Compliance Readiness
What HRSA reviewers actually ask for in your cybersecurity file
There is no cybersecurity chapter in the Health Center Program Site Visit Protocol.
That is not a free pass. It is why centers get surprised.
Reviewers still ask whether records can be retrieved, whether patient information is protected against loss, destruction, or unauthorized use, and whether you can produce the data HRSA requires. They open files. They interview the person named on the policy. If production does not match the PDF, the PDF does not count.
This is the operator version of that file. Written for the CEO, CIO, compliance lead, and IT lead at a 330 center in Puerto Rico or the USVI.
Millennial Networks is healthcare IT and MSP for FQHCs and CHCs in this region. Founded 2017. Ten-year mark: January 2027. Humans First, Tech Second.
Where this actually sits in the visit
HRSA uses the Compliance Manual and the Site Visit Protocol. Cybersecurity is not a named chapter. It shows up inside chapters you already know.
Quality Improvement/Assurance (Compliance Manual Chapter 10; Site Visit Protocol Chapter 8):
- A retrievable health record for each patient. A certified EHR is the example HRSA names. If the record cannot be opened, you have a QI/QA problem.
- Systems and procedures that protect confidentiality and safeguard information against loss, destruction, or unauthorized use, consistent with federal and state requirements.
The November 2025 Site Visit Protocol update is explicit: security policies should protect all patient information, even when it is not technically PHI under HIPAA. Scheduling notes and care-management logs count.
Program Monitoring and Data Reporting Systems (Compliance Manual Chapter 18): a system that collects and organizes data for UDS and other required reports. A failed restore does not pause that duty.
Board Authority: the board adopts and updates the policies that govern operations. A security policy that never went to the board is a governance gap.
Contracts: vendors who touch those systems need executed agreements. For PHI, that includes Business Associate Agreements. A reviewer can ask for the BAA with your EHR host, billing vendor, cloud, and MSP.
HIPAA is a federal requirement you already have. Reviewers are not OCR. They still ask whether you meet applicable federal requirements. A missing risk analysis is the fastest way to look unready. FTCA deeming is a separate file. Do not mix it in and call it done.
What a file a reviewer can open means
HRSA tells you to provide documents at least two weeks before the visit. What is not provided by the close of day one is not considered.
Document titles do not matter. Content does. You can call it a procedure, a protocol, or a plan. The reviewer reads what it says and whether staff follow it.
Interviews are part of the method. The security official, the CIO, the person who actually resets eCW access: they will be asked to describe the program without hunting a share drive.
So the file is not a binder you assemble when the dates land. It is how you run, sitting where the named owner can open it on the first ask. The themes below map to HIPAA Security Rule duties and to Chapter 10. Not a secret HRSA checklist. Not a certification shopping list.
Risk analysis
HIPAA's Security Rule requires an analysis of risks to electronic protected health information. Centers that cannot produce a dated analysis, with scope and findings, look unready.
What a reviewer can defend looking at: a dated document, not "we did one a few years ago." Scope that names the systems that hold patient information: EHR, backups, email, imaging, sliding-fee file shares. Findings and what you did with them. An analysis with no follow-through is a paper.
Do not invent a 40-control matrix for the visit. Produce the analysis you actually run, with owners on open items.
Policies that match production
Chapter 10 asks for systems and procedures, not a binder with last year's header.
Board-approved where your governance requires it. Staff can find it. The version in the file is the version in production.
What usually has to exist because HIPAA and Chapter 10 both demand it: how you protect patient information, including information that is not PHI. Who is allowed to see what, and how access is granted and removed. What happens when something breaks: incident, downtime, restore. How you train the workforce that touches that information.
If the policy says unique passwords and the front desk shares one eCW login, the interview will find it. Write what you do. Then do it.
Access control
Reviewers looking at EHR use and confidentiality will ask, in plain language, who can open a chart.
Be ready to show access tied to a person and a role, not a shared "nurse" account. Joiners get access that matches the job. Leavers lose it. Transfers get a change, not a pile of old rights. A way to see who accessed what, if you are asked.
A 330 center has MAs, temps, students, locums, and billing staff across sites. Shared logins are how PHI walks out. They are also how you fail the "safeguard against unauthorized use" test.
Backup and retrievable records
"Retrievable" is the word in the Manual. Backup software is not the proof. Restore is the proof.
Be ready to show what is backed up: EHR, the systems that feed UDS, the files that are not in the EHR. Where it lives, and that it is not only on the same island as the only server. That you have restored, on a date you can name. What clinic staff do when the EHR is down, and how the note gets back into the record.
Puerto Rico and the USVI make this non-optional. Generator time is not infinite. Connectivity fails in pieces. A mainland restore window that assumes a same-day truck roll is not a plan here.
If the record cannot be retrieved, Chapter 10 is already in play. Health outcomes sit on whether the provider can open the chart.
Incident response
You need a written path for security incidents and for downtime. HIPAA requires incident procedures. The OSV will test whether anyone knows it.
A reviewer can reasonably ask who the named owner is, what staff do when they see a wrong mailbox, a ransom note, or eCW that will not open, how you decide whether something is a reportable breach, and what you log. Even "no incidents this period" needs a place to live.
Do not write a 30-page plan that names tools you do not own. Write the call tree you would actually use at 6:40 a.m. when the west site is down.
Business Associate Agreements
Anyone outside your workforce who creates, receives, maintains, or transmits PHI for you needs a BAA. EHR vendor. Cloud. Billing. Shredding. Your MSP. Automation that touches charts.
The OSV samples contracts. Fully executed. Current. Emails documenting acceptance count. A draft in legal does not.
If digital staff has a named account in the EHR, that vendor is in this pile. So is the managed IT provider. Ask for the BAA before the visit, not during it.
Training
Workforce training is a HIPAA Security Rule requirement. Reviewers who ask "how do you protect patient information" will often ask who was trained.
What they can open: completions for staff who handle patient information, for the period you claim. New-hire timing, not only the annual blast. A roster that matches people who still work there.
A slide deck with no attendance list is not evidence.
HITRUST and SOC 2 are our stack, not your homework
Millennial Networks claims HIPAA, HITRUST, and SOC 2 Type II on our site as the posture of our own operation. We do not publish badge dates here. That is how we run the stack under your clinic. It is not a 330-center mandate.
HRSA does not require a health center to buy HITRUST or SOC 2. A reviewer wants your risk analysis, procedures, access, restore, BAAs, and a person who can speak to them. A certification you will not maintain is worse than a clean, dated file that matches production.
If you are being sold "get certified before the OSV," ask whether the seller has sat in a 330-center visit. Then ask to see that file tomorrow.
Island operating reality is part of the file
A mainland template will not mention generator run time, a USVI spare-parts delay, or a site that stays open while the main clinic is dark.
Your contingency procedures should. Chapter 10's "loss or destruction" test is this: can you protect and retrieve patient information when power and connectivity fail the way they fail here.
Magaly López, Health IT Specialist at the PR Primary Care Association (HCCN for Puerto Rico and the Virgin Islands):
"As Health IT Specialist for the 330 Centers in Puerto Rico and the Virgin Islands, I have seen how Millennial's services have been fundamental in strengthening the technology infrastructure across our clinics. Their team has been a key ally in modernizing systems, enabling more agile, secure, and efficient care."
How we work the file with you
We do not drop a binder and leave.
The work is to make the file match the stack: managed IT for 330 centers, access that matches roles, backup you have restored, an incident path staff can recite, executed BAAs, training with names on it. Automation that touches PHI has to be HIPAA-ready before you deploy it. Then a named owner can open the file on the first ask.
More on who we are and in resources.
FAQ
What does "HRSA cybersecurity" mean for a 330 center
Not a separate chapter. The overlap of Chapter 10 (retrievable records and confidentiality), Chapter 18 (data you can report), vendor contracts, board-approved policies, and HIPAA Security Rule duties you already have. If you cannot open the evidence, you do not have it.
What is HRSA site visit cybersecurity documentation
The file a reviewer can open: dated risk analysis, policies that match production, access control, backup and restore evidence, incident path, executed BAAs, and training completions. Titles do not matter. Content and interviews do. Documents are due before the visit. Day-one gaps stay gaps.
Book a discovery call
If your OSV dates are on the calendar, or you want the file current before they are, say so. We will look at what a reviewer can open today: risk analysis, policies, access, backup, incident path, BAAs, training. We will tell you what is ready and what is theater.
Millennial Networks · Metro Office Park Lot. 6, Suite 204, Guaynabo, PR 00968 · 4850 Tamiami Trl N, Suite 301, Naples, FL 34103 · 787-945-2260 · corp@mnetpr.com
