PACS Compliance Audit Calendar: 12 Annual Checkpoints for Healthcare IT

Table of Contents

A HIPAA security risk assessment tends to get scheduled once, usually in January, and then forgotten until the next compliance deadline creates urgency. That pattern leaves eleven other months where BAAs go unreviewed, access lists go unaudited, and contingency plans sit untested until an actual outage proves whether they work. A PACS compliance audit calendar fixes the pattern by spreading twelve checkpoints across the year, so no single month carries the entire burden of proving the imaging environment is still compliant.

Why a Calendar, Not Just a Checklist

Knowing what to check and knowing when to check it are two different problems. A compliance officer can hold a complete list of imaging-specific HIPAA controls and still fail an OCR review if every control was last verified eighteen months ago. A risk assessment methodology has the same gap: a structured framework tells a security team how to run the assessment, not when the next one is due relative to the BAA review, the access recertification, or the disaster recovery test.

This calendar assumes both pieces already exist. It does not replace an imaging HIPAA compliance checklist or a structured risk assessment framework. It sequences twelve checkpoints, including where those two pieces slot in, into a working HIPAA audit schedule that spans the whole year instead of clustering everything into one audit season.

HIPAA’s Security Rule requires covered entities to conduct a risk analysis, but the regulation itself does not specify a frequency for how often that analysis has to run. HHS guidance on the requirement states that covered entities may perform the process annually or on a different interval, depending on the circumstances of their environment. Annual has become the default because it satisfies OCR’s expectation of an ongoing, documented process, not because the rule sets a calendar date.

A handful of HIPAA obligations are genuinely fixed rather than periodic. The breach notification clock starts at 60 days from discovery, not from a review cycle. Audit log and policy documentation must be retained for at least six years. Everything else on this calendar, the BAA reviews, the access recertifications, the training refreshers, the vendor reviews, is a best-practice cadence a compliance program chooses to impose on itself, because “periodic” is not a defensible answer during an OCR audit unless there is a documented, followed schedule behind it.

The 12-Month PACS Compliance Audit Calendar

Assign each checkpoint an owner and a month, and treat the calendar itself as a living document reviewed at the December checkpoint. Platforms such as OmniPACS build several of the underlying controls, audit logging, encryption, and role-based access, directly into the infrastructure layer, which shifts some checkpoints from building a control to verifying one that already exists. The sequence below spreads administrative, physical, technical, and vendor-facing reviews so no quarter is empty and no single month is overloaded.

January: Annual HIPAA Security Risk Assessment

January is when most compliance calendars start, and it is a practical month to run the annual HIPAA security risk assessment while budget and staffing plans for the year are still being set. This is the formal risk analysis the Security Rule requires: asset inventory, threat modeling, vulnerability findings, and a documented risk score for the imaging environment. Whatever framework the team already uses to run this step should produce a remediation plan the rest of the calendar can reference.

February: Business Associate Agreement Register Review

February is a practical month to audit the BAA register: every PACS vendor, cloud storage provider, and teleradiology platform that touches imaging ePHI needs a current, signed agreement. Confirm effective dates, renewal dates, and subcontractor obligations. An expired or missing BAA is a commonly cited finding in OCR enforcement actions, and it is far easier to catch with a dedicated review month than to discover during a breach investigation.

March: Access Control and Role Review

March is for recertifying who has access to what. Pull the full list of PACS, RIS, and VNA accounts and confirm every credential is unique, every role matches current job function, and every departed or transferred employee lost access when their role changed, not months later. Shared login credentials found during this review should be eliminated immediately rather than logged for a future fix.

April: Contingency Plan and Failover Test

April is a reasonable point in the year to run a full contingency plan test, cutting over to a secondary environment and confirming the imaging archive keeps serving reads. A plan that has only ever been reviewed on paper is not a tested plan. Document how long failover actually took against the recovery time target the plan assumes, not the number written in the document.

May: Workforce Security Training Refresh

May is a workforce training checkpoint, refreshing staff on access credential handling, DICOM transmission security, and what to do if a reading workstation goes missing. HIPAA does not fix an exact training interval, but an annual refresh, documented with attendance records, is the standard OCR looks for when it reviews a security management process.

June: Physical Safeguards Walkthrough

June covers the physical side: workstation placement, screen lock policies, server room access logs if any imaging infrastructure is still on premise, and removable media handling. Walk the actual reading rooms rather than reviewing a policy document, since workstations positioned in hallways or shared spaces are a common finding a paper review misses entirely.

July: Device and Removable Media Audit

July is dedicated to the inventory of removable media, exported studies on CDs, DVDs, or USB drives, and the destruction records for any media that has reached end of life. This checkpoint also tends to catch modalities and workstations still running unsupported operating systems, a recurring finding in imaging environments that skip a dedicated device review.

August: Audit Log Review Cadence Check

Audit log review itself should happen monthly, not annually, but August is a reasonable midyear point to audit the review process itself: are logs actually being read for unfamiliar IP addresses, bulk downloads, and after-hours access, or just retained and ignored? OmniPACS retains configurable audit log history natively, which keeps this checkpoint focused on reviewing access patterns instead of confirming that logging exists in the first place. Teams sizing how much manual effort this checkpoint actually takes can Check Out OmniPACS Services to see how that native logging, paired with role-based access controls and BAA support, reduces the review burden instead of adding a new tool to audit alongside everything else.

September: Vendor and Subcontractor Security Review

September is for reviewing every PACS-adjacent vendor against current security expectations: SOC 2 or equivalent audit reports, subcontractor disclosures, and confirmation that each vendor’s own risk analysis is current. Reusing the vendor evaluation checklist built for initial procurement works just as well for an annual re-evaluation, and running it here catches vendor drift before a contract renewal forces the question.

October: Breach Notification Tabletop Exercise

October lines up with Cybersecurity Awareness Month, which makes it a natural time to run a breach notification tabletop exercise against the ransomware and phishing scenarios that dominate current healthcare-specific cybersecurity guidance for the sector. Walk through a mis-routed DICOM transmission or a ransomware incident and confirm the team knows who determines whether an exception applies, who owns the 60-day notification clock, and who contacts HHS if the incident crosses the reporting threshold.

November: Data and Documentation Retention Review

November is a retention audit: confirm audit logs and policy documentation meet the six-year HIPAA floor, and check whether state medical records law in your jurisdiction extends that further for imaging studies specifically. This is also the month to confirm destruction procedures were actually followed for anything that passed its retention date during the year.

December: Policy Refresh and Next-Year Planning

December closes the loop: update policy documents with anything that changed during the year, confirm every checkpoint above actually happened and was documented, and adjust next year’s calendar for new modalities, new vendors, or a changed risk profile. This is also where OmniPACS customers typically start scoping what the platform’s built-in controls can absorb from next year’s manual review load.

Making the Calendar Work for Your Team

A healthcare compliance calendar only works when each checkpoint has a named owner, not just a month. Assign the January risk assessment to whoever owns security, the BAA register to whoever owns vendor contracts, and the physical walkthrough to whoever manages facilities. Put all twelve on a shared calendar with enough lead time that no checkpoint becomes a scramble in the week before it is due.

Some of these checkpoints are lighter when the underlying infrastructure already does part of the work. Centralized audit logging, role-based access controls, and BAA support built into OmniPACS reduce the review burden behind several of the checkpoints above, rather than requiring a new tool to audit alongside everything else.

Keeping the Calendar Defensible

A documented, followed twelve-month cadence is what turns “periodic” from a vague legal term into something an OCR auditor can actually verify. The specific months matter less than the discipline of never letting any one checkpoint go a full year without proof that it happened.

Facilities weighing how much of this calendar their current PACS setup already covers, versus how much still depends on someone remembering to run a report, can look at how OmniPACS Delivers Scalable Monthly Plans, built around the same controls this calendar assumes are in place, with audit logging, encryption, and BAA support included rather than added on later.

Twelve glowing nodes arranged in a circular ring around a central PACS server silhouette, connected by thin arcs of purple and cyan light, representing a twelve month compliance cycle

Frequently Asked Questions

How often should a HIPAA security risk assessment be conducted?

HIPAA’s Security Rule does not set a fixed interval for a HIPAA security risk assessment. Most healthcare organizations run one annually and after any significant change, such as a new modality, a new vendor, or a cloud migration. Annual is the de facto standard OCR looks for, not a specific calendar requirement written into the rule text.

Is an annual risk assessment required by HIPAA?

No. HIPAA requires periodic risk analysis but does not mandate an annual schedule. HHS guidance states the frequency depends on each organization’s environment and could reasonably be annual, biannual, or every three years. Most compliance programs still choose annual because it is easier to defend during an OCR audit than a longer, undocumented gap.

What is a typical HIPAA audit schedule?

A typical internal HIPAA audit schedule runs the major reviews, risk assessment, BAA register, access controls, and contingency plan testing, on an annual cycle, layered with lighter monthly or quarterly checks like audit log reviews. HIPAA itself does not dictate this cadence; it follows OCR’s expectation of an ongoing, documented program rather than a single point-in-time check.

How do I build a healthcare compliance calendar?

Start by listing every recurring HIPAA obligation, risk assessment, training, BAA reviews, access recertification, contingency testing, and then assign each one a month and an owner. Spread them across the year instead of clustering everything into one audit season, and revisit the calendar itself annually to account for new vendors, modalities, or risks.

Share this article with a friend