HIPAA Compliance Checklist for Scan Packet Vendors at Interstitial Lung Imaging Desks

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Checklist for Scan Packet Vendors at Interstitial Lung Imaging Desks

Kevin Henry

HIPAA

June 10, 2026

7 minutes read
Share this article
HIPAA Compliance Checklist for Scan Packet Vendors at Interstitial Lung Imaging Desks

Business Associate Agreement Requirements

As a scan packet vendor supporting Interstitial Lung Imaging Desks, you handle protected health information (PHI). A Business Associate Agreement defines what PHI you may receive, how you must safeguard it, and the accountability you carry for any misuse or breach.

What your BAA must include

  • Permitted uses and disclosures: limit activities to scanning, indexing, transport, and delivery functions tied to patient care and operations.
  • Safeguards: administrative, physical, and technical controls proportionate to the data sensitivity and workflow risk.
  • Breach and incident reporting: defined timelines, content of notices, evidence preservation, and cooperation duties.
  • Subcontractor flow-down: require any subcontractors to sign equivalent Business Associate Agreement terms before accessing PHI.
  • Minimum necessary standard: procedures that restrict access to only what staff need to do their job.
  • Return or destruction: methods and timelines to return or destroy PHI at contract end, with documented attestation if destruction is infeasible.
  • Audit and verification: right of the covered entity to review controls, including on-site inspections and document requests.
  • Sanctions and termination: corrective action and termination triggers for noncompliance.

Keep a current, countersigned BAA on file, map every clause to your internal policies, and brief relevant team members on their obligations.

Chain of Custody Documentation Practices

Chain of Custody Logs prove who handled each scan packet, when and where it moved, and that contents remained intact. For busy imaging desks, precise custody records reduce misplaced records and support timely care.

Required elements for each custody record

  • Unique packet identifier (barcode or QR), patient identifier truncated or masked, and packet contents category (e.g., orders, prior CT reports, PFTs).
  • Date/time stamps for creation, pickup, scanning start/finish, quality check, and delivery/return.
  • Names and signatures/initials of each custodian with role (intake, courier, scanner, QA).
  • Location transitions: desk, secure cabinet, vehicle, scanning room, archive.
  • Tamper-evident seal number (if used) and condition on receipt and handoff.
  • Exceptions and variance codes (e.g., damaged seal, missing page) with corrective action taken.
  • Retention period and storage location for the custody record itself.

Standardize custody forms across all sites, verify completion at handoffs, and reconcile daily counts to catch discrepancies early.

Secure Transport Protocols

PHI Transport Security covers both digital and physical movement of records. Your procedures must prevent interception, loss, or unauthorized access from desk to scanner to repository.

Digital transport controls

  • Encrypt in transit using TLS 1.2 or higher for uploads and APIs; use SFTP or mutually authenticated VPN for system-to-system transfers.
  • Disallow email for PHI unless using managed S/MIME or PGP with approved key management and recipient verification.
  • Harden endpoints with full-disk encryption, automatic lock, remote wipe, and mobile device management for laptops or tablets used at imaging desks.
  • Apply least-privilege access, multifactor authentication, and session timeouts on scanning and indexing applications.
  • Prohibit local storage of PHI on personal devices and removable media unless specifically approved, encrypted, and logged.

Physical transport controls

  • Use locked, tamper-evident containers; seal and record seal numbers in Chain of Custody Logs.
  • Train couriers on privacy, spill response, and emergency procedures; require visible ID and documented pickup/drop-off times.
  • Secure vehicles (locked, alarmed if possible); avoid unattended stops; store containers out of sight.
  • Define approved routes and maximum dwell times between locations; escalate if time thresholds are exceeded.
  • Log any transfer to temporary holding areas with responsible custodian identified.

Physical Access Controls Implementation

Physical Access Restrictions reduce the chance that unauthorized individuals view, copy, or remove documents while you work at imaging desks or vendor facilities.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Facility and workstation safeguards

  • Badge-controlled entry to scanning rooms and records storage; maintain visitor logs and escort all non-cleared individuals.
  • Position scanners and monitors away from public view; apply privacy filters and automatic screen locks.
  • Store unscanned packets in locked cabinets; separate intake, in-process, and completed queues to avoid mix-ups.
  • Use secured shred bins for misprints and duplicates; never dispose of PHI in regular trash.
  • Install surveillance in intake and scanning areas according to policy; retain footage per retention schedule.
  • Keep clean-desk standards: no PHI left exposed during breaks or shift changes; perform end-of-day sweeps.

Staff HIPAA Training Programs

Your program should deliver role-based instruction with proof of completion. Maintain HIPAA Training Certification records for auditors and clients.

Training scope and cadence

  • Provide onboarding training before independent PHI handling; refresh at least annually or when policies, systems, or laws change.
  • Cover Privacy Rule principles, Security Rule safeguards, minimum necessary, and breach/incident reporting.
  • Include practical modules for imaging-desk workflows: packet intake, labeling, scanning resolution and modes, indexing, and exception handling.
  • Teach social engineering and phishing awareness, secure transport, and device security basics.
  • Assess understanding with quizzes or observed competency checks; document remediation where needed.

Track attendance, dates, curriculum, and trainer credentials. Tie access to systems and areas to current training status.

Encryption and Digital File Security

Encryption and file hygiene protect PHI during and after scanning. Align your controls with HIPAA Security Rule Encryption expectations and document your approach.

File creation and handling

  • Standardize scan settings (e.g., 300 dpi or higher, grayscale/color as appropriate) to ensure legibility without oversharing PHI.
  • Use file naming conventions that omit direct identifiers when possible; avoid embedding PHI in filenames or folder names.
  • Export to durable formats (e.g., PDF/A) and remove hidden metadata; apply approved redaction methods for sensitive fields.

Encryption and access control

  • Encrypt data at rest with strong algorithms (e.g., AES-256) using FIPS 140-2/140-3 validated modules where available.
  • Manage keys centrally with rotation, separation of duties, and restricted administrator access.
  • Enforce MFA, unique user IDs, short session lifetimes, and automatic logoff on scanning and repository systems.
  • Enable Data Loss Prevention rules to block uploads to unapproved cloud apps and removable media.
  • Patch operating systems and scanning software promptly; monitor endpoints for malware and unauthorized changes.

Quality Assurance and Audit Documentation

Quality controls ensure clinical usability and regulatory defensibility. Your Audit Trail Documentation must make every action traceable from packet intake to archive.

Operational quality checks

  • Sample each batch for image clarity, completeness, orientation, and correct patient/indexing metadata.
  • Measure error rates (missing pages, misfiles, duplicates) and set thresholds that trigger corrective action.
  • Record root causes and corrective/preventive actions (CAPA); verify effectiveness on subsequent runs.
  • Use dual verification for merges/splits and any manual re-indexing that could impact care.

Audit and retention

  • Maintain immutable logs of user access, edits, exports, and deletions with timestamps and device/location data.
  • Retain Chain of Custody Logs, QA checklists, incident reports, and training records per client and regulatory schedules.
  • Conduct periodic internal audits and readiness drills; document findings, remediation owners, and closure dates.
  • Provide clients with routine KPI reports and attestations covering PHI Transport Security and Physical Access Restrictions controls.

Conclusion

This checklist gives you a practical path to safeguard PHI at Interstitial Lung Imaging Desks: anchor responsibilities in a solid Business Associate Agreement, prove handling with custody records, secure every transport channel, restrict physical access, keep staff trained, encrypt and control digital files, and preserve evidence through rigorous audits.

FAQs.

What is a Business Associate Agreement and why is it required?

A Business Associate Agreement is a contract that allows you to receive and process PHI on behalf of a covered entity while binding you to HIPAA privacy and security safeguards. It clarifies permissible uses, mandates protections, sets breach reporting duties, and gives the client audit rights—making it essential for compliant scanning and handling.

How should chain of custody be documented for PHI?

Use Chain of Custody Logs that capture a unique packet ID, masked patient identifier, dates/times, each custodian’s name and signature/initials, location changes, seal numbers, and any exceptions with corrective action. Reconcile counts at shift end and retain the logs per policy.

What are the requirements for secure transport of patient records?

Encrypt digital transfers with TLS or SFTP/VPN, secure endpoints with full-disk encryption and MFA, and ban unapproved storage. For physical movement, use locked, tamper-evident containers, trained couriers, documented handoffs, and time-bounded routes—recording all steps in custody logs.

How often must staff complete HIPAA training?

Provide training before staff handle PHI independently and refresh at least annually, or sooner when policies, systems, or regulations change. Keep HIPAA Training Certification records to verify compliance and tie system or area access to current training status.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles