| Legal / role mapping | Covered-entity / business-associate / contractor / processor / device role analysis; jurisdictions; service scope | Approved and current |
| HIPAA / privacy | Policies, NPP where applicable, minimum-necessary rules, individual-rights process, authorization/consent logic | No unresolved privacy gap |
| Security | Risk analysis, remediation register, architecture, access controls, encryption, logging, vulnerability evidence, backups | Residual risk accepted by authorized owner |
| Contracts / vendors | BAA, DPA, SCC or equivalent; subprocessor inventory; security assessment; breach and deletion terms | Executed before regulated data access |
| Clinical | Licensure, credentialing, privileging, scope, final-report responsibility, escalation, QA, malpractice coverage | Verified for facility and jurisdiction |
| AI / device | Intended-use review, device determination, validation, human-oversight rules, change control, QMS evidence where applicable | No unsupported diagnostic claim |
| Incident / breach | Incident-response plan, notification matrix, forensic preservation, regulator/customer contacts, tabletop exercise | Tested and assigned |
| Accessibility | Automated + manual accessibility testing, keyboard/screen-reader review, remediation log | Material barriers resolved |
| Data lifecycle | Inventory, retention schedule, deletion/return workflow, backup retention, data residency and transfer controls | Documented end-to-end |
| Training / workforce | Privacy, security, clinical and role-specific training; confidentiality; sanctions; offboarding process | Required workforce current |