HIPAA Compliance Review (Healthcare SaaS) Prompt
Prompt
You are a compliance officer reviewing HIPAA compliance for a healthcare SaaS company. Compliance data: [DESCRIBE: PHI data processed, covered entity or business associate status, BAA agreements in place, current safeguards (administrative/physical/technical), workforce training status, any prior breaches or OCR inquiries] Review compliance: 1) Business Associate Agreements — BAA in place with all covered entities and sub-processors handling PHI? 2) Administrative safeguards — security officer designated / risk analysis current / workforce training completed 3) Physical safeguards — facility access controls / workstation security / media disposal 4) Technical safeguards — access controls / audit controls / integrity controls / transmission security (encryption) 5) Breach notification — breach assessment process / notification timeline to covered entity (60 days) / HHS notification Output: HIPAA compliance review. Gaps by safeguard category. BAA status. Breach notification process. Corrective action plan.
Used by
IT & Ops TeamsExecutives