HIPAA Audit Checklist for the Cath Lab: USB Angiogram Export Controls and Device Vendor BAAs

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Audit Checklist for the Cath Lab: USB Angiogram Export Controls and Device Vendor BAAs

Kevin Henry

HIPAA

August 20, 2026

7 minutes read
Share this article
HIPAA Audit Checklist for the Cath Lab: USB Angiogram Export Controls and Device Vendor BAAs

This HIPAA audit checklist helps you verify that the cath lab protects electronic protected health information (ePHI) end to end. It focuses on USB angiogram export controls, device media controls, and device vendor business associate agreement requirements.

Administrative Safeguards for ePHI Protection

Governance and security official designation

  • Designate a Security Official with documented authority to enforce policies, lead risk analysis, and approve exceptions.
  • Define roles for imaging leadership, biomedical engineering, IT security, compliance, and privacy.

Policies, procedures, and minimum necessary

  • Publish policies covering data handling in the cath lab, including media controls for removable storage and minimum-necessary access to ePHI.
  • Standardize user provisioning, access reviews, and termination timelines for all cath lab systems.

Incident response and breach notification procedures

  • Maintain an incident playbook for lost media, misdirected exports, malware, and unauthorized disclosures.
  • Define breach notification procedures, decision trees, timelines, and required approvals.

Oversight, audit logging, and accountability

  • Require audit logging for logins, export actions, media insert/removal events, configuration changes, and remote vendor sessions.
  • Review logs routinely, escalate anomalies, and document outcomes in your risk management plan.

Physical Security of Cath Lab Equipment

Facility and device protections

  • Control access to procedure rooms, consoles, and image review areas with badges and visitor logs.
  • Secure angiography systems, modality workstations, and PACS gateways with locked racks, cable locks, and tamper seals.

Media and port protections

  • Restrict physical USB ports where feasible, using port blockers or locked service covers on consoles and viewers.
  • Store approved encrypted USB media in a locked cabinet with check-in/check-out tracking.

Asset lifecycle and sanitation

  • Maintain an inventory of cath lab devices, storage media, and their ePHI exposure.
  • Document sanitization or destruction of media and devices prior to reuse, return, or disposal.

Technical Measures for Access Control

Identity, authentication, and authorization

  • Issue unique user IDs; require MFA for remote access and privileged roles.
  • Enforce least-privilege roles for techs, nurses, physicians, vendor engineers, and administrators.

Session management and encryption

  • Set session timeouts and automatic screen locks at cath lab consoles and viewers.
  • Encrypt ePHI in transit (TLS) and at rest on servers and approved removable media.

System hardening and network segmentation

  • Segment imaging networks (e.g., VLANs) and restrict DICOM services to required endpoints.
  • Harden OS and applications; limit local admin rights and disable unneeded services.

Audit logging and monitoring

  • Forward system, application, and DICOM export logs to a centralized SIEM.
  • Alert on unusual export volumes, off-hours activity, or unknown USB device IDs.

USB Angiogram Export and Media Handling

Approved use cases and media controls

  • Limit exports to patient care coordination, surgical planning, and authorized research with IRB approval.
  • Allow only organization-issued, hardware-encrypted USB drives; prohibit personal media.

Standard operating procedure (SOP) for exports

  1. Verify necessity and minimum dataset; confirm patient identifiers and destination.
  2. Authenticate to the workstation; confirm role permits export.
  3. Insert an approved encrypted USB; device control software auto-enforces encryption and logs mount events.
  4. Export the angiogram using the approved viewer with default anonymization/profile settings where applicable.
  5. Record export metadata: MRN, accession, study UID, user, time, purpose, destination, and media serial number.
  6. Scan exported media for malware, then deliver via secure handoff or courier; avoid email attachments.
  7. Import to PACS/VNA or destination system within a defined window (e.g., 24–48 hours).
  8. Return media for check-in; verify checksum; securely wipe or reinitialize the encrypted volume.

Preventive and detective controls

  • Use device control to block unapproved USB classes and to enforce read-only mounts when exporting viewer-only packages.
  • Whitelist authorized applications and DICOM destinations; disable OS drag-and-drop to removable media.
  • Enable automatic watermarking or on-screen overlays when feasible to deter misuse.
  • Correlate export logs with user access logs; investigate mismatches promptly.

Ensuring Vendor Compliance with BAAs

Business associate agreement requirements

  • Define permitted uses/disclosures, minimum necessary, and required safeguards for ePHI on vendor-managed systems.
  • Flow down obligations to subcontractors; require equivalent protections and oversight.

Clauses tailored to device vendors

  • Breach notification procedures with clear timelines, event content, and cooperation duties.
  • Security baselines for devices: encryption, access control, audit logging, patching SLAs, and vulnerability disclosure expectations.
  • Remote access controls: jump hosts, MFA, time-bound approvals, and session recording.
  • Data location, return, and destruction terms; incident evidence preservation and audit rights.
  • Indemnification and insurance appropriate to clinical risk and data volume.

Due diligence and ongoing assurance

  • Collect security questionnaires, MDS2, and test results; map controls to your risk management plan.
  • Review BAA compliance during device acceptance testing and at contract renewal.

Risk Assessment and Remediation Planning

Structured risk analysis

  • Identify assets (modalities, viewers, PACS, USB media), threats, and vulnerabilities affecting ePHI.
  • Rate likelihood and impact; document existing controls and residual risk in a centralized register.

High-priority cath lab risks to evaluate

  • Unauthorized USB exports or lost media; misconfigured DICOM shares and open network paths.
  • Vendor remote access without MFA or session capture; delayed security patches on imaging systems.

Actionable remediation and tracking

  • Create a time-bound remediation plan with owners, due dates, funding needs, and acceptance criteria.
  • Sequence quick wins (30 days), near-term fixes (90 days), and strategic initiatives (180+ days).

Workforce Training and Documentation

Role-based training content

  • Cover ePHI handling, media controls, USB export SOPs, phishing awareness, and incident reporting.
  • Include hands-on practice for exports and secure transfers relevant to cath lab workflows.

Frequency and recordkeeping

  • Provide training at hire, annually, and after policy or technology changes.
  • Document attendance, curricula, assessments, and acknowledgments; retain training records per HIPAA documentation requirements.

Documentation essentials

  • Maintain current policies, BAAs, device inventories, access reviews, and audit logging procedures.
  • Record Security Official decisions, risk acceptance memos, and your living risk management plan.

Summary

This checklist aligns administrative, physical, and technical safeguards with strict USB export media controls and enforceable vendor BAAs. By logging decisively, training routinely, and executing a practical risk management plan, you reduce the chance of ePHI exposure while supporting safe, efficient cath lab care.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

FAQs

What are the key elements of a HIPAA audit in the cath lab?

Auditors look for documented governance and a security official designation, role-based policies, breach notification procedures, and complete audit logging. They also verify physical protections of imaging gear, technical access controls, rigorous media controls for exports, enforceable device vendor BAAs, a current risk assessment with an active risk management plan, and evidence of workforce training and documentation.

How should USB angiogram exports be controlled to comply with HIPAA?

Limit exports to defined use cases, allow only organization-issued encrypted USB drives, and enforce exports through an approved viewer. Log user, time, purpose, study identifiers, and media serial numbers; scan media for malware; hand off securely; import to PACS/VNA promptly; and wipe or reinitialize media on return. Use device control to block unapproved USBs, whitelist apps, and alert on anomalies.

What clauses must be included in device vendor BAAs?

Include business associate agreement requirements covering permitted uses, minimum necessary, safeguards, subcontractor flow-downs, and breach notification procedures. Add device-focused terms for encryption, access control, audit logging, patch SLAs, vulnerability disclosure, remote access with MFA and session capture, data return/destruction, audit rights, and appropriate indemnification and insurance.

How often should workforce HIPAA training be documented?

Document training at onboarding, at least annually, and whenever policies or systems change or after incidents. Retain attendance, content, and assessments alongside acknowledgments for the required documentation retention period to demonstrate ongoing compliance.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles