
HIPAA for Puerto Rico clinics: a checklist that passes audit
PHI in EHR, front desk, and backups. Minimum controls for PR clinics aligned to NIST and OCR.
Clinics in Guaynabo, Ponce, and Mayagüez handle PHI in EHR systems, front-desk tablet forms, and office NAS backups. NIST SP 800-66 maps technical controls to the HIPAA Security Rule; OCR does not accept "we did not know" when a laptop stolen from a parking lot exposes 2,000 patient records.
The checklist we use with mid-size practices starts with inventory: where PHI lives (cloud EHR, billing Excel, lab scans in email), who accesses it, and documented retention. Encryption in transit and at rest for EHR is baseline; so is the shared front-desk printer storing jobs in memory and the physician's USB with lab exports.
Access controls: no personal accounts on EHR, MFA on remote access, termination checklist when clinical staff leave. Bruce Schneier has noted for years that insider threat and orphaned accounts are as real as external hackers. Review access logs monthly even as a random sample — OCR asks for diligence, not perfection.
Backups and continuity: copies outside the practice AD domain, quarterly restore tests, and a plan if SaaS EHR fails during hurricane season. Business Associate Agreements signed with every PHI-touching vendor — hosting, billing, telehealth — not generic templates without local legal review.
Awareness for clinical staff: no case discussion on WhatsApp, verify identity before releasing records by phone, report lost laptops within minutes. HIPAA in Puerto Rico is not just mainland compliance; Puerto Rican patients trust you with sensitive data and OCR fines do not discriminate by practice size.

Operations and execution — connecting strategy with what the team ships every week.


