Independent Radiology Imaging Center HIPAA Compliance Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Independent Radiology Imaging Center HIPAA Compliance Checklist

Kevin Henry

HIPAA

September 30, 2026

8 minutes read
Share this article
Independent Radiology Imaging Center HIPAA Compliance Checklist

This Independent Radiology Imaging Center HIPAA Compliance Checklist turns regulatory requirements into concrete actions you can execute across imaging workflows that handle electronic protected health information (ePHI). Work through each section to verify that your safeguards are complete and current.

Conduct Risk Analysis

Perform an “accurate and thorough” assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI as required by 45 CFR §164.308(a)(1)(ii)(A). Your analysis should be evidence‑based, repeatable, and tightly mapped to real radiology operations.

Scope the environment

  • Include modalities (CT, MR, US, X‑ray), acquisition consoles, PACS/VNA, diagnostic viewers, RIS/EHR interfaces, HL7/DICOM brokers, teleradiology gateways, image portals, speech recognition, and backup/archival systems.
  • Map data flows for DICOM, HL7, and web protocols to identify where ePHI is created, received, maintained, transmitted, exported, or destroyed.

Identify threats and vulnerabilities

  • Common risks: plaintext DICOM links, unsupported OS on modalities, weak or shared passwords, exposed vendor remote access, misrouted studies, removable media, and incomplete backups.
  • Consider human factors (misdelivery, mislabeling), third‑party dependencies, and environmental hazards (power, HVAC, water).

Analyze and document risk

  • Rate likelihood and impact, record assumptions, and capture existing controls and gaps in a living risk register.
  • Prioritize remediation with owners and dates; link each action to policy references and budget line items.

Integrate into operations

  • Update the analysis at least annually and whenever substantial changes occur (new PACS, cloud migration, telerad expansion).
  • Exercise incident response and breach notification protocols with tabletop scenarios that use imaging‑specific cases (e.g., misconfigured DICOM routing).

Maintain Asset Inventory

Maintain a complete, continuously updated inventory of every system that touches ePHI. Accurate inventories power patching, access reviews, incident response, and lifecycle management.

What to track for each asset

  • Owner/custodian, physical location, role (e.g., modality, PACS node, viewer, broker), and data classification.
  • Identifiers: hostname, IP, MAC, DICOM AE Title, serial number, firmware/OS version, and support status/EOL.
  • Security posture: encryption at rest enabled, backup status, vulnerability/patch level, logging status, and network segment/VLAN.
  • Connectivity: inbound/outbound DICOM peers, HL7 endpoints, web services, and any remote support tools.
  • Vendor details: contract dates, business associate agreement requirements status, and points of contact.

Operational practices

  • Automate discovery where possible; reconcile daily. Label devices and maintain data‑flow diagrams alongside the inventory.
  • Track spares/loaners and temporary devices used during service events to ensure they inherit required controls.
  • Embed onboarding/offboarding checklists so nothing joins or leaves the network without registration, encryption, and wipe/sanitization as needed.

Implement Access Controls

Limit ePHI exposure using least privilege and the minimum necessary standard. Design access so clinicians can work efficiently without opening unnecessary pathways to data.

Identity, roles, and provisioning

  • Assign unique user IDs; prohibit shared logins on modalities, PACS, and viewers.
  • Implement role‑based access control (RBAC) mapped to job functions (technologist, radiologist, scheduler, physicist, admin).
  • Provision and deprovision promptly; remove or disable accounts within 24 hours of role change or termination.
  • Provide documented, time‑limited emergency (“break‑glass”) access with mandatory justification and enhanced auditing.

Authentication and session security

  • Enforce MFA for remote access and all privileged/admin accounts; integrate with an enterprise IdP for SSO where feasible.
  • Control service and vendor accounts via vaulting, rotation, and per‑use enablement; require supervised sessions.
  • Enable automatic logoff/timeouts on consoles and viewers; lock screens on all workstations left unattended.

Data handling controls

  • Constrain export/print/burn functions to authorized roles; watermark exports and log all external sharing events.
  • Apply approval workflows for bulk queries and data pulls, and monitor for anomalous access patterns.

Apply Encryption Standards

Encrypt ePHI in motion and at rest, selecting controls that are practical for imaging throughput and legacy devices while maintaining strong cryptographic assurance.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Data in motion

  • Use DICOM TLS encryption end‑to‑end for image exchange between modalities, PACS/VNA, and gateways; disable plaintext where possible.
  • Standardize on TLS 1.2/1.3 with modern AEAD ciphers; manage certificates via an internal CA and automated renewal.
  • Protect viewer portals, admin consoles, and APIs with HTTPS/TLS; use VPNs for teleradiology and remote service access.
  • For legacy nodes that cannot speak TLS, deploy DICOM‑TLS gateways or segment them in tightly controlled enclaves with compensating controls.

Data at rest

  • Enable full‑disk encryption for laptops and workstations; use FIPS 140‑validated modules where available.
  • Protect server databases, PACS object stores, and archives with encryption and key rotation; encrypt backups and offsite media.
  • Ensure encrypted export media and secure key handling for any removable drives used in workflows.

Key management

  • Centralize keys in a KMS or HSM; enforce role separation, rotation schedules, secure backup of keys, and revocation procedures.
  • Document key lifecycle, access approvals, and recovery drills aligned to RPO/RTO for imaging operations.

Enforce Audit Controls

Record and routinely review activity to detect inappropriate access and support investigations. Logging should be comprehensive, tamper‑evident, and correlated across systems.

What to log

  • PACS/RIS/viewer events: user logins, study opens, annotations, dictations, edits, exports, prints, and deletes.
  • Administrative actions: configuration changes, role/permission changes, and break‑glass justifications.
  • System events: failed logins, VPN connections, vendor remote sessions, and DICOM routing anomalies.

Retention, integrity, and review

  • Define PACS audit logs retention based on risk, regulatory, and litigation needs; many centers align to six‑year HIPAA documentation retention.
  • Synchronize time (NTP), centralize to a SIEM, and store logs on tamper‑evident or WORM media with access controls.
  • Implement daily alert triage, weekly summaries, and monthly deep‑dives; feed findings back into the risk analysis.

Response integration

  • Link alerts to incident runbooks and breach notification protocols; preserve chain of custody for any evidence.

Establish Business Associate Agreements

Execute and manage BAAs with any vendor or partner that creates, receives, maintains, or transmits ePHI on your behalf. Ensure contracts reflect practical, testable safeguards.

Identify business associates

  • Cloud PACS/VNA and image‑sharing platforms, teleradiology groups, billing/clearinghouses, dictation/transcription, MSPs, secure messaging, backup/storage, and device vendors with remote access.

Business associate agreement requirements

  • Permitted uses/disclosures, safeguard obligations, the minimum necessary standard, and flow‑down to subcontractors.
  • Breach reporting timelines that allow you to meet HIPAA deadlines (e.g., vendor notifies you within a few days of discovery).
  • Right to audit/assess, incident cooperation, termination assistance, and return/secure destruction of ePHI.
  • Security points of contact, change‑notification duties, and cyber insurance/indemnification where appropriate.

Lifecycle management

  • Execute BAAs before any ePHI exchange; maintain a repository linked to your asset/vendor inventory.
  • Re‑evaluate BAAs on service changes, acquisitions, or new data flows; test vendor access end‑to‑end with DICOM TLS encryption enabled.

Adhere to Physical Safeguards

Control physical access and protect devices to prevent theft, tampering, or inadvertent exposure of ePHI in clinical and back‑office areas.

Facility access controls

  • Restrict server rooms and network closets with badges and logs; escort visitors and service personnel.
  • Use cameras, door alarms, and environmental monitoring (power, temperature, water) for critical spaces.
  • Maintain documented procedures for emergency access and disaster recovery site entry.

Workstation and console security

  • Place diagnostic workstations in controlled areas; use privacy screens and automatic screen locks.
  • Secure devices with cable locks or cabinets; disable unnecessary USB ports and optical burners.
  • Ensure encrypted local storage and rapid patching for OS and viewer components.

Device and media controls

  • Track portable media; encrypt and label all media that may contain ePHI; document chain of custody.
  • Sanitize or destroy media per NIST SP 800‑88 before reuse, service, or disposal; verify vendor practices during RMA/repair.
  • Standardize on secure electronic image exchange to reduce reliance on CDs/DVDs.

Conclusion

By executing this checklist—anchored in rigorous risk analysis, precise asset control, strong access and encryption, robust auditing, disciplined BAAs, and pragmatic physical safeguards—you transform HIPAA compliance from a one‑time project into daily, measurable practice for your imaging center.

FAQs

What is required for HIPAA risk analysis in radiology centers?

You must conduct an accurate and thorough assessment of risks to ePHI per 45 CFR §164.308(a)(1)(ii)(A). Scope all imaging systems and data flows, identify threats and vulnerabilities, rate likelihood and impact, and document a risk management plan with owners and deadlines. Reassess at least annually and after major changes, and retain documentation in accordance with HIPAA record‑keeping requirements.

How should access controls be implemented for imaging systems?

Use unique user IDs, RBAC tied to job roles, and the minimum necessary standard. Enforce MFA for remote and privileged access, apply automatic logoff on consoles, and require documented, audited break‑glass access. Review privileges regularly, vault and rotate service/vendor credentials, and disable accounts promptly when roles change.

What are the encryption requirements for transmitting DICOM data?

HIPAA treats encryption as an addressable safeguard—you must implement it when reasonable and appropriate or document equivalent protections. For imaging, use DICOM TLS encryption end‑to‑end (TLS 1.2/1.3 with strong ciphers) between modalities, PACS/VNA, gateways, and viewers. For legacy devices that cannot use TLS, isolate them, use secure gateways or VPNs, and document compensating controls in your risk analysis.

When must business associate agreements be established?

Execute BAAs before disclosing any ePHI to a vendor or partner that will create, receive, maintain, or transmit it on your behalf. Ensure the agreement covers permitted uses/disclosures, safeguards, subcontractor obligations, breach notification timelines, termination, and return or destruction of ePHI. Update BAAs when services or data flows change.

What are the breach notification timelines under HIPAA?

Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. For breaches affecting 500 or more individuals in a state or jurisdiction, also notify prominent media and HHS within 60 days. For fewer than 500 individuals, log the event and report it to HHS within 60 days of the end of the calendar year. Your BAAs should set vendor reporting deadlines that enable you to meet these timelines.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles