIEncryptionMFASIEMBAA

Why HIPAA matters to your IT team

For healthcare organizations and their business associates, HIPAA's Security Rule is not a checkbox — it is a continuous operational requirement. The HHS Office for Civil Rights (OCR) levied over $14 million in HIPAA penalties in 2024 alone, with the most common findings being missing risk analyses, lack of encryption, and inadequate access controls.

The Security Rule defines three categories of safeguards for protecting electronic protected health information (ePHI). Here is what each category means for your IT environment and the specific controls that satisfy them.

HIPAA SECURITY RULE — THREE SAFEGUARD CATEGORIES ADMINISTRATIVE • Annual risk analysis • Security policies & procedures • Workforce training • BAA with every vendor • Incident response plan • Contingency plan / DR PHYSICAL • Facility access controls • Workstation use policy • Workstation security • Device & media controls • Secure media disposal • Equipment inventory TECHNICAL • Unique user IDs + MFA • Automatic logoff • Audit controls / SIEM • Encryption at rest & transit • Integrity controls • Transmission security (TLS) IDENETY maps each control to your stack: SentinelOne · Adlumin SIEM · Microsoft 365 · Datto Backup and maintains the documentation evidence required for OCR audits. Figure 1 — HIPAA Security Rule: three safeguard categories and the controls that satisfy each.

Figure 1 — HIPAA Security Rule safeguard categories. Technical safeguards are the IT team's primary responsibility and the most common area of OCR findings.

Technical safeguards — the IT checklist

HIPAA RequirementImplementationTool / Control
Access control — unique user IDsNo shared accounts; every user has a named identityMicrosoft Entra ID / Active Directory
Access control — MFAMulti-factor authentication on all systems touching ePHIMicrosoft Authenticator, Entra Conditional Access
Automatic logoffSession timeout after inactivity on workstations and appsIntune policy, GPO, application settings
Audit controlsCentralized logging of all access to ePHI systemsAdlumin SIEM, Microsoft Purview Audit
Integrity controlsProtections against improper alteration or destruction of ePHIEDR (SentinelOne), file integrity monitoring
Transmission securityEncryption of ePHI in transitTLS 1.2+, VPN for remote access
Encryption at restDisk and database encryption for all ePHI storageBitLocker, Azure encryption, Datto encryption

Administrative safeguards — what IT owns

While administrative safeguards are often considered a compliance or legal function, IT owns several of them directly:

  • Annual risk analysis: A documented assessment of threats and vulnerabilities to ePHI. This is the #1 finding in OCR audits — organizations either skip it or do it once and never update it.
  • Incident response plan: A documented procedure for identifying, containing, and reporting security incidents involving ePHI, including breach notification timelines (60 days to HHS for breaches affecting 500+ individuals).
  • Contingency plan: Backup and disaster recovery procedures with tested RTOs. IDENETY uses Datto with documented restore SLAs.
  • Business Associate Agreements (BAAs): Every vendor that touches ePHI — including your IT provider — must sign a BAA. IDENETY provides BAAs for all HIPAA clients.
IDENETY HIPAA policy: Healthcare clients are onboarded on the COMPLETE plan only, with BAA management included. This ensures encryption, EDR, SIEM, and compliant backup are all in place from day one — and that the annual risk analysis is documented and updated.

Documentation is a control too

OCR auditors want evidence, not assertions. "We do encryption" is not sufficient — you need to show the BitLocker policy, the Intune compliance report, and the log proving it was enforced on every device. IDENETY maintains this documentation as part of the COMPLETE plan and produces it on demand for audits or due diligence requests.

Physical safeguards — quick wins

  • Privacy screens on workstations in clinical areas where patients can see the screen.
  • Automatic screen lock (5 minutes or less) enforced via Intune policy.
  • Secure media disposal — NIST 800-88 wiping or physical destruction for decommissioned drives.
  • Equipment inventory — every device that can access ePHI must be tracked.

See our HIPAA & Wireless Networks article for wireless-specific compliance requirements in healthcare facilities.

Contact our engineers to schedule a HIPAA technical safeguards assessment for your organization.

HIPAA IT compliance for healthcare organizations in San Antonio, Austin, Houston, and Texas. IDENETY delivers HIPAA-aligned IT infrastructure, wireless, and cybersecurity services to healthcare clients across Texas and nationwide. Headquartered in San Antonio, TX. Call (726) 224-2222.
About the Author