Security Risk Assessment (SRA) Checklist Before Connecting a Street Medicine Van to Your EHR

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Security Risk Assessment (SRA) Checklist Before Connecting a Street Medicine Van to Your EHR

Kevin Henry

Risk Management

August 12, 2026

7 minutes read
Share this article
Security Risk Assessment (SRA) Checklist Before Connecting a Street Medicine Van to Your EHR

Before you connect a street medicine van to your EHR, use this Security Risk Assessment (SRA) checklist to verify that Electronic Protected Health Information (ePHI) is identified, protected, and monitored. The steps below align with the HIPAA Security Rule and translate mobile-clinic realities into practical controls you can implement quickly.

Defining Assessment Scope for ePHI Coverage

Start by drawing the boundaries of your assessment so you know exactly which systems, people, and workflows create, receive, maintain, or transmit ePHI. Be explicit about data flows between the van, cloud services, and the EHR.

Checklist

  • Inventory assets: tablets, rugged laptops, routers/hotspots, IoMT devices, printers, external drives, and any on-van servers or gateways.
  • Map ePHI data flows from point-of-care capture to EHR ingestion, including store-and-forward workflows and offline caching.
  • Define logical and physical boundaries: van network segments, cellular backhaul, VPNs, and clinic-side infrastructure.
  • Identify users and roles: clinicians, drivers, case managers, volunteers, and remote IT support with access to ePHI.
  • Catalog data types: demographics, clinical notes, images, lab readings, prescriptions, and eligibility documents.
  • Document trust assumptions for each connection (e.g., VPN termination points, certificate validation, mobile MDM posture checks).
  • Confirm which regulatory requirements apply, centering on the HIPAA Security Rule for ePHI and any state privacy obligations.

Artifacts to Produce

Identifying Threats and Vulnerabilities

Evaluate what could go wrong—then tie each threat to specific weaknesses in your environment. Consider technical, human, and environmental risks unique to mobile care.

Checklist

  • Threat categories: device loss/theft, unauthorized access, misdirected messages, malware/ransomware, roadside power issues, weather, and public-encounter privacy risks.
  • Vulnerability scan results for endpoints and network gear; review patch levels, OS versions, and default credentials.
  • Authentication gaps: shared accounts, weak passcodes, lack of MFA, or absent certificate-based device trust.
  • Encryption gaps: unencrypted local storage, missing TLS 1.2+ for transit, or key handling weaknesses.
  • Wireless risks: open SSIDs, weak hotspot passwords, no client isolation, missing VPN for EHR traffic.
  • Process gaps: inadequate screening of volunteers, missing check-in/check-out of devices, weak media handling, or absent change control.

Risk Rating

Rate each risk by likelihood and impact, then record it in a risk register. Note existing controls and proposed mitigations so leadership can decide to mitigate, accept, transfer, or avoid each risk.

Evaluating Third-Party Vendor Compliance

Third-Party Integration Compliance is critical when carriers, EHRs, telehealth platforms, and MDM providers touch ePHI. Validate that each business associate meets your security standards and contractual duties.

Checklist

  • Confirm Business Associate Agreements cover ePHI handling, breach notification, and right-to-audit.
  • Request security attestations: HIPAA program overview, SOC 2 Type II summaries, penetration test reports, and vulnerability management cadence.
  • Verify data residency, subcontractor use, and encryption standards for data in transit and at rest.
  • Review API security: OAuth 2.0/OIDC, token scopes, mutual TLS, rate limiting, and audit logging.
  • Assess support practices: secure remote access, ticket redaction of ePHI, and incident escalation paths.
  • Evaluate update policies: firmware/OS patch SLAs for routers, gateways, and managed endpoints.

Artifacts to Produce

  • Vendor due-diligence summaries and risk ratings.
  • BAA repository and evidence of control alignment with the HIPAA Security Rule.
  • Integration security requirements for each vendor connection to the EHR.

Integrating IoMT Device Security Measures

Internet of Medical Things (IoMT) Security must account for constrained devices and clinical safety. Treat each device as an ePHI-capable endpoint that requires lifecycle controls.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Checklist

  • Create a live IoMT inventory with make, model, firmware, serial, owner, and clinical workflow mapping.
  • Provision unique credentials and disable defaults; prefer certificate-based authentication where supported.
  • Segment networks: place IoMT on dedicated VLANs with least-privilege rules to EHR, gateways, and update servers.
  • Harden devices: disable unused services/ports, lock down USB/Bluetooth, and enforce secure time sync.
  • Encrypt data at rest and in transit; verify integrity checks for results sent to the EHR.
  • Establish patch/firmware processes, including rollback plans and maintenance windows for mobile operations.
  • Enable telemetry and audit logs; forward to a central SIEM with alerts for anomalous behavior.
  • Define safe fallback modes to prevent patient-care disruption if connectivity or certificates fail.

Conducting Facility Physical Security Walkthroughs

Physical Security Controls protect devices, media, and staff in dynamic street settings. Walk through the van, storage sites, and any pop-up clinics to validate safeguards.

Checklist

  • Access control: key management, lock quality, tamper-evident seals, and after-hours storage procedures.
  • Device security: cable locks, secure cabinets, privacy filters, and auto-lock timeouts for endpoints.
  • Media handling: locked containers for forms and labels, secure printers, and defined chain-of-custody for paper ePHI.
  • Environmental safety: power conditioning, surge protection, and safe placement to avoid overheating or moisture.
  • Privacy in public spaces: patient check-in positioning, verbal disclosure minimization, and screen shielding.
  • Vehicle protection: GPS tracking, alarm systems, and process for rapid wipe if a device or van is stolen.
  • Waste management: secure shredding or sealed return-to-clinic protocol for ePHI-bearing materials.

Implementing Risk Management Strategies

Translate findings into a prioritized action plan using a Risk Management Framework. Balance speed, cost, and residual risk so you can connect to the EHR confidently.

Checklist

  • Create a risk register with owners, target dates, and chosen treatments (mitigate, accept, transfer, avoid).
  • Define administrative controls: policies, training, sanctions, onboarding/offboarding, and vendor oversight.
  • Define technical controls: MFA, MDM/EMM baselines, disk encryption, VPN, endpoint protection, and centralized logging.
  • Define physical controls: secure storage, escort requirements, equipment labeling, and transport protections.
  • Build a Plan of Action and Milestones (POA&M) with measurable success criteria and verification steps.
  • Document residual risk and obtain leadership sign-off before go-live.

Establishing Incident Response Procedures

Prepare an Incident Response Plan that addresses mobile threats and ensures rapid containment and recovery without compromising care.

Checklist

  • Define roles and contacts: incident commander, privacy/compliance officer, IT lead, vendor liaisons, and legal.
  • Set severity levels and triage criteria for events like lost devices, suspected ePHI exposure, or ransomware.
  • Create step-by-step playbooks: device theft (remote lock/wipe, key revocation), compromised hotspot (rotate creds, replace SIM), and EHR credential misuse (disable, investigate, re-enroll).
  • Establish evidence handling and chain-of-custody procedures for forensics.
  • Prestage communications: internal alerts, patient notifications when required, and regulator reporting timelines.
  • Conduct tabletop exercises focused on van operations and after-hours scenarios; track lessons learned.
  • Define recovery verification: integrity checks, log review, and approval to return to service.

FAQs.

What is the purpose of an SRA before EHR integration?

An SRA identifies how ePHI will flow between the van and your EHR, pinpoints threats and vulnerabilities, and maps controls to the HIPAA Security Rule. It gives you a prioritized action plan to reduce risk before go-live and documents due diligence for auditors and leadership.

How do you assess vendor compliance for street medicine vans?

Confirm Business Associate Agreements, review security attestations and testing summaries, validate encryption and access controls for integrations, and ensure incident escalation paths are clear. Score each vendor’s Third-Party Integration Compliance and require remediation or compensating controls before enabling connectivity.

What security measures are essential for IoMT devices?

Maintain a live inventory, enforce unique credentials or certificates, segment networks, encrypt data in transit and at rest, patch firmware on schedule, and centralize logs. These Internet of Medical Things (IoMT) Security practices protect clinical data and sustain safe device operation in the field.

How often should the SRA be updated?

Review at least annually and whenever there are material changes—new devices, vendors, workflows, or connectivity methods. Update the risk register, control set, and Incident Response Plan so your protections evolve with the van program and the EHR environment.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles