General HIPAA checklists talk about access controls and encryption in the abstract. Imaging environments have their own, more specific exposure points — this is the checklist we actually walk through with clients.
Access & identity
- PACS and RIS accounts tied to individual users, not shared logins.
- Role-based access separating techs, radiologists, referring physicians, and administrative staff.
- Automatic session timeout on viewing workstations, especially shared reading-room terminals.
- Offboarding process that actually revokes PACS/VNA access on the day someone leaves.
Transmission & networking
- DICOM traffic encrypted in transit between sites, not just relying on network isolation.
- VPN or dedicated links for any modality or gateway communicating outside your firewall.
- Business associate agreements in place with every vendor that touches PHI-bearing studies — including AI vendors and cloud storage providers.
De-identification & data sharing
- A documented process for both header-level and pixel-level de-identification before any external data sharing.
- Visual or OCR-based review of burned-in text on ultrasound, C-arm, and secondary-capture images before release.
- An audit trail showing what was de-identified, when, and by what process — not just an assumption that "the export tool handles it."
Vendor & third-party risk
- Security review completed for any AI vendor with access to live studies.
- Clear data retention and deletion terms with cloud PACS or VNA providers.
- Incident response plan that includes imaging systems specifically, not just the EHR.
This checklist is a starting point, not a substitute for a formal risk assessment. If any of these items raise a question you can't answer confidently, that's worth a closer look before an auditor — or a breach — finds it first.