Privacy Officer Check-Up 10 Things You Should Review

by

Privacy Officer Check-Up: 10 Things You Should Review

When was the last time you checked whether your privacy management program still reflects how your healthcare practice actually operates?

Employees change. Technology changes. Vendors change. New AI tools appear. Meanwhile, policies, procedures and Privacy Impact Assessments can quickly become outdated.

A Privacy Officer Check-Up helps you recognize what you have accomplished, identify what has changed and prioritize what needs attention next.

You do not need to fix everything today. The goal is to know where you are—and what comes next.

1. Confirm Your Privacy Officer Information Is Current

Check that the correct Privacy Officer information appears in your policies, collection notices, patient information, website, Privacy Impact Assessments and information provided to your privacy regulator, where applicable.

Identify the Privacy Officer including a telephone number or email address patients can use.

Most importantly, make sure everyone on your team knows who the Privacy Officer is and how to contact them.

2. Review Privacy Awareness Training

Privacy training should be included in onboarding, regular annual refresher training and updates following changes to legislation, technology, policies or privacy risks.

Registering someone for training is not the same as confirming they completed it. Your records should demonstrate who completed the training and when.

3. Review Oaths of Confidentiality Agreements

Confirm that custodians and affiliates—including employees, contractors, students and volunteers—have signed current and appropriate Oaths of Confidentiality.

Check that the agreements are signed, current, appropriate to each person’s responsibilities and accessible in the applicable personnel or contractor record.

4. Review User Accounts and Access Permissions

Ask your system administrators or IT provider to generate current user-account reports for your:

  • EMR, pharmacy management or clinical systems
  • Email and business computer systems
  • Microsoft 365 or Google Workspace
  • Shared folders and cloud applications
  • Remote-access tools
  • Administrative accounts

Remove or disable accounts that are no longer required. Confirm that current users have access appropriate to their roles. Document that the review was completed.

5. Check Whether Your PIAs Are Current

Compare your current operations with your existing Privacy Impact Assessments.

Have you changed software, vendors, locations, patient communication tools, information flows, business structure or Privacy Officer? Have you changed how health information is collected, used, disclosed, stored or destroyed?

Determine whether a PIA amendment, update or new PIA may be required.

6. Identify New Software, Vendors and Technology

Make a list of technology introduced since your last privacy review. This might include online booking, patient portals, electronic forms, payment systems, cloud storage, messaging tools, virtual care, transcription services or AI.

Privacy Officers should know which technologies handle health information and what safeguards are in place.

Review your Information Management Agreement listing and confirm that you have appropriate agreements with your service providers.

7. Find Out How Staff Are Using AI

Do not assume you know how AI is being used in your practice. Ask.

Staff and healthcare providers may be using AI for clinical documentation, meeting notes, drafting emails, summarizing documents, patient education, administration or marketing.

Confirm that identifying health information is not being entered into unapproved AI tools. Review whether your organization needs an AI Governance Framework, approved-tool list, vendor assessment, training or PIA.

8. Review Your Privacy Breach and Incident Log

Review the privacy incidents, near misses, complaints and concerns recorded by your organization.

Look for recurring problems, incomplete corrective actions, additional training needs and outstanding notifications.

For example, if faxes continue to be sent to the wrong recipients, reminding employees to “be more careful” may not be an effective corrective action. A recurring problem may indicate that the process or technology needs to change.

If you do not have a privacy breach log, now is a good time to start one.

9. Review and Test Your Privacy Breach Response

Review the Privacy Breach Management procedure in your Health Information Privacy and Security Policies and Procedures Manual.

Confirm that staff know how to recognize a possible breach, who to notify, what immediate containment steps to take and what information to document.

Test the procedure using a short, realistic scenario. A five-minute tabletop exercise can help your team understand what to do before a real incident occurs.

Document the exercise, who participated and any follow-up actions identified.

10. Document Your Review and Follow-Up Actions

For each checklist item:

  • Record what you reviewed
  • Identify any gaps
  • Assign responsibility
  • Establish a realistic follow-up date
  • Document when the action is completed

Keep the completed checklist as evidence of your ongoing privacy management program and demonstrable accountability.

Practical Privacy Tip

Do not try to fix everything during the check-up.

First, identify what is working, what has changed and what needs attention. Then prioritize your actions, assign responsibility and set realistic follow-up dates.

One completed action followed by another is more effective than an overwhelming list that never gets started.

Download the Privacy Officer Check-Up

Would you like a practical way to complete this review?

Download the Privacy Officer Check-Up: 10 Things You Should Review checklist.

Use it to recognize your accomplishments, identify gaps, assign responsibility and plan your next privacy management activities.

Get the checklist here:

Wish You Had a “Jeanie” to Help With Your Privacy Officer Role?

You don’t have to figure everything out on your own.

Practical Privacy Officer Strategies gives you practical training, tools, templates, and live coaching to help you know what to do next—and how to get it done.

Learn More About Practical Privacy Officer Strategies